25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

March 1, 2025: Deadline for Submitting 2024 Data Breach Reports to OCR
Feb04

March 1, 2025: Deadline for Submitting 2024 Data Breach Reports to OCR

The deadline for submitting reports of 2024 data breaches affecting fewer than 500 individuals to the HHS’ Office for Civil Rights (OCR) is March 1, 2025. Late filing of breach reports will put HIPAA-regulated entities at risk of a financial penalty for non-compliance with the HIPAA Breach Notification Rule. The HIPAA Breach Notification Rule requires HIPAA-regulated entities to report data breaches to OCR, issue notifications to the affected individuals, and – for breaches affecting 500 or more residents of a state or jurisdiction – notify prominent media outlets serving that state or jurisdiction. All notifications must be issued without unreasonable delay and no later than 60 days after the date of discovery of a data breach. If there is insufficient contact information for 10 or more individuals, a substitute breach notice must be placed on the home page of the entity’s website for at least 90 days or the notice must be provided to major print or broadcast media where the affected individuals likely reside. HIPAA-regulated entities have greater flexibility regarding...

Read More
Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals
Feb03

Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals

Cyberattacks have been reported by River Region Cardiology in Alabama and Delta County Memorial Hospital District in Colorado. Lucent Health Solutions in Tennessee has notified individuals who had their data exposed in an October 2, 2023 phishing attack. Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals River Region Cardiology in Alabama has recently notified approximately half a million current and former patients that some of their protected health information was compromised in a September 2024 security incident. Unauthorized access to its systems was detected on September 16, 2024, with the investigation confirming a hacker accessed the network via the remote connection used by an unnamed vendor. The vendor’s remote connection was severed when the unauthorized access was detected. The review of the exposed files confirmed they contained full names, dates of birth, Social Security numbers, and patients’ sex, height, and weight. The breach was reported to the HHS’ Office for Civil Rights on December 11, 2024, as involving the protected health information of...

Read More
Over 1 Million Patients Affected by Community Health Center Data Breach
Feb03

Over 1 Million Patients Affected by Community Health Center Data Breach

Community Health Center, a nonprofit healthcare provider in Middletown, Connecticut, has notified more than 1 million individuals about a recent data breach. Unauthorized activity was identified in its computer systems on January 2, 2025, and external cybersecurity experts were engaged to assist with the investigation and determine the nature and scope of the unauthorized activity. The investigation confirmed that a criminal hacker accessed its computer systems and exfiltrated data from its network. Community Health Center did not confirm whether a ransom demand was issued; however, explained that no data was deleted from its network and files were not encrypted, therefore the incident had no impact on daily operations. Community Health Center explained in the notification to the Maine Attorney General that “We believe we stopped the criminal hacker’s access within hours, and there is no current threat to our systems.” The Maine Attorney General breach notice states that the breach first occurred on October 14, 2024. The file review has now been completed and Community Health...

Read More
Is Google Drive HIPAA Compliant?
Feb03

Is Google Drive HIPAA Compliant?

Google Drive is HIPAA compliant if it is used as part of a paid-for Google Workspace plan with the capabilities to support HIPAA compliance, or if it is used as part of a Google Workspace plan that is combined with other security measures to support HIPAA compliance. The free version of Google Drive cannot be used to store or share Protected Health Information (PHI) What is Google Drive? Google Drive is a file storage and synchronization service that enables Google customers to store files in the cloud so they can be accessed and shared remotely. The service automatically synchronizes changes to files stored in the cloud to facilitate multi-user collaboration and multi-user editing. It can also be configured to enable teams to work on a project simultaneously. The service can be used as a standalone service or as a key component of a Google Workspace plan. Workspace plans include productivity tools such as Google Docs, Sheets, and Slides, and communication tools such as Google Meet, Chat, and Gmail. Depending on which plan is subscribed to, businesses also benefit from security and...

Read More

Is G Suite HIPAA Compliant?

G Suite is HIPAA compliant provided organizations subscribe to a Google Workspace Business Account that includes the capabilities to support HIPAA compliance and provided the capabilities are configured to support compliance with HIPAA. It will also be necessary for a system administrator to agree to Google’s Business Associate Addendum to the Service Agreement. Note: The name of G Suite was changed to Google Workspace in 2020. As many people still refer to Workspace under its former name, this article has been updated to reflect the changes since 2020 while still maintaining G Suite references. In June 2022, any organizations still using the former free G Suite legacy edition were migrated to a paid-for Google Workspaces subscription. Making G Suite HIPAA Compliant (by default it isn’t) When an organization subscribes to a G Suite (Workspace) account, there are four options to choose from. These start with the feature limited Business Starter Plan and go up to the G Suite Enterprise Plan. The choice of options depends on whether G Suite services will be used to create, collect,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist