25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is HIPAA Compliance Verification?

“HIPAA Compliance Verification” is a term used by training providers to indicate an individual or organization has undergone and passed a course in HIPAA compliance. After passing the course in HIPAA compliance, the successful individual or organization is allowed to display the training provider´s “Certificate” or “Seal of Approval” on their website and other documentation – such as a résumé. The term “HIPAA Compliance Verification” is often interchanged with “HIPAA Certification” or “HIPAA Certified”. None of the three terms are recognized by the Department of Health & Human Services, who state on its website: “There is no HIPAA Certification process, and no company has the authority to certify HIPAA compliance. Such certifications do not absolve Covered Entities of their legal obligations.” So, Is There Any Point to HIPAA Compliance Verification? In a word “yes”. Although HIPAA compliance verification may not be recognized by the Department of Health & Human Services, HIPAA compliance training is mandatory. The training services provided by third-party companies...

Read More
City of Long Beach Notifies Individuals Affected by November 2023 Cyberattack
Apr30

City of Long Beach Notifies Individuals Affected by November 2023 Cyberattack

It has taken more than a year for current and former residents of the City of Long Beach in California to learn that some of their personally identifiable and protected health information was compromised in a cyberattack. Notifications have been sent to multiple U.S. states confirming that the information of 470,060 individuals was exposed and potentially stolen in the attack. That figure includes 258,191 individuals whose protected health information was compromised. No ransomware group is known to have claimed responsibility for the attack. The cyberattack was detected on or around November 14, 2023, and the forensic investigation confirmed on March 18, 2024, that sensitive data had been accessed or acquired by the threat actor. It then took a further 13 months before notification letters were mailed to the affected individuals. City officials confirmed that notification letters started to be mailed on April 14, 2025. City officials explained that most of the affected systems were restored and brought back online within a matter of weeks after the attack was detected, and while...

Read More
What is an 834 File in Healthcare?
Apr30

What is an 834 File in Healthcare?

An 834 file in healthcare is a benefit enrollment and maintenance file used to electronically exchange information about health plan members between employers, plan sponsors, third party administrators, and health plans. Because health plans are covered entities under HIPAA, an 834 file in healthcare must comply with the HIPAA 5010 version of the ASC X12N standard. One of the primary objectives of HIPAA was to simplify the administration of health insurance in order to reduce the costs of providing and paying for health care. However, prior to the passage of HIPAA, many organizations that used Electronic Data Exchanges (EDIs) had developed their own transaction formats. It was estimated at the time that about 400 formats for electronic health claims were in existence. Acknowledging that the use of different transaction formats limited the ability of healthcare providers and health plans to improve efficiency and reduce costs, Congress instructed the Secretary for Health and Human Services (HHS) to standardize the formats. In 2000, the Standards for Electronic Transactions to be...

Read More
Healthcare Orgs Fined for Employing Nurses on the HHS-OIG Exclusion List
Apr30

Healthcare Orgs Fined for Employing Nurses on the HHS-OIG Exclusion List

This month, the Department of Health and Human Services’ Office of Inspector General (HHS-OIG) agreed to settlements with two healthcare providers who employed nurses on the HHS-OIG exclusion list, who provided items or services that were billed to federally funded healthcare programs. The exclusion list, formally known as the List of Excluded Individuals and Entities (LEIE), contains entities and individuals excluded from participating in federally funded healthcare programs. The exclusion list was established to prevent fraud, waste, and abuse in federally funded healthcare programs. If an individual or entity has been added to the list, they are not permitted to participate in federally funded healthcare programs in any capacity. There are many different reasons for exclusion, including fraud convictions, patient abuse and neglect, felony drug convictions, submission of false claims, and participation in illegal kickback schemes. Certain violations carry a mandatory minimum exclusion period, with HHS-OIG having discretion over how long an entity or individual remains on the...

Read More
Ascension Health Notifying 437K Patients About Data Breach at Former Business Partner
Apr29

Ascension Health Notifying 437K Patients About Data Breach at Former Business Partner

Ascension Health in St. Louis, Missouri, has started notifying certain patients about a security incident at one of its former business partners. Ascension learned on December 5, 2024, that the business partner had experienced a hacking incident. An investigation was launched, and it was determined on January 21, 2025, that Ascension had inadvertently disclosed patient data to the former business partner, and that data had likely been stolen in the hacking incident. Ascension confirmed that its own systems were unaffected. A hacker was able to exploit a vulnerability in third-party software to gain access to data held by the former business partner. The data review confirmed that the information likely stolen in the incident included names, addresses, phone numbers, dates of birth, email addresses, race/gender, Social Security numbers, medical record numbers, insurance company names, and clinical information related to inpatient visits, which may have included, service locations, physicians’ names, discharge dates, and diagnosis and billing codes. Ascension said it has reviewed its...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist