25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is MSP in Healthcare?
Apr29

What is MSP in Healthcare?

The term MSP in healthcare most often relates to Managed Service Providers who support healthcare staffing, supply medical equipment, or manage multi-vendor IT services on behalf of healthcare organizations. HIPAA compliance plays a role in all three versions of MSP in healthcare, but has the biggest impact on providers of managed IT services. When a healthcare organization engages the services of a healthcare MSP, it is usually for one of three purposes. The first purpose is to support healthcare staffing. This involves a healthcare staffing MSP placing a healthcare professional or allied health professional in a healthcare organization on a short-term or a temp-to-hire contract to cover a staffing shortage. In this scenario, the responsibility for HIPAA compliance is shared three ways: The healthcare organization has the responsibility for training temporary members of the workforce on its HIPAA policies and procedures and security awareness. Healthcare professionals and allied health professionals have the responsibility for understanding the basics of HIPAA before taking a...

Read More
Endue Software Confirms Data Breach Affecting Multiple Providers
Apr29

Endue Software Confirms Data Breach Affecting Multiple Providers

Cybersecurity incidents have been announced by Endue Software, Whitman County Public Hospital District No. 3, Palo Verde Hospital, and Northern California Children’s Therapy Center. Endue Software Endue Software, an infusion management platform provider, has recently confirmed it has been affected by a cyberattack that involved unauthorized access to patient data. In its April 11, 2025, substitute breach notice, Endue Software explained that unauthorized access to some of its systems was identified on February 17, 2025. The forensic investigation confirmed that an unauthorized actor gained access to some of its systems for a brief period on February 16, 2025. While the window of opportunity was short, files were copied from its systems during that time. Since February, Endue Software has been reviewing the compromised data to determine which clients and patients have been affected. It has now been confirmed that the compromised data included patients’ full names, addresses, dates of birth, Social Security numbers, and medical record numbers. It is unclear how many of...

Read More

What is Considered a Breach of HIPAA?

A breach of HIPAA is considered to be any acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of the protected health information. It is important to understand what is considered a breach of HIPAA – and how breaches differ from violations of HIPAA – to avoid penalties for non-compliance with the Breach Notification Rule.  The text of HIPAA is very clear about what is considered a breach of HIPAA – § 164.402 of the Breach Notification Rule defining a breach as “the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part [the HIPAA Privacy Rule] which compromises the security or privacy of the protected health information.” When a breach of HIPAA is identified, Covered Entities must notify affected individuals within sixty days. The notification must include a description of the breach, the nature of information that was acquired, accessed, used, or disclosed, and advice about what steps individuals should take to protect themselves from...

Read More
Who is Not Covered by OSHA?
Apr28

Who is Not Covered by OSHA?

The categories of workers not covered by federal OSHA include volunteers and temporary workers, self-employed workers, family members of farm workers, workers in industries regulated by an agency other than OSHA, and state and local government employees. However, in states with OSHA-approved State Plans, different regulations may apply. Volunteers & Temporary Workers Volunteers are generally not covered by OSHA – but there are exceptions. Volunteer firefighters may be covered by OSHA if they are remunerated for time spent serving the community, covered by workers’ compensation, or regarded as public employees by the state or local government with jurisdiction over the location they volunteer in. There are also some special cases in which an agency has adopted an OSHA standard as one of its own and included volunteers in the coverage. For example, when the Environmental Protection Agency adopted OSHA’s Hazardous Waste and Emergency Response standard, the Agency applied the standard to both paid and uncompensated workers. Temporary workers that are paid by either an employer or a...

Read More
Alternate Solutions Health Network Notifies Patients About May 2024 Email Breach
Apr28

Alternate Solutions Health Network Notifies Patients About May 2024 Email Breach

Email accounts have been compromised at four HIPAA-regulated organizations: Alternate Solutions Health Network in Ohio; Park Royal Hospital in Florida; 90 Degree Benefits in Minnesota; and the Charleston Fire Department in West Virginia. Almost 107,000 individuals have been affected. Alternate Solutions Health Network, Ohio Alternate Solutions Health Network, LLC, a Kettering, Ohio-based provider of home healthcare services, has identified unauthorized access to an employee’s email account that contained patient data. It is unclear for how long the threat actor had access to the account or when the breach was detected; however, it has taken almost a year for the affected individuals to be notified. Alternate Solutions Health Network explained in its substitute breach notice that the forensic investigation confirmed that the account was breached on or around May 30, 2024. When the breach was detected, the account was secured, and third-party cybersecurity professionals were engaged to investigate the incident. “After an extensive investigation and manual document review, we...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist