25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Permitted Disclosures
Mar06

HIPAA Permitted Disclosures

The HIPAA permitted disclosures of PHI are summarized in §164.502 of the Privacy Rule, with more details about each type of permitted disclosure (i.e., to Business Associates, etc.) being provided in §§164.504-164.514 of the Privacy Rule. It is important for covered entities and business associates to be aware of HIPAA permitted disclosures to avoid unintentional violations of HIPAA.   According to the Privacy Rule, covered entities must disclose PHI in only two scenarios – 1) when a patient requests access to their PHI or an accounting of disclosures, and 2) when the Department of Health and Human Services (HHS) conducts a review or a compliance investigation, or undertakes enforcement action. In neither scenario is patient authorization necessary. Other Disclosures Permitted by the HIPAA Privacy Rule Thereafter, covered entities are permitted, but not required, to disclose PHI without patient authorization for the following purposes or situations: To the Individual The Privacy Rule states that, except for the required HIPAA permitted disclosures for patient access or accounting...

Read More

HIPAA Compliance for Insurance Brokers

HIPAA compliance for insurance brokers acting on behalf of a HIPAA-covered health plan consists of complying with the HIPAA Security and Breach Notification Rules and any parts of the HIPAA Administrative Simplification Regulations relevant to their activities on behalf of a health plan. Medical insurance brokers do not meet the definition of a HIPAA Covered Entity because, although they may create, receive, or maintain individually identifiable health information, they do so on behalf of a health plan. Under HIPAA, the health plan is the Covered Entity, and the insurance broker – acting as an intermediary between the health plan and the plan member – is a Business Associate. As a Business Associate, HIPAA compliance for insurance brokers consists of complying with the HIPAA Security Rule and any Privacy Rule and Breach Notification requirements included in a Business Associate Agreement. However, insurance brokers can act as intermediaries for multiple health plans simultaneously – each of which may have unique Business Associate requirements. HIPAA Training for Business...

Read More
Survey Confirms Majority of Healthcare Orgs Plan to Increase Cybersecurity Investment
Mar06

Survey Confirms Majority of Healthcare Orgs Plan to Increase Cybersecurity Investment

An annual survey of healthcare leaders by the Healthcare Information and Management Systems Society (HIMSS) has revealed that more than half of healthcare organizations (55%) plan to increase cybersecurity spending in 2025. Twenty-one percent say budgets are largely unchanged year over year, and four percent plan to spend less on cybersecurity than in 2024. This year’s HIMSS Healthcare Cybersecurity Survey was conducted on 273 healthcare cybersecurity professionals, 50% of whom were in executive management, 37% in non-executive management, and 13% in non-management roles. 46% of respondents had primary responsibility for cybersecurity, 30% had some responsibility, and 24% sometimes had responsibility, as needed.  The survey was conducted between November 6, 2024, and December 16, 2024, and asked questions about cybersecurity spending and cybersecurity experiences over the previous 12 months. Historically, healthcare organizations have invested 6% or less of their IT budgets in cybersecurity; however, more money is now being spent on cybersecurity improvements, with 30% of...

Read More
Rite Aid Settles Data Breach Lawsuit for $6.8 Million
Mar06

Rite Aid Settles Data Breach Lawsuit for $6.8 Million

Rite Aid has agreed to settle a class action lawsuit over a June 2024 data breach that involved the personal information of approximately 2.2 million customers. Class members can claim up to $10,000 as reimbursement for documented expenses incurred as a result of the data breach. On June 6, 2024, the RansomHub ransomware group gained access to some of its computer systems, exfiltrated sensitive data, and encrypted files. According to Rite Aid, the breach was identified within 12 hours, but not in time to prevent the theft of customer data. The stolen data related to customers who made purchases between June 6, 2017, and July 30, 2017, and included names, addresses, dates of birth, driver’s license numbers, and other ID documents. The affected individuals were offered complimentary credit monitoring and identity theft protection services for 12 months. Several lawsuits were filed in response to the data breach that asserted similar claims. The lawsuits were consolidated into a single action – Margaret Bianucci v. Rite Aid Corporation – in the U.S. District Court for the Eastern...

Read More
Supreme Court Declines Petition to Take on Data Breach Case Against South Carolina FQHC
Mar06

Supreme Court Declines Petition to Take on Data Breach Case Against South Carolina FQHC

The Supreme Court has declined to hear a case about whether a Federally Qualified Health Center (FQHC) is immune from liability over data breach that exposed the personally identifiable information of patients. Sandhills Medical Foundation is an FQHC that serves patients in the Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina. Sandhills used a vendor (Netgain Technologies) for electronic storage of its scheduling, billing, and reporting systems. The vendor notified Sandhills on January 8, 2021, about a ransomware attack on November 15, 2020. The ransomware group used compromised credentials to access its systems and steal sensitive data. Ransomware was deployed on December 3, 2020. According to Sandhills, the breach involved the information of 39,602 patients. Health information was not compromised, although claims information may have allowed an attacker to determine diagnoses and conditions. The information stolen in the attack included names, dates of birth, mailing and email addresses, driver’s licenses, and Social Security numbers. One of the affected...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist