25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Rocky Mountain Gastroenterology Associates Data Breach Affects 366K Patients
Dec20

Rocky Mountain Gastroenterology Associates Data Breach Affects 366K Patients

Rocky Mountain Gastroenterology Associates has experienced a cyberattack that involved unauthorized access to the protected health information of more than 366,000 patients. Email incidents have been announced by Radiologic Medical Services and the law firm Ott Cone & Redpath. Rocky Mountain Gastroenterology Associates In November, Littleton, CO-based Rocky Mountain Gastroenterology Associates started notifying 366,491 patients about a hacking incident that was identified on September 13, 2024. Suspicious activity was identified within its network, and the investigation confirmed that a threat actor had accessed and potentially copied files containing patient data. The affected files were reviewed and found to contain patient data such as names, addresses, dates of birth, patient account numbers, medical record numbers, Social Security numbers, health insurance identification numbers, and health information such as diagnoses and treatment information. The types of information involved varied from individual to individual. Rocky Mountain Gastroenterology Associates has...

Read More
HHS-OIG Issues Updated Compliance Guidance for Nursing Facilities
Dec20

HHS-OIG Issues Updated Compliance Guidance for Nursing Facilities

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has released compliance program guidance for nursing facilities. The guidance document is the first release in a new set of industry segment-specific compliance program guidance (ICPG) documents that should be used in conjunction with the General Compliance Program Guidance (GCPG) that applies to all entities and individuals in healthcare. The purpose of the Nursing Facility ICPG is to help with risk identification and the implementation of an effective voluntary compliance program to improve the quality of care for using home residents and reduce risks to prevent fraud, waste, and abuse. The GCPG covers the seven elements of a compliance program and includes adaptations for small and large entities and other compliance considerations, whereas the nursing facility ICPG is tailored to compliance risk areas for the nursing facility industry segment and explains specific compliance measures that nursing facilities can take to reduce risk. The nursing facility ICPG updates previous guidance issued by...

Read More
Ascension Ransomware Attack Affects 5.6 Million Patients
Dec20

Ascension Ransomware Attack Affects 5.6 Million Patients

In May 2024, Ascension Health suffered a ransomware attack; however, it has taken months to determine how many individuals were affected. The data breach was reported to the HHS’ Office for Civil Rights (OCR) in July 2024 using a placeholder figure of 500 affected individuals, as is common when the HIPAA Breach Notification Rule reporting deadline is approaching, and the investigation and data review are ongoing. On or around December 19, 2024, the OCR data breach portal was updated and Ascension Health’s 500 estimate was changed to 5,599,699 records, which makes it the third largest healthcare data breach of the year, behind the Change Healthcare ransomware attack (100 million records) and the Kaiser Foundation Health Plan tracking technology data breach (13.4 million records). Ascension announced it was dealing with a cyberattack in May 2024, then issued an update in June confirming patient data was stolen in the attack; however, at that time it was unclear exactly what data types were involved and how many individuals had been affected. Since then, Ascension has been working...

Read More
HHS Publishes Final Rules Implementing Interoperability and Information Blocking Provisions
Dec19

HHS Publishes Final Rules Implementing Interoperability and Information Blocking Provisions

The Department of Health and Human Services (HHS) issued two final rules related to interoperability and information blocking. The final rules clarify when healthcare providers can provide electronic information and certain activities that are not considered information blocking, amend exceptions to previously published information blocking rules, and aim to make sharing health information easier and more secure. The first final rule was issued on December 11, 2024, and implements provisions related to the Trusted Exchange Framework and Common Agreement (TEFCA) that were proposed in August 2024 in the Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability  (HTI-2) proposed rule. TEFCA is a nationwide Federal framework required by the 21st Century Cures Act that allows healthcare organizations to easily share health information securely while allowing patients to control what information about them is shared. The provisions implemented by the final rule are intended to advance equity, innovation, and...

Read More
Is Qualtrics HIPAA Compliant?
Dec19

Is Qualtrics HIPAA Compliant?

The issue with answering the question is Qualtrics HIPAA compliant is that, although the “experience management” platform appears to support HIPAA compliance, configuring and using the platform in a HIPAA compliant manner looks more complicated than some Covered Entities will be comfortable with. For those who struggle with fancy terminology, Qualtrics is an online platform that enables businesses to create and send surveys, obtain customer/employee feedback, and address satisfaction issues using analytics and AI-powered automation. As an engagement and response tool, Qualtrics is a very advanced option. But is Qualtrics HIPAA compliant? Certainly, Qualtrics appears to be HIPAA compliant in its role as a Business Associate to a Covered Entity. It has multiple security certifications – including self-certified compliance with the HiTRUST CSF Framework – and is willing to enter into a Business Associate Agreement with a Covered Entity if the platform is going to be used for collecting, storing, or transmitting PHI. Qualtrics doesn’t provide previews of its Business...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist