25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Florida Radiology Practice Announces 171K-record Data Breach
Oct09

Florida Radiology Practice Announces 171K-record Data Breach

Data breaches have been announced by Doctors Imaging Group in Florida, Rectangle Health in New York, and Care N’ Care in Texas. Doctors Imaging Group, Florida Doctors Imaging Group, a Gainesville, Florida-based physician-owned radiology practice, has recently reported a data breach to the HHS’ Office for Civil Rights that has affected 171,862 current and former patients. Suspicious activity was identified within its computer network on or around November 11, 2024, and the forensic investigation confirmed that unknown actors accessed its network between November 5, 2024, and November 11, 2024. During that time, files were copied from its systems, some of which contained the protected health information of patients. The substitute breach notice does not say if this was an extortion attempt, such as a ransomware attack, and the HIPAA Journal has not identified any posts by ransomware groups claiming responsibility for the attack. Doctors Imaging Group conducted a file review to identify the types of information exposed in the incident, which was completed on August 29, 2025. Data...

Read More

HIPAA Compliance for Visiting Nurses

HIPAA compliance for visiting nurses is the same as for any other medical professional, even though their working environments can be much different and the challenges to HIPAA compliance harder to overcome. This is because a visiting nurse is an employee of medical facility, hospice or other independent visiting nurse service, and is regarded to be a member of a Covered Entity´s workforce. As such, a visiting nurse is not a Business Associate – even though he or she provides a service for the Covered Entity – and is subject to the policies and procedures enforced by the Covered Entity. However, there are unique challenges with regards to HIPAA compliance for visiting nurses working in the community. These challenges primarily concern the disclosure of Protected Health Information (PHI) to people they meet in their working environments and how their patients´ PHI is created, used, stored and shared with other members of the Covered Entity´s workforce. Families and HIPAA Compliance for Visiting Nurses Similar to nurses working in medical centers, visiting nurses have to...

Read More
Best Psychiatry EMR
Oct09

Best Psychiatry EMR

The best psychiatry EMR supports prescribing and medication monitoring, psychiatric assessment and progress note documentation, lab ordering and results review, insurance and patient billing workflows, and administrative controls such as role-based access and audit logging to support consistent clinical operations and HIPAA-compliant handling of electronic protected health information. Psychiatry Practice Workflow Requirements Psychiatry practices manage ongoing medication decisions, symptom tracking across time, and clinical documentation that must remain coherent across frequent follow-up visits. The EMR needs to support medication reconciliation, refill workflows, and clinical decision support that fits outpatient psychiatry cadence without forcing duplicative documentation. Care coordination is common. Referring providers, primary care, therapists, and hospitals may send records that need to be filed, searchable, and available at the point of care. The EMR should support structured capture of diagnosis, medications, and allergies while also supporting narrative clinical...

Read More
Why is HIPAA Important for Billing and Coding?
Oct08

Why is HIPAA Important for Billing and Coding?

HIPAA is important for billing and coding because these functions depend on the lawful, accurate, and secure handling of protected health information and directly affect patient privacy, data security, and trust in the healthcare system. Billing and coding professionals routinely work with diagnosis codes, procedure codes, insurance identifiers, and patient demographics, all of which are tied to identifiable individuals and fall within the scope of HIPAA protections. Billing and coding teams often have access to a wide range of patient information that combines clinical details with financial data. This creates a higher risk profile because the information can reveal both a person’s medical history and their identity. HIPAA establishes rules that limit how this information can be accessed, used, and disclosed, helping ensure that billing activities support reimbursement and operations without exposing patients to unnecessary privacy risks. HIPAA is also mandatory in billing and coding because of the principle of minimum necessary use. Staff must access only the information required...

Read More
Harris Health Notifies Patients About 10-Year Insider Data Breach
Oct08

Harris Health Notifies Patients About 10-Year Insider Data Breach

Harris Health in Texas has recently started notifying 5,357 patients that their electronic health records may have been impermissibly accessed by a former employee. Concerningly, the unauthorized access had been ongoing for a decade before it was identified. Harris Health operates Ben Taub Hospital and Lyndon B. Johnson Hospital, and a network of 37 clinics, health centers, and specialty locations in and around Houston, Texas.  While notification letters are now being mailed to the affected individuals, the unauthorized access was detected on February 10, 2021. An investigation was launched to determine the extent of the employee’s HIPAA violation, with assistance provided by a nationally recognized digital forensics firm. The investigation confirmed unauthorized access to patient records from January 4, 2011, to March 8, 2021. After confirming that patients’ medical records had been accessed without any legitimate work purpose, the employee was terminated, and the Federal Bureau of Investigation (FBI) was notified. Harris Health has been assisting with the investigation,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist