25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Zapier HIPAA Compliant?
Jul17

Is Zapier HIPAA Compliant?

Zapier is not HIPAA compliant due to the number of applications that integrate with the online automation platform and the sub-processors used by Zapier that themselves do not support HIPAA compliance. While this does not prevent HIPAA covered entities from using the platform, the inability to create, receive, store, or transmit Protected Health Information (PHI) limits the potential uses of Zapier in healthcare. Zapier is a “no-code” automation platform that connects web applications via a drag and drop interface and orchestrates the flow of data between them. Zapier can be used to automate time-consuming tasks such as managing files and folders, sending notifications, and backing up data. It can also be used to prioritize workloads  and streamline communications. In the healthcare industry, a platform with Zapier’s capabilities could be deployed for mapping patients’ journeys, managing medications, and coordinating discharges. It could also be used to automate eligibility, authorization, claims, and billing processes. However, Zapier does not support HIPAA compliance and cannot...

Read More
Class Action Lawsuit Alleges Pruitt Health Ransomware Attack Due to Negligence
Jul17

Class Action Lawsuit Alleges Pruitt Health Ransomware Attack Due to Negligence

Pruitt Health is facing a class action lawsuit over a 2023 ransomware attack that exposed the protected health information of 56,405 patients. Pruitt Health, the operator of 180 care centers in Florida, Georgia, North Carolina, and South Carolina, suffered a ransomware attack on November 2023 that exposed patient data. The NoEscape ransomware group claimed responsibility for the attack and said 1.5TB of data was stolen. The stolen data was uploaded to its data leak site in December 2023; however, the data leak site was taken down before Pruitt Health was able to confirm exactly what data had been stolen. Pruitt Health concluded that the types of data likely stolen in the attack included patient names, contact information, demographic information, dates of birth, government identification information, Social Security numbers, bank account numbers, health insurance information, and health information. Pruitt Health notified all individuals potentially affected by the attack in May 2024. A class action lawsuit – Tina Clayton v. PruittHealth Inc.- was filed in the U.S. District...

Read More
Advancement of AI is Accelerating the Need for a Federal Privacy Law
Jul17

Advancement of AI is Accelerating the Need for a Federal Privacy Law

On 11 July 2024, Senate Committee on Commerce, Science and Transportation Chair Maria Cantwell (D-WA) held a full committee hearing, titled “The Need to Protect Americans’ Privacy and the AI Accelerant,” in which Cantwell stressed the need for a federal privacy law to prevent AI data misuse. In April, Cantwell and House Energy & Commerce Committee Chair Cathy McMorris Rodger (R-WA) released a draft of the bipartisan bicameral American Privacy Rights Act (APRA), which seeks to introduce federal privacy regulations to replace the current patchwork of state laws. The APRA is the successor to the American Data Privacy and Protection Act (ADPPA) which showed great promise but ultimately stalled due to a lack of support. The APRA addresses some of the issues that resulted in the failure of ADPPA and was recently amended to attract more support. On May 23, 2024, the U.S. House Committee on Energy and Commerce Subcommittee on Data, Innovation, and Commerce released a revised APRA draft ahead of a scheduled markup by the House Energy and Commerce Committee. The revised draft...

Read More
Bipartisan Bill Introduced to Improve Cybersecurity in Healthcare
Jul16

Bipartisan Bill Introduced to Improve Cybersecurity in Healthcare

A bipartisan group of three senators has introduced legislation to improve cybersecurity in the healthcare and public health (HPH) sector. The Healthcare Cybersecurity Act of 2024 was introduced by Jacky Rosen (D-NV), Todd Young (R-IN), and Angus King (I-ME) in response to recent devastating cyberattacks, such as the ransomware attack on Change Healthcare that caused massive disruption for providers and patients across the country. That attack highlighted the impact of a lack of preparation and training on the recovery process. If passed, the Healthcare Cybersecurity Act will direct the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to collaborate with the Department of Health and Human Services to develop resources for non-federal entities on cyber threat indicators and appropriate defensive measures. CISA will also be required to create a special liaison to the HHS within CISA to coordinate the government’s response during cybersecurity incidents and provide support to HPH sector entities. “It’s imperative that we take measures to...

Read More
Consumer Health Information Privacy Protection Act Introduced in DC to Protect Non-HIPAA Health Data
Jul16

Consumer Health Information Privacy Protection Act Introduced in DC to Protect Non-HIPAA Health Data

District of Columbia Attorney General Brian L. Schwalb recently introduced the Consumer Health Information Privacy Protection Act of 2024 (CHIPPA) to better protect the personal health data of District residents. CHIPPA was introduced to improve the protection of health data not covered by the Health Insurance Portability and Accountability Act (HIPAA). HIPAA-regulated entities are already required to implement privacy and security measures to protect health data; however, health data is collected by many companies that are not required by law to implement safeguards, such as tech companies that have developed fitness, health, and wellness apps and patient support groups. CHIPPA requires those entities to adhere to strengthened privacy provisions regarding the collection, sharing, use, or sale of consumer health data. They must establish a consumer health data privacy policy and make that policy available to the public on the home page of their website. The policy must contain information about the entity’s collection, use, and sharing of consumer health data. Covered entities are...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist