25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Publicly Accessible Database Contained 148,000 Files Related to COVID-19 Testing
Jul18

Publicly Accessible Database Contained 148,000 Files Related to COVID-19 Testing

An InHouse Physicians database containing 148K files related to COVID-19 testing has been exposed online, and Freudenberg Medical and Fairfax Radiological Consultants have experienced cyberattacks that exposed patient data. Publicly Accessible Database Contained 148,000 Files Related to COVID-19 Testing InHouse Physicians, a provider of on-site medical services and wellness programs to organizations, has inadvertently exposed a database on the Internet that included almost 150,000 documents that contained information about individuals’ COVID-19 status – whether they had been cleared to attend an event or had tested positive for COVID-19. The exposed database was identified by researcher Jeremiah Fowler, who found 12 GB of documents in the non-password-protected database, including 148,415 PDF files that contained full names, phone numbers, the name of the event, and whether individuals had been cleared to attend or were COVID-19 positive. Fowler notified InHouse Physicians about the exposed database and it was rapidly secured. It is unclear whether the database was managed by...

Read More
Is Zapier HIPAA Compliant?
Jul17

Is Zapier HIPAA Compliant?

Zapier is not HIPAA compliant due to the number of applications that integrate with the online automation platform and the sub-processors used by Zapier that themselves do not support HIPAA compliance. While this does not prevent HIPAA covered entities from using the platform, the inability to create, receive, store, or transmit Protected Health Information (PHI) limits the potential uses of Zapier in healthcare. Zapier is a “no-code” automation platform that connects web applications via a drag and drop interface and orchestrates the flow of data between them. Zapier can be used to automate time-consuming tasks such as managing files and folders, sending notifications, and backing up data. It can also be used to prioritize workloads  and streamline communications. In the healthcare industry, a platform with Zapier’s capabilities could be deployed for mapping patients’ journeys, managing medications, and coordinating discharges. It could also be used to automate eligibility, authorization, claims, and billing processes. However, Zapier does not support HIPAA compliance and cannot...

Read More
Class Action Lawsuit Alleges Pruitt Health Ransomware Attack Due to Negligence
Jul17

Class Action Lawsuit Alleges Pruitt Health Ransomware Attack Due to Negligence

Pruitt Health is facing a class action lawsuit over a 2023 ransomware attack that exposed the protected health information of 56,405 patients. Pruitt Health, the operator of 180 care centers in Florida, Georgia, North Carolina, and South Carolina, suffered a ransomware attack on November 2023 that exposed patient data. The NoEscape ransomware group claimed responsibility for the attack and said 1.5TB of data was stolen. The stolen data was uploaded to its data leak site in December 2023; however, the data leak site was taken down before Pruitt Health was able to confirm exactly what data had been stolen. Pruitt Health concluded that the types of data likely stolen in the attack included patient names, contact information, demographic information, dates of birth, government identification information, Social Security numbers, bank account numbers, health insurance information, and health information. Pruitt Health notified all individuals potentially affected by the attack in May 2024. A class action lawsuit – Tina Clayton v. PruittHealth Inc.- was filed in the U.S. District...

Read More
Advancement of AI is Accelerating the Need for a Federal Privacy Law
Jul17

Advancement of AI is Accelerating the Need for a Federal Privacy Law

On 11 July 2024, Senate Committee on Commerce, Science and Transportation Chair Maria Cantwell (D-WA) held a full committee hearing, titled “The Need to Protect Americans’ Privacy and the AI Accelerant,” in which Cantwell stressed the need for a federal privacy law to prevent AI data misuse. In April, Cantwell and House Energy & Commerce Committee Chair Cathy McMorris Rodger (R-WA) released a draft of the bipartisan bicameral American Privacy Rights Act (APRA), which seeks to introduce federal privacy regulations to replace the current patchwork of state laws. The APRA is the successor to the American Data Privacy and Protection Act (ADPPA) which showed great promise but ultimately stalled due to a lack of support. The APRA addresses some of the issues that resulted in the failure of ADPPA and was recently amended to attract more support. On May 23, 2024, the U.S. House Committee on Energy and Commerce Subcommittee on Data, Innovation, and Commerce released a revised APRA draft ahead of a scheduled markup by the House Energy and Commerce Committee. The revised draft...

Read More
Bipartisan Bill Introduced to Improve Cybersecurity in Healthcare
Jul16

Bipartisan Bill Introduced to Improve Cybersecurity in Healthcare

A bipartisan group of three senators has introduced legislation to improve cybersecurity in the healthcare and public health (HPH) sector. The Healthcare Cybersecurity Act of 2024 was introduced by Jacky Rosen (D-NV), Todd Young (R-IN), and Angus King (I-ME) in response to recent devastating cyberattacks, such as the ransomware attack on Change Healthcare that caused massive disruption for providers and patients across the country. That attack highlighted the impact of a lack of preparation and training on the recovery process. If passed, the Healthcare Cybersecurity Act will direct the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to collaborate with the Department of Health and Human Services to develop resources for non-federal entities on cyber threat indicators and appropriate defensive measures. CISA will also be required to create a special liaison to the HHS within CISA to coordinate the government’s response during cybersecurity incidents and provide support to HPH sector entities. “It’s imperative that we take measures to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist