25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The Three Pillars of HIPAA Compliance
Nov12

The Three Pillars of HIPAA Compliance

The three pillars of HIPAA compliance are to develop, implement and continuously improve a HIPAA compliance program, a HIPAA training program, and an information technology security program. Achieving compliance with the Rules of the Health Insurance Portability and Accountability Act (HIPAA) can be a challenge for healthcare organizations and their business associates. The HIPAA Rules were developed to cover healthcare organizations of different types and sizes, so the Rules needed to be flexible to accommodate this diversity. They also needed to be capable of standing the test of time without requiring regular updates in response to changing technology and operating practices. While HIPAA sets standards for privacy, security, and administrative processes, the Rules can seem complex and often lack important details and they do not include an easy-to-follow HIPAA compliance checklist, so it’s no surprise that achieving and maintaining HIPAA compliance can be a daunting prospect. One of the biggest challenges for compliance professionals is interpreting the HIPAA Rules and...

Read More
Data Breaches Announced by New Jersey Rehabilitation Center & Rhode Island Orthopedic Practice
Nov12

Data Breaches Announced by New Jersey Rehabilitation Center & Rhode Island Orthopedic Practice

Cyberattacks involving unauthorized access to patient information have been reported by Physical Medicine & Rehabilitation Center in New Jersey and Orthopedics Rhode Island. The Physical Medicine & Rehabilitation Center In July 2024, the Physical Medicine & Rehabilitation Center in New Jersey experienced a cybersecurity incident that caused disruption to its network. Third-party digital forensics experts were engaged to investigate the incident and confirmed that an unauthorized third party had access to its network from July 8, 2024, to July 9, 2024, and during that time, accessed and potentially acquired files containing patient information. The types of information involved varied from patient to patient and may have included names along with one or more of the following: address, email address, phone number, date of birth, Social Security number, driver’s license/state ID number, credit/debit card number, treatment/diagnosis information, prescription information, provider name, date of service, patient ID, Medicare/Medicaid number, medical record number, treatment...

Read More
Health & Palliative Services of the Treasure Coast & Universal Health Corporation Suffer Email Breaches
Nov12

Health & Palliative Services of the Treasure Coast & Universal Health Corporation Suffer Email Breaches

Health & Palliative Services of the Treasure Coast in Florida and Universal Health Corporation in Virginia have discovered unauthorized access to their email systems and the exposure of patients’ protected health information. Health & Palliative Services of the Treasure Coast Health & Palliative Services of the Treasure Coast, a Florida-based provider of end-of-life care, has recently confirmed that 22,459 individuals had some of their personal and protected health information compromised in an email security incident. Suspicious activity was identified in an employee’s email account on February 27, 2024. A third-party cybersecurity firm was engaged to conduct an investigation and confirmed on April 15, 2024, that there had been unauthorized access to a single email account. The data mining process to identify the individuals affected and the types of data involved was completed on July 17, 2024; however, virtually none of the affected individuals had addresses on file. The final list of affected patients was manually reviewed, and that process was completed on...

Read More
Data Breaches Confirmed by South West Family Medicine Associates & Sango Family Dentistry
Nov11

Data Breaches Confirmed by South West Family Medicine Associates & Sango Family Dentistry

Cyberattacks have recently been confirmed by South West Family Medicine Associates in Texas and Sango Family Dentistry in Tennessee that involved unauthorized access to patient data. South West Family Medicine Associates South West Family Medicine Associates in Dallas, Texas, has notified 36,959 current and former patients and employees that some of their protected health information was compromised in an August security breach. Suspicious activity was identified within its network on August 7, 2024, and cybersecurity professionals were engaged to investigate the activity and confirmed that unauthorized individuals accessed its network and viewed or acquired files containing patient and employee information. The affected files were reviewed, and on October 24, 2024, it was confirmed that they contained patient and employee information including names, addresses and zip codes, dates of birth, Social Security numbers, driver’s license numbers, medical histories, lab results, diagnosis/condition information, medication information, passwords, passport numbers, personal identification...

Read More
Healthcare Providers Fined for Failing to Check the HHS-OIG Exclusions List
Nov11

Healthcare Providers Fined for Failing to Check the HHS-OIG Exclusions List

Two healthcare providers who employed individuals who had been excluded from participation in Federal healthcare programs have entered into settlement agreements with the Department of Health and Human Services Office of Inspector General (HHS-OIG). HHS-OIG is required by law to maintain an exclusions list of individuals who have been convicted of Medicaid/Medicaid fraud, SCHIP, state healthcare programs, patient abuse and neglect, felony convictions for other healthcare-related fraud, financial misconduct, theft, and unlawful manufacture, distribution, prescription, or dispensing of controlled substances. HHS-OIG also has the discretion to exclude individuals from Federal healthcare programs on other grounds, including a range of healthcare-related misdemeanor convictions, false claims submissions, and unlawful kickback arrangements. Healthcare organizations must routinely check the HHS-OIG List of Excluded Individuals/Entities (LEIE) to check that current employees and new hires have not been added to the LEIE. If a healthcare organization employs an excluded individual, they...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist