25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

City of Oakland Agrees Settlement to Resolve Class Action Data Breach Lawsuit
May07

City of Oakland Agrees Settlement to Resolve Class Action Data Breach Lawsuit

The City of Oakland in California has agreed to settle litigation stemming from a ransomware attack and data breach that affected more than 13,000 current and former employees. The attack was detected in February 2023, and notification letters were sent to the affected employees in early March 2023. The Play ransomware group claimed responsibility for the attack, which forced the city to shut down its IT systems, resulting in a state of emergency being declared in the city. The ransomware group released the stolen data on its data leak site when the city refused to pay the ransom. Among the leaked data was the personal information of individuals employed by the city between July 2010 and January 2022. The ransomware group gained access to the network after employees responded to phishing emails. Several lawsuits were filed in response to the breach, alleging the city was negligent by failing to implement appropriate safeguards to protect its network and data. The city maintains there was no wrongdoing; however, it agreed to settle the litigation to prevent further legal costs and...

Read More
OSHA to Hold Public Hearing on Proposed Heat Injury and Illness Standard
May07

OSHA to Hold Public Hearing on Proposed Heat Injury and Illness Standard

The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) is hosting a virtual public hearing on June 16, 2025, on its Notice of Proposed Rulemaking (NPRM) on Health Injury and Illness Prevention in Outdoor and Indoor Work Settings. The heat injury and illness NPRM was published in the Federal Register on August 30, 2024, and requires employers in all general industry, construction, maritime, and agriculture sectors to create a plan to evaluate and control heat hazards in the workplace and ensure that workers are adequately protected from hazardous heat levels in indoor and outdoor work settings. In the United States, heat is the leading cause of death out of all weather-related phenomena, yet prior to the heat injury and illness NPRM, there was no federal OSHA standard regulating heat stress hazards in the workplace, only guidance from governmental and non-governmental organizations on measures to protect workers. Exposure to excessive heat poses a significant risk of illness and injury. In many industries, workers are required to work through shifts with...

Read More
Horizon Behavioral Health Falls Victim to Ransomware Attack
May06

Horizon Behavioral Health Falls Victim to Ransomware Attack

Data breaches have been announced by Horizon Behavioral Health, BayMark Health Services, Carlton County Public Health and Human Services, the City of Bristol in Tennessee, and Schewitz Psychological Services (Couples Learn). Horizon Behavioral Health Horizon Behavioral Health, a Lynchburg, VA-based provider of mental health, substance use, and intellectual disability services in Central Virginia, has fallen victim to a ransomware attack. The attack was detected on March 16, 2025, when computer systems were disrupted. Immediate action was taken to try to contain the attack and prevent further unauthorized access, and a forensic investigation was launched to determine the extent of the compromise. Horizon Behavioral Health determined that a ransomware group had access to its network between March 13, 2025, and March 16, 2025, during which time sensitive data may have been viewed or acquired by the ransomware group. The file review confirmed that the affected data included names, Social Security numbers, addresses, ZIP codes, driver’s license numbers, dates of birth,...

Read More
Federal Judge Vacates FDA’s Final Rule Reclassifying Laboratory-Developed Tests as Medical Devices
May06

Federal Judge Vacates FDA’s Final Rule Reclassifying Laboratory-Developed Tests as Medical Devices

A Federal judge recently vacated a Final Rule proposed by the U.S. Food and Drug Administration (FDA) that sought to reclassify laboratory-developed tests (LDTs) as medical devices, thus regulating the LDTs under the Federal Food, Drug, and Cosmetic Act (FDCA). The rule was first proposed by the FDA on October 3, 2024, and a final rule was added to the Federal Register on May 6, 2024. Prior to the Final Rule, the FDA exercised general enforcement discretion for LDTs, with action only taken against an LDT if it was thought to have resulted in inaccurate diagnoses. LDTs are generally not sold to other laboratories and are used internally to help provide diagnoses from samples sent to the laboratory by a healthcare provider. LDTs are subjected to robust testing to ensure they are accurate and reliable before they are used for diagnostic purposes, and laboratories were already regulated by the Centers for Medicare and Medicaid Services (CMS) under the Clinical Laboratory Improvement Amendments of 1988 (CLIA). The Final Rule reclassified LDTs as medical devices, which means that they...

Read More
Is JotForm HIPAA Compliant?
May05

Is JotForm HIPAA Compliant?

JotForm is HIPAA compliant and can be used to collect, store, and share Protected Health Information (PHI) provided businesses subscribe to a Gold or Enterprise plan and agree to the terms of JotForm’s Business Associate Agreement. Existing subscribers with a Starter, Bronze, or Silver plan must upgrade their plan to use JotForm in compliance with HIPAA. JotForm is a software solution for creating online forms that can be used in the healthcare industry to simplify the collection and documentation of PHI. Use cases include collecting PHI during the patient intake process, documenting patient consent and authorizations, soliciting patient feedback, and scheduling appointments via forms embedded into a web page or patient portal. JotForm integrates with multiple HIPAA compliant productivity and collaboration tools (i.e., OneDrive, Google Workspace, Salesforce, etc.) to streamline workflows and increase efficiency. Through these integrations, it is also possible to transmit PHI to EHRs or other systems to improve the patient experience. However, in order to use the software solution...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist