25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is a HIPAA Confidentiality Agreement for Employees?
Dec08

What is a HIPAA Confidentiality Agreement for Employees?

A HIPAA confidentiality agreement for employees is similar to a non-disclosure agreement inasmuch as members of the workforce agree not to disclose any confidential information they encounter in the performance of their functions – unless the disclosure is permissible by the Privacy Rule, relevant to the function they are performing, and limited to the minimum necessary. The agreement should not only relate to the confidentiality of Protected Health Information, but to any information employees encounter that may not be protected by the Privacy Rule. This might include identifying non-health data maintained outside a protected designated record set, billing information, or proprietary information about the organization´s operations. An agreement of this type can also cover the non-disclosure of login credentials for the organization’s systems and the return of the organization’s property (for example, keys, ID badges, access cards, etc.) on termination or completion of employment. Other conditions may be added to the agreement depending on the nature of the...

Read More
Virtual 43rd National HIPAA Summit April 7-10, 2026
Dec08

Virtual 43rd National HIPAA Summit April 7-10, 2026

The National HIPAA Summit, a leading forum on healthcare EDI, privacy, cybersecurity, and HIPAA compliance, will be hosting the Virtual 43rd National HIPAA Summit on April 7, 2026, through April 10, 2026, with professional certification and HIPAA Summit Workforce Training sessions running before the event.   The event provides a tremendous opportunity for learning through HIPAA workforce training sessions and keynote speeches from top government officials and leading industry professionals. Attendees will gain valuable insights into health information privacy, healthcare cybersecurity, HIPAA enforcement, and a wealth of information to help them maintain HIPAA compliance and take healthcare data privacy and security to the next level. The HIPAA Summit runs from Tuesday, April 7, 2026, through Friday, April 10, 2026, and includes a preconference training program with an expanded curriculum. The training program kicks off on March 11, 2026, with AI Cyber Risk Professional (aiCRP) Training and the Professional Certification Exam with Uday Pabrai, MSEE, CMMC. Training sessions will...

Read More
HHS Publishes New AI Strategy for Expanding AI Adoption
Dec08

HHS Publishes New AI Strategy for Expanding AI Adoption

Last week, the Department of Health and Human Services (HHS) published its artificial intelligence (AI) strategy – a plan for increasing AI adoption within the HHS to improve efficiency and cut costs. The AI plan will see AI tools shared across all HHS departments, including the CDC, CMS, FDA, and NIH, with the goal of “supercharging internal operations through an AI-empowered workforce”. This approach, dubbed OneHHS, is intended to unify the HHS through shared AI infrastructure, streamline workflows, improve cybersecurity, and modernize the nation’s public health systems. While OneHHS has an initial internal focus, the HHS will seek to improve engagement with private sector stakeholders to develop new AI tools. The HHS strategy is based on five strategic pillars: Strengthening governance and risk management Developing infrastructure and platforms around users’ needs Promoting workforce development and burden reduction to improve efficiency Fostering health research and reproducibility through gold standard science Modernizing clinical and public health for better...

Read More
District Court Judge Blocks DOJ Subpoena for Medical Records of Transgender Children
Dec08

District Court Judge Blocks DOJ Subpoena for Medical Records of Transgender Children

Children’s Hospital of Philadelphia (CHOP) has won a legal challenge against the Department of Justice (DOJ) over a request for access to the protected health information of child-patients who received gender affirming care at CHOP. District Court Judge Mark Kearney ruled that the requests for patient data were “beyond the authority granted by Congress.” CHOP filed the lawsuit in the District Court for the Eastern District of Pennsylvania in response to a DOJ subpoena for fifteen categories of records related to gender-affirming care provided by CHOP. The records were requested as part of an investigation into the labeling and distribution of prescribed clinically authorized puberty blockers and hormone therapy to identify potential fraud and unlawful promotion of hormones and puberty blockers for transgender children, in violation of the Food, Drug, and Cosmetic (FD&C) Act. CHOP was one of twenty healthcare providers to receive subpoenas from the DOJ requesting information on minor patients as part of its efforts to restrict federal funding for gender-affirming care. The DOJ...

Read More
HIPAA Compliance Checklist
Dec08

HIPAA Compliance Checklist

This HIPAA compliance checklist explains what you need to know about HIPAA regulations: Establish whether your organization is required to comply with HIPAA. Appoint a HIPAA Privacy Officer. If required, appoint a Security Officer. Understand what PHI is. Conduct an audit to determine where and how PHI is used. Minimize the number of designated record sets in which PHI is maintained. Be aware that the HIPAA Security Rule consists of more than just the Administrative, Physical, and Technical Safeguards. Have procedures for notifying individuals and HHS’ Office for Civil Rights of data breaches. Verify if your organization is exempted from reporting data breaches to the State Attorneys General. Track changes to HIPAA and temporary Notices of Enforcement Discretion. Get The FREEHIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.Business Email *Name *FirstLastNumber *Company Name *Get Free Checklist Please enter correct email address Your Privacy Respected HIPAA Journal Privacy...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist