25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The HIPAA Breach Notification Rule

The Health Insurance Portability and Accountability Act of 1996 is one of the most important pieces of legislation to affect the healthcare industry, yet many healthcare providers and insurers are unaware of HIPAA obligations, in particular those relating to the HIPAA Breach Notification Rule. There has been considerable criticism of healthcare providers and insurance companies in recent months regarding the speed at which individuals affected by data breaches are notified that their healthcare data and personal information have been stolen, lost, or divulged to an unauthorized individual. With this in mind, and given the rise in the number of HIPAA data breaches in recent months, we have prepared a summary of the important elements of the HIPAA Breach Notification Rule to help healthcare organizations respond quickly to data breaches and stay HIPAA-compliant. Summary of the HIPAA Breach Notification Rule HIPAA Rules set standards that healthcare providers and other covered entities must follow in order to reduce the chance of patient data being exposed; however, even with the most...

Read More
Medical Practice Marketing
Dec20

Medical Practice Marketing

An effective medical practice marketing strategy can help ensure a consistent flow of new patients and maintain relationships with existing patients in order to support growth and profitability. However, when developing and executing a medical practice marketing strategy, it is important not to overlook regulatory requirements. Medical practice marketing has come a long way in the past quarter of a century. Twenty-five years ago, larger healthcare organizations dominated medical marketing due to having sizeable marketing teams, large advertising budgets, and significant purchasing power. Since then, the growth of the Internet has levelled the playing field, and now organizations of all sizes have the same marketing opportunities. Nonetheless, it is not always easy for smaller medical practices to take advantage of the opportunities. Some may have limited resources to dedicate to building a website, maintaining a blog, and promoting the website via social media. Others may have the resources, but not the knowledge to develop and execute an effective medical practice marketing...

Read More
Rocky Mountain Gastroenterology Associates Data Breach Affects 366K Patients
Dec20

Rocky Mountain Gastroenterology Associates Data Breach Affects 366K Patients

Rocky Mountain Gastroenterology Associates has experienced a cyberattack that involved unauthorized access to the protected health information of more than 366,000 patients. Email incidents have been announced by Radiologic Medical Services and the law firm Ott Cone & Redpath. Rocky Mountain Gastroenterology Associates In November, Littleton, CO-based Rocky Mountain Gastroenterology Associates started notifying 366,491 patients about a hacking incident that was identified on September 13, 2024. Suspicious activity was identified within its network, and the investigation confirmed that a threat actor had accessed and potentially copied files containing patient data. The affected files were reviewed and found to contain patient data such as names, addresses, dates of birth, patient account numbers, medical record numbers, Social Security numbers, health insurance identification numbers, and health information such as diagnoses and treatment information. The types of information involved varied from individual to individual. Rocky Mountain Gastroenterology Associates has...

Read More
HHS-OIG Issues Updated Compliance Guidance for Nursing Facilities
Dec20

HHS-OIG Issues Updated Compliance Guidance for Nursing Facilities

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has released compliance program guidance for nursing facilities. The guidance document is the first release in a new set of industry segment-specific compliance program guidance (ICPG) documents that should be used in conjunction with the General Compliance Program Guidance (GCPG) that applies to all entities and individuals in healthcare. The purpose of the Nursing Facility ICPG is to help with risk identification and the implementation of an effective voluntary compliance program to improve the quality of care for using home residents and reduce risks to prevent fraud, waste, and abuse. The GCPG covers the seven elements of a compliance program and includes adaptations for small and large entities and other compliance considerations, whereas the nursing facility ICPG is tailored to compliance risk areas for the nursing facility industry segment and explains specific compliance measures that nursing facilities can take to reduce risk. The nursing facility ICPG updates previous guidance issued by...

Read More
Ascension Ransomware Attack Affects 5.6 Million Patients
Dec20

Ascension Ransomware Attack Affects 5.6 Million Patients

In May 2024, Ascension Health suffered a ransomware attack; however, it has taken months to determine how many individuals were affected. The data breach was reported to the HHS’ Office for Civil Rights (OCR) in July 2024 using a placeholder figure of 500 affected individuals, as is common when the HIPAA Breach Notification Rule reporting deadline is approaching, and the investigation and data review are ongoing. On or around December 19, 2024, the OCR data breach portal was updated and Ascension Health’s 500 estimate was changed to 5,599,699 records, which makes it the third largest healthcare data breach of the year, behind the Change Healthcare ransomware attack (100 million records) and the Kaiser Foundation Health Plan tracking technology data breach (13.4 million records). Ascension announced it was dealing with a cyberattack in May 2024, then issued an update in June confirming patient data was stolen in the attack; however, at that time it was unclear exactly what data types were involved and how many individuals had been affected. Since then, Ascension has been working...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist