25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Examples of PHI in Healthcare
Feb10

Examples of PHI in Healthcare

Examples of PHI in healthcare include any individually identifiable health information maintained by a covered entity or business associate that relates to an individual’s health condition, treatment for a health condition, or payment for treatment. Non-health information assumes the same protections as PHI only when it is maintained in the same designated record set as PHI. When the HIPAA Privacy Rule was published in 2000, it contained a list of eighteen identifiers that had to be removed from medical and billing records (“designated record sets”) under the “Safe Harbor” method of de-identification. Thereafter, any health information remaining in a designated record set was no longer considered “individually identifiable” and no longer protected by the HIPAA Privacy Rule. Some sources interpreted the list of identifiers as a definition of Protected Health Information (PHI). However, the identifiers do not qualify as individually identifiable health information because they do not relate to an individual’s health condition, treatment for a health condition, or payment for...

Read More
Data Breach at New York Medical Imaging Provider Affects 138,000 Patients
Feb10

Data Breach at New York Medical Imaging Provider Affects 138,000 Patients

Several data breaches have recently been reported to the HHS’ Office for Civil Rights and State Attorneys General that involved unauthorized access to individuals’ personal and protected health information. Affected HIPAA-regulated entities include University Diagnostic Medical Imaging, Newport Harbor Pathology Medical Group, and the Athens County Board of Developmental Disabilities. University Diagnostic Medical Imaging University Diagnostic Medical Imaging in New York is notifying 138,080 patients about a hacking incident that involved unauthorized access to its network for a short period on November 26, 2024. The unauthorized access was detected and blocked the same day, and a review was conducted to determine the types of information exposed and the individuals affected. That process has recently been completed and confirmed names, addresses, dates of birth, referring physician names, and medical diagnosis/treatment information have been exposed. University Diagnostic Medical Imaging said there is no reason to believe that any patient data has been or will be misused....

Read More
Is QuickBooks HIPAA Compliant?
Feb09

Is QuickBooks HIPAA Compliant?

QuickBooks is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information unless the desktop version of the software is used via a third party hosting service that supports HIPAA compliance. However, due to the cost of deploying QuickBooks Desktop on a third party hosting service, it may be better for healthcare providers to use a HIPAA compliant QuickBooks alternative. QuickBooks by Intuit is a popular accounting software solution – available as an online SaaS solution or a downloadable desktop solution – that offers a range of financial management packages for small and medium sized businesses. In addition to its own capabilities, QuickBooks Online integrates with hundreds of third party apps to increase payment options, accelerate payment processing, simplify tax reporting, and better analyze data. For businesses in the healthcare industry, QuickBooks can be used for budgeting, payroll management, financial reporting, and auditing. Time-tracking add-ons exist to support compliance with the Fair Labor Standards Act (FLSA) and...

Read More
HIPAA Compliant Appointment Reminders
Feb09

HIPAA Compliant Appointment Reminders

HIPAA compliant appointment reminders are communications with patients that must take into account any consent requirements or privacy restrictions and the channel of communication being used to remind the patient of the appointment. In addition to complying with HIPAA, appointment reminders must also comply with FCC regulations. The HIPAA Privacy Rule permits the use of Protected Health Information (PHI) to remind patients of appointments under the treatment, payment, and healthcare operations (TPO) provisions of §164.506. This is according to an FAQ published by the Department of Health and Human Services (HHS) in 2002. However, while the use of PHI is permitted, how much PHI can be disclosed may be subject to several factors, including: Who is receiving the appointment reminder? Have privacy restrictions been requested? How is the reminder being communicated? Does the reminder comply with FCC regulations? Who is Receiving the Appointment Reminder? In the context of how much PHI can be disclosed in HIPAA compliant appointment reminders, although the minimum necessary standard...

Read More
Is HoneyBook HIPAA Compliant?
Feb08

Is HoneyBook HIPAA Compliant?

HoneyBook is not HIPAA compliant and cannot be used to create, collect, store, or transmit electronic Protected Health Information if a healthcare provider qualifies as a HIPAA covered entity or provides services to or on behalf of a covered entity as a business associate. However, this does not mean HoneyBook cannot be used by healthcare providers at all. HoneyBook describes itself as a client flow management platform for small businesses. The description is  accurate inasmuch as the platform is a scaled down version of an enterprise CRM that can be used by small businesses to manage enquiries, schedule appointments, and automate workflows. HoneyBook can also be used for invoicing clients and accepting payments. Businesses that want more capabilities can upgrade to an Essentials or Premium Plan – both of which also support integrations with apps such as Calendly, Gmail, Outlook, QuickBooks, and Zapier. For many individual healthcare providers and small medical practices, these capabilities are usually sufficient for managing client flow and backroom client administration. When...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist