25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Colorado Fertility Center Ransomware Attack Affects 80,000 Patients
Jan03

Colorado Fertility Center Ransomware Attack Affects 80,000 Patients

Conceptions Reproductive Associates of Colorado has suffered a ransomware attack, hacking incidents have been reported by Lexington Diagnostic Center, In-Home Attendant Services, and Youth Eastside Services, and email accounts have been compromised at Summit Medical Group. Conceptions Reproductive Associates of Colorado The fertility clinic, Conceptions Reproductive Associates of Colorado, has recently confirmed that it was the victim of a ransomware attack that involved unauthorized access to its network and the theft of the information of up to 80,000 current and former patients and their partners. The incident was detected in mid-April when disruption was caused to some of its legacy computer systems. Incident response procedures were immediately implemented, the intrusion was reported to law enforcement, and an investigation was launched to determine the nature and extent of the unauthorized activity. The investigation confirmed that the ransomware group gained access to certain legacy systems earlier in the month and exfiltrated data. The file review has recently been...

Read More
HIPAA Administrative Safeguards
Jan02

HIPAA Administrative Safeguards

Compared to the specific HIPAA administrative safeguards of the Security Rule (the Administrative, Physical, and Technical Safeguards), most other references to safeguards in the text of HIPAA are intentionally flexible to accommodate the different types of covered entities and business associates that have to comply with them. While this flexibility means it can be easier for some organizations to comply with the HIPAA safeguards, other organizations may find the lack of direct guidance unhelpful. To demonstrate the difference between the safeguards of the Security Rule and the safeguards of the Privacy Rule, we have provided a synopsis of the Security Rule Administrative, Physical, and Technical Safeguards to compare against the safeguards mentioned in the Privacy Rule Administrative Requirements. There is also a section relating to the Organization Requirements of the Privacy and Security Rules – both of which include further HIPAA administrative safeguards. HIPAA Security Rule Safeguards The HIPAA Security Rule is dominated by the Administrative, Physical, and Technical...

Read More
Does HIPAA Apply to Animals?
Jan02

Does HIPAA Apply to Animals?

HIPAA does apply to animals if details of an animal could be used to identify the subject of Protected Health Information maintained in the same designated record set by a covered entity or business associate. However, HIPAA does not apply to animals in all other circumstances – including when details of animals are maintained in a veterinary medical record. The most common answer to the question does HIPAA apply to animals is “no”, because the HIPAA Administrative Simplification Regulations apply to Protected Health Information created, received, maintained, or transmitted by a covered entity or business associate that relates to an individual’s health condition, treatment for the health condition, or payment for the treatment. An “Individual” is defined in HIPAA (§160.103) as “the person who is the subject of the Protected Health Information”, and “person” is defined as “a human who is born alive”. This would imply that HIPAA does not apply to animals. However, there are circumstances in which information about an animal could assume the same protections as Protected Health...

Read More
Indiana AG Agrees to $350,000 Penalty to Resolve Egregious HIPAA Violations
Jan02

Indiana AG Agrees to $350,000 Penalty to Resolve Egregious HIPAA Violations

An Indianapolis dental practice has agreed to pay a financial penalty of $350,000 to the Office of the Indiana Attorney General (OIG) to resolve multiple alleged violations of federal and state laws related to an unreported October 2020 ransomware attack and data breach. Several dental practices operate under the name Westend Dental, including Westend Dental LLC, Arlington Westend Dental LLC, Sherman Westend Dental LLC, Fountain Square Westend Dental LLC, Lafayette Westend Dental LLC, and Affordable Westend Dental LLC, all of which are owned by Dr. Pooja Mandalia D.D.S. The Indiana OIG initiated an investigation of Westend Dental following a complaint from a patient who had requested a copy of their dental records, which could not be provided due to a hacking incident. The Indiana OIG investigation uncovered evidence that Westend Dental had experienced a ransomware attack on or around October 20, 2020, involving state residents’ protected health information. Westend Dental submitted a data breach notification form to the Indiana OIG on October 28, 2022, more than two years...

Read More
What is TPA in Healthcare?
Jan01

What is TPA in Healthcare?

TPA in healthcare stands for Third Party Administrator – most often a state-licensed individual or organization that acts as an independent intermediary between an employer’s self-funded health plan and healthcare providers. Although independent, the purpose of a TPA in healthcare is to support self-funded health plans by managing administrative tasks and processes on health plans’ behalf. Most employers with fifty or more full-time employees – including full-time equivalent (FTE) employees – are required to provide health insurance under the Affordable Care Act (ACA). Those with fewer than fifty FTE employees may choose to provide health insurance in order to attract and retain employees, or to benefit from Small Business Health Care Tax Credits or the Small Business Health Options Program (also known as the SHOP Marketplace). To comply with ACA, private sector employers have several health plan options. These include, but are not limited to: Fully insured employer-sponsored health plans, in which employers pay a fixed premium to a commercial insurance carrier that...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist