25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Lawsuit Filed Against Rhode Island HIE by Whistleblower Who Alleged Impermissible Uses of HIE Data
Feb07

Lawsuit Filed Against Rhode Island HIE by Whistleblower Who Alleged Impermissible Uses of HIE Data

A lawsuit has been filed against the Rhode Island Quality Institute (RIQI) by a former HIPAA officer who alleges she was terminated for blowing the whistle on impermissible disclosures of HIE data. RIQI is a Rhode Island state government contractor and was the operator of the state health information exchange (HIE) – CaseCurrent – from 2021 to July 2024, when the contract was awarded to another vendor. Darlene Morris first started working for RIQI in 2012 in the role of Manager of the Electronic Health Record Adoption Program. Morris was promoted on several occasions and was appointed Senior Director, Programs in 2019. Two years later she started serving as RIQI’s HIPAA Privacy Officer and, in 2023, her job title was changed to Senior Director, Risk Management & Compliance/HIPAA Compliance Officer. In that role, Morris reported to RIQI’s President and CEO, Dr. Indra Neil Sarkar. Morris remained in that role until July 2024 when she was terminated. Dr. Sarkar was appointed to the position of President and CEO of RIQI in 2020, after serving as the interim President and CEO. Dr....

Read More
Hospital Sisters Health System: August 2023 Data Breach Affected 883K Individuals
Feb07

Hospital Sisters Health System: August 2023 Data Breach Affected 883K Individuals

Hospital Sisters Health System (HSHS) in Springfield, IL, and Prevea Health in Green Bay, WI, were affected by a cyberattack in late August which caused an outage on August 27, 2023, that affected their computer systems, phone lines, and websites. The outage lasted for several days, during which time HSHS and Prevea operated under downtime procedures. The attack took its websites and certain applications offline, including the MyChart and MyPrevea applications. HSHS was also unable to process online payments as its computer system was offline, but care continued to be provided to patients. HSHS decided to suspend collecting payments for outstanding bills while it was recovering from the attack, although some of its partners in Illinois and Wisconsin continued to send bills to patients. In early September, HSHS published an open letter to patients warning them about the potential misuse of their information, as reports had been received from some patients who had been contacted by email, SMS, and phone by an unidentified third party that claimed to be an HSHS representative who was...

Read More
Is WebEx HIPAA Compliant?
Feb06

Is WebEx HIPAA Compliant?

Webex is HIPAA compliant and, provided policies relating to disclosures are complied with, can be used to disclose PHI during videoconference calls between healthcare providers or during telehealth calls between providers and patients. It is also important the platform is configured to support HIPAA compliance and that a Business Associate Agreement is in place with Webex by Cisco. What is Webex? Webex by Cisco is a web and video conferencing and collaboration platform that helps businesses connect with remote workers and partners as if they are in the same room. With tools such as Webex, healthcare organizations can communicate quickly and easily with the workforce, no matter where employees are located. Regional operational meetings can be conducted, medical education can take place online, and healthcare employees can be trained on new processes and procedures. These platforms can also potentially be used for communicating with patients. However, before any collaboration tools can be used in connection with protected health information (PHI), healthcare organizations must be...

Read More
What is Cal/OSHA Compliance?
Feb06

What is Cal/OSHA Compliance?

Cal/OSHA compliance means complying with all applicable workplace safety and health regulations adopted by California’s Occupational Safety and Health Standards Board and enforced by the Department of Industrial Relations’ Division of Occupational Safety and Health. Prior to the passage of the Occupational Safety and Health Act in 1970, many States had already enacted workplace safety and health regulations. Consequently, Section 18 of the OSH Act permits States to develop their own OSHA plans based on existing safety and health regulations – provided the State Plans are at least as effective as the federal OSHA program. California was one of the first States to develop an OSHA State Plan. In 1973, the California Occupational Safety and Health Act established the Occupational Safety and Health Standards Board. The Board was tasked with adopting safety and health standards for California, or adopting federal OSHA standards if no existing State standard covered the same issue. The responsibility for enforcing the California OSHA State Plan was delegated to the Division of...

Read More
2024 Saw Increase in Ransomware Attacks but 35% Decrease in Payments
Feb06

2024 Saw Increase in Ransomware Attacks but 35% Decrease in Payments

A blockchain analysis suggests an increasing reluctance to pay money to ransomware groups. A new report from Chainalysis revealed a 35% year-over-year decline in ransom payments, which fell from $1.25 billion in 2023 to $813,550,000 in 2024 – the second-lowest annual total in the past 5 years behind the $655.44M paid in 2022. In the first half of 2024, the number of additions to ransomware groups’ data leak sites increased by 2.38% compared to the corresponding period in 2023, and attacks continued to increase in H2 reaching a peak in November 2024; however, November saw the lowest number of ransom payments of the year. Over the entire year, fewer than half of victims of ransomware attacks ended up paying the ransom. When companies are presented with a ransom demand, contact is often made with the cybercriminal group and ransom negotiations commence. Ransomware groups appear more willing to negotiate payments and accept lower amounts, with the median ransom payment falling in 2024; however, fewer than one-third (30%) of companies that initiated negotiations ended up paying a...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist