25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Arisa Health Confirms Data Breach Affected More Than 375,000 Patients
Aug05

Arisa Health Confirms Data Breach Affected More Than 375,000 Patients

Arisa Health Incorporated in Arkansas has experienced a breach of the protected health information of 375,436 individuals. Cyberattacks and data breaches have also been reported by Sun City Pediatrics in Texas and Calibrated Healthcare in California. Arisa Health Incorporated Arisa Health Incorporated, an Arkansas-based integrated behavioral health system, has started notifying hundreds of thousands of patients about a recent cyberattack. The attack was detected on or around March 18, 2024, when connectivity to its network was disrupted. The forensic investigation confirmed that unauthorized individuals had access to its network between March 1, 2024, and March 18, 2024, and there may have been unauthorized access to files containing sensitive patient data. Those files may also have been exfiltrated from the network in the attack. The review of those files confirmed that the following data had been exposed: full names, addresses, email addresses, dates of birth, Social Security numbers, medical record numbers, health insurance numbers/Member IDs, certification of substance abuse...

Read More
Almost Three-quarters of Ransomware Victims Hit Multiple Times
Aug05

Almost Three-quarters of Ransomware Victims Hit Multiple Times

A recent study conducted by the cybersecurity firm Semperis has revealed that companies are often targeted by ransomware groups multiple times, with almost three-quarters (74%) of companies that experienced a ransomware attack saying they had been attacked multiple times. These attacks caused disruption at 87% of attacked companies, 37% reported suffering data loss and 33% of companies said they had to take all of their systems offline. In healthcare, 40% suffered data loss and 29% had to take all of their systems offline. Companies in the United States and the United Kingdom were most likely to have experienced a ransomware attack, with 85% of surveyed companies in those countries suffering at least one ransomware attack in the past 12 months. The industries with the highest number of attacks were finance and healthcare, with 88% and 85% of respondents in those sectors saying they had experienced a ransomware attack in the past 12 months. Initial attacks were most successful in education and healthcare, with healthcare organizations the most likely to suffer multiple simultaneous...

Read More
Is HubSpot HIPAA compliant?
Aug02

Is HubSpot HIPAA compliant?

HubSpot is HIPAA compliant for specific covered services which can be used to collect, store, process, and transmit Protected Health Information subject to covered entities subscribing to an enterprise account and agreeing to the terms of HubSpot’s Business Associate Agreement. In addition, any apps integrated with HubSpot must also be HIPAA compliant. In June 2024, HubSpot announced the launch of sensitive data tools that can be configured to support HIPAA compliance for specific “covered services”. The company also announced it will (automatically) enter into a Business Associate Agreement with customers that identify as HIPAA covered entities or business associates when activating the sensitive data settings. While the announcement is good news for customers that have long been requesting a HIPAA compliant version of the CRM, covered entities are reminded that only specific services are covered by the Business Associate Agreement. Furthermore, configuring the covered services to make HubSpot HIPAA compliant can be difficult for administrators unfamiliar with the platform. Which...

Read More
HHS-OIG Completes Review of West Virginia Medicaid Fraud Control Unit
Aug02

HHS-OIG Completes Review of West Virginia Medicaid Fraud Control Unit

The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has conducted an inspection of the West Virginia Medicaid Fraud Control Unit. These annual audits are conducted to assess each Unit’s performance in accordance with the requirements of the grant awards and to recertify each unit. The review spanned Fiscal Years 2020-2022, during which time the Unit obtained 37 indictments, 34 convictions, 41 civil settlements, and $75.3 million in recoveries. The Unit’s performance was generally good, with ample training provided to staff members, strong working relationships maintained with stakeholders, and measures implemented to ensure continuous case flow. HHS-OIG identified some areas where adherence to performance standards could be improved. A new case management system was introduced that allowed managers to effectively monitor cases, but there were some reporting issues. The new system did not allow accurate reporting of Unit performance to HHS-OIG, adverse actions were not reported to the National Practitioner Data Bank (NPDB) from 2017 through 2022, and...

Read More
What is PACS in Healthcare?
Aug02

What is PACS in Healthcare?

A PACS in healthcare is a Picture Archiving and Communications System – a digital system used to store, retrieve, and transmit medical images captured from devices such as X-ray machines, MRI scanners, CT scanners, and ultrasound machines. The acronym PACS is still commonly used in healthcare despite being retired by the FDA in 2021 in favor of MIMPS (Medical Image Management and Processing Systems). Medical imaging has come a long way since Wilhelm Roentgen discovered X-rays in 1895. Originally maintained on physical glass plates and (from 1918) photographic film, medical images were first captured digitally and communicated via Intranets in the 1970s. The subsequent development of the DICOM standard in the 1980s enabled the storage and transmission of medical images via otherwise incompatible devices and networks. Later versions of the DICOM standard in the 1990s improved the interoperability of PACS in healthcare. Support for HL7 standards facilitated the integration of scheduling and billing software, while improvements to HTTP transport capabilities via Port 80 enabled remote...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist