25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Explains Department’s Key Priorities at HHS-NIST Conference
Oct28

OCR Explains Department’s Key Priorities at HHS-NIST Conference

Last week, the Department of Health and Human Services (HHS) and the National Institute for Standards and Technology (NIST) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2024 conference after a 5-year absence. Attendees learned about the current cybersecurity landscape in healthcare, how compliance with the HIPAA Security Rule can help HIPAA-regulated entities combat cyber threats, and were provided with practical tips and techniques for implementing the requirements of the HIPAA Security Rule. On October 24, 2024, in a keynote speech, OCR Director Melanie Fontes Rainer provided an update on OCR’s main priorities. One of the key priorities is an update to the HIPAA Security Rule to add new cybersecurity requirements. OCR has been working on an update to the HIPAA Security Rule this year and has now finalized its proposed rule. The proposed rule is now being reviewed by the Office of Management and Budget (OMB) and Fontes Rainer anticipates publishing a Notice of Proposed Rulemaking (NPRM) before the end of the year. Fontes Rainer did not...

Read More
Healthcare Compliance Teams Stretched Thin Due to Complex Regulations and New Risks
Oct28

Healthcare Compliance Teams Stretched Thin Due to Complex Regulations and New Risks

New compliance requirements are on the horizon as the HHS’ Office for Civil Rights (OCR) expects to publish a notice of proposed rulemaking later this year to update the HIPAA Security Rule with new cybersecurity requirements, but healthcare compliance professionals are already struggling to comply with existing regulations, according to a recent report from the Indianapolis, IN-based business law firm Barnes & Thornburg. For its 2025 Healthcare Compliance Outlook Report, the law firm surveyed 120 compliance, risk, and legal leaders at U.S.-based healthcare and life sciences organizations, including health systems, pharma firms, biotech companies, and medical device manufacturers. The survey revealed a majority of the respondents felt stretched thin due to the current complex regulatory landscape and expanding areas of risk, including increasingly sophisticated cyberattacks, the rapid adoption of artificial intelligence (AI) solutions, and increased scrutiny of mergers and acquisitions. Only 31% of surveyed compliance, risk, and legal professionals felt they were very prepared...

Read More

More Than 50% of Healthcare Employees Fail a HIPAA Assessment, New Data Reveals

Businesses in the healthcare sector have a responsibility to minimise the risks of HIPAA violations, for the sake of their patients, staff and the organization as a whole. One way in which organizations can mitigate internal breaches is by ensuring that staff receive regular HIPAA training. However the number of internal breaches recorded each year would suggest that more needs to be done to ensure employees are HIPAA compliant. To investigate the standards of HIPAA training in the healthcare sector, The HIPAA Journal researchers have examined HIPAA assessment fail rates, the percentage of staff who have witnessed HIPAA violations, and how frequently training is being conducted in 2023. How many employees working with PHI fail a HIPAA assessment? More than half of employees working in the healthcare sector fail a HIPAA assessment. The data suggests that more than 50% of staff working with PHI do not have a comprehensive understanding of HIPAA regulations, and therefore require more training. Which area of HIPAA training sees the highest fail rates? During a HIPAA assessment in...

Read More

HIPAA Compliant Remote Access Software

HIPAA compliant remote access software provides HIPAA-covered entities and their busines associates with a secure way of remotely accessing systems containing electronic protected health information (ePHI) and simplifies the management of remote access. Healthcare organizations can have dozens of vendors who require remote access to servers, applications, and healthcare data, and oftentimes several different methods are used to provide access to vendors. Without a single solution, management of remote access is time consuming, complex, and difficult to carefully control. Healthcare employees also need remote access to applications, files, and ePHI and remote access has become even more important in the COVID-19 era. To reduce the risk of infection and help control the spread of COVID-19, there has been a major expansion of telehealth services. Healthcare professionals are now conducting more visits virtually and need to remotely access applications, EHRs, and files to provide those telehealth services. Windows Remote Desktop Protocol can be used for remote access, but RDP is not...

Read More
Healthcare Data Breaches Reported in New York, Florida, & Arkansas
Oct25

Healthcare Data Breaches Reported in New York, Florida, & Arkansas

Data breaches have recently been reported by Advanced Recovery Equipment & Supplies in New York, We Level Up Treatment in Florida, and Arkansas Blue Cross and Blue Shield. Advanced Recovery Equipment & Supplies, New York Advanced Recovery Equipment & Supplies, a New York-based supplier of medical recovery products, has identified a breach of its network and the theft of files containing customer data. The forensic investigation confirmed that an unauthorized third party accessed its network between June 27, 2023, and July 28, 2023, and removed files from the network. Assisted by third-party specialists, Advanced Recovery Equipment & Supplies conducted a comprehensive review of the affected files, which concluded on September 29, 2024. The files exfiltrated from its network included the protected health information of 56,000 individuals. Data compromised in the incident included names along with one or more of the following: Social Security number, date of birth, driver’s license number/state identification number, credit or debit card information, username and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist