25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Google Drive HIPAA Compliant?
Feb03

Is Google Drive HIPAA Compliant?

Google Drive is HIPAA compliant if it is used as part of a paid-for Google Workspace plan with the capabilities to support HIPAA compliance, or if it is used as part of a Google Workspace plan that is combined with other security measures to support HIPAA compliance. The free version of Google Drive cannot be used to store or share Protected Health Information (PHI) What is Google Drive? Google Drive is a file storage and synchronization service that enables Google customers to store files in the cloud so they can be accessed and shared remotely. The service automatically synchronizes changes to files stored in the cloud to facilitate multi-user collaboration and multi-user editing. It can also be configured to enable teams to work on a project simultaneously. The service can be used as a standalone service or as a key component of a Google Workspace plan. Workspace plans include productivity tools such as Google Docs, Sheets, and Slides, and communication tools such as Google Meet, Chat, and Gmail. Depending on which plan is subscribed to, businesses also benefit from security and...

Read More

Is G Suite HIPAA Compliant?

G Suite is HIPAA compliant provided organizations subscribe to a Google Workspace Business Account that includes the capabilities to support HIPAA compliance and provided the capabilities are configured to support compliance with HIPAA. It will also be necessary for a system administrator to agree to Google’s Business Associate Addendum to the Service Agreement. Note: The name of G Suite was changed to Google Workspace in 2020. As many people still refer to Workspace under its former name, this article has been updated to reflect the changes since 2020 while still maintaining G Suite references. In June 2022, any organizations still using the former free G Suite legacy edition were migrated to a paid-for Google Workspaces subscription. Making G Suite HIPAA Compliant (by default it isn’t) When an organization subscribes to a G Suite (Workspace) account, there are four options to choose from. These start with the feature limited Business Starter Plan and go up to the G Suite Enterprise Plan. The choice of options depends on whether G Suite services will be used to create, collect,...

Read More
HIPAA Compliant Computer Disposal
Feb03

HIPAA Compliant Computer Disposal

The requirement for HIPAA compliant computer disposal applies to any electronic device that is used to create, receive, maintain, transmit or access electronic Protected Health Information (ePHI), and any electronic media on which ePHI has been stored. However, although the HIPAA Security Rule states what the requirement is, guidance to support compliance with the requirement is long out of date. When the HIPAA Security Rule was published, it was deliberately technology neutral. Consequently, many of the standards and implementation specifications are just as applicable now as they were then. This has the advantage of supporting consistency in HIPAA compliance, but also has the disadvantage of creating compliance issues when guidance published to support compliance is out of date. The requirement for HIPAA compliant computer disposal – and the guidance provided to support the requirement – are an example of when taking a twenty year old implementation specification out of context can create a compliance issue. This is because the only implementation specification relating to...

Read More

21st Century Cures Act Compliance for HIPAA Covered Entities

Although the 21st Century Cures Act did not directly amend HIPAA, subsequently Rulemaking could create Cures Act compliance challenges for HIPAA covered entitieswith regards to individuals’  access to ePHI via APIs and the security risks that may involve. This article looks at some of the potential challenges and discusses what covered entities can do to overcome them. The challenges include: Information Blocking Interoperability Patient Access Compliance Costs Security Concerns Legal and Regulatory Understanding Workforce Training Technology Integration Public Perception and Trust Vendor Management The 21st Century Cures Act, enacted in the United States in 2016 “to accelerate the discovery, development, and delivery of 21st century cures and for other purposes”, was designed to support medical product development and bring new innovations and advances to patients who need them faster and more efficiently. Title IV of the Act instructed the Secretary of Health and Human Services (HHS) and the Office of the National Coordinator (ONC) to develop standards to accelerate the exchange...

Read More
Does HIPAA Apply to Workers Comp?
Feb02

Does HIPAA Apply to Workers Comp?

HIPAA does not apply to workers comp inasmuch as workers compensation insurers and administrative agencies are not required to comply with the HIPAA Administrative Simplification Requirements. However, HIPAA does apply to disclosures of Protected Health Information by HIPAA covered entities for workers comp purposes. HIPAA does not apply to workers comp because, when Congress passed the Health Insurance Portability and Accountability Act in 1996, it adopted the “excepted benefits” clause of the Public Health Service Act (42 USC 300gg-91(c)(1)). Among other excepted benefits, workers’ compensation and similar insurance were listed as “benefits not subject to requirements”. Consequently, when the Department of Health and Human Services published the HIPAA Administrative Simplification Requirements and the original HIPAA Privacy Rule in 2000, policies, plans, and programs that provided or paid for the cost of excepted benefits – including workers compensation – were excluded from the definition of a health plan (45 CFR §160.103). This means that workers compensation...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist