25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New York Neurology Practice Pays $25,000 to Resolve Alleged Risk Analysis Violation
Apr28

New York Neurology Practice Pays $25,000 to Resolve Alleged Risk Analysis Violation

The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an alleged violation of the risk analysis implementation specification of the HIPAA Security Rule. Comprehensive Neurology PC, a small neurology practice in New York City that specializes in diagnosing and treating neurological conditions such as dementia, Parkinson’s disease, epilepsy, and memory loss, has agreed to settle the alleged violation and pay a $25,000 financial penalty. The alleged HIPAA violation was identified by OCR during an investigation of a 2020 data breach that involved unauthorized access to the electronic protected health information (ePHI) of 6,800 individuals. OCR was informed of the data breach on December 17, 2020. Comprehensive Neurology discovered it had been attacked with ransomware on December 14, 2020, when staff were prevented from accessing patients’ medical records. The forensic investigation confirmed that the ePHI of 6,800 individuals had been exposed and potentially stolen in the attack, including names, clinical information, health insurance information,...

Read More

Communication Between Doctors and Nurses

Accurate and efficient communication between doctors and nurses is a key component of providing high quality care to patients because, when there is not effective communication, care standards fall. Poor communication between doctors and nurses is common in hospitals, but there are strategies and technologies that can be adopted to improve communication between these two groups of healthcare professionals. Problems Arising from Poor Communication Effective communication is a key requirement to collaborative workflow in all industries, but more so in healthcare where there needs to be constant collaboration. Healthcare is now delivered by multidisciplinary teams that can include dozens of healthcare professionals across a week-long hospital stay. When there is poor communication between these healthcare professionals, patients ultimately suffer. That could mean a longer stay in hospital, a slower recovery, or a miscommunication could have far more serious consequences for the patient and the healthcare provider. According to research conducted by The Joint Commission (TJC), almost...

Read More
OSHA and HIPAA Compliance
Apr25

OSHA and HIPAA Compliance

Ensuring OSHA and HIPAA compliance simultaneously requires healthcare organizations to integrate workplace safety measures and health data privacy protections seamlessly, addressing the physical and digital aspects of healthcare while safeguarding both employee well-being and patient confidentiality. OSHA and HIPAA compliance are both essential despite being separate standards. Although separate, there are broad similarities in terms of reporting, recordkeeping, and enforcement. OSHA compliance requires implementing workplace safety measures to protect healthcare workers from hazards, such as exposure to infectious diseases, while also ensuring the safe handling of medical equipment and hazardous substances. This may include providing personal protective equipment (PPE), establishing protocols for handling biohazardous materials, and maintaining a safe environment within healthcare facilities. HIPAA compliance focusses on safeguarding the privacy and security of patient health information. It requires stringent controls on access to electronic health records (EHRs), secure data...

Read More
SOC 2 Compliance Checklist
Apr25

SOC 2 Compliance Checklist

A SOC 2 compliance checklist – also known as a SOC 2 audit checklist or SOC 2 assessment checklist – is a set of guidelines, measures, and best practices an organization can implement and follow to prepare for a SOC 2 audit. As the nature of SOC 2 audits can vary from organization to organization, there is no one-size-fits-all checklist for SOC 2 compliance. SOC 2 is a voluntary compliance standard developed in 2010 by the American Institute of Certified Public Accountants (AICPA). Organizations wishing to demonstrate compliance with the standard undergo an SOC 2 compliance audit conducted by an AICPA-certified public accountant or by an audit firm commissioned by AICPA. The resulting SOC 2 compliance report can then be shared with third parties to prove the organization has implemented controls to secure its systems and data. In the healthcare industry, an SOC 2 compliance report does not guarantee compliance with the standards of the HIPAA Security Rule because the controls mapped to the SOC 2 compliance audit are discretionary. Nonetheless, it can be beneficial for Covered...

Read More
ELENOR-Corp Ransomware Group Targets Healthcare with New Mimic Ransomware Variant
Apr25

ELENOR-Corp Ransomware Group Targets Healthcare with New Mimic Ransomware Variant

The healthcare sector is being targeted by a new ransomware group called ELENOR-corp, according to the cybersecurity firm Morphisec. Researchers determined that ELENOR-corp was using a new version of Mimic ransomware (version 7.5), a ransomware strain first identified in 2022. The new ransomware variant was identified during an incident investigation at a healthcare victim and appears to be linked to a previous Clipper malware infection. Clipper malware is a Python-based clipboard hijacker used for credential theft. The malware is thought to have allowed re-entry to the victim’s environment. The malware took daily snapshots of user activity and was installed along with a cryptocurrency miner. The researchers determined with a high degree of probability that Clipper malware had been deployed by the same threat actors. Initial access was gained around a week before the ransomware payload was deployed. After gaining access to the healthcare provider’s environment, the group moved laterally and compromised multiple servers via Remote Desktop Protocol (RDP), using tools such as Process...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist