25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Improving Clinical Workflow

The key to improving profitability in hospitals is improving clinical workflow. Workflow is a process consisting of a series of tasks that must be completed to achieve a particular goal, which in healthcare means the delivery of clinical services. There is considerable waste in healthcare. Resources are often underutilized, many tasks are conducted manually when there is potential for automation, and there is often considerable repetition of tasks. It has been estimated that around 40% of clinical office work involves redundant tasks and wasted effort and clinicians often end up wasting a considerable amount of their working day as a result of inefficient processes and outmoded communication methods. Optimizing clinical workflows eliminates waste and allows hospitals to use their resources more efficiently, which translates into improved patient flow, better bed utilization, and the delivery of higher quality care to patients. Improving clinical workflow can be a challenge. Any changes made by senior management to fine-tune hospital workflows are likely to affect everyone in the...

Read More

Mistrial Declared in Criminal HIPAA Prosecution of Couple Who Disclosed PHI to Undercover FBI Agent

The prosecution of two doctors accused of criminal HIPAA violations and conspiring with the Russian government has ended in a mistrial as the jury could not reach a unanimous guilty verdict. Dr. Anna Gabrielian. 37, a former anesthesiologist at Johns Hopkins, and her spouse, Jamie Lee Henry, 40, a doctor and U.S. Army Major previously stationed at Fort Bragg, were indicted on September 28, 2022, and charged with conspiracy to assist Russia with its invasion of Ukraine and criminal HIPAA violations for wrongfully disclosing the personally identifiable health information of individuals to someone they believed to be a Russian agent. In an eight-count indictment, the couple was alleged to have conspired to cause harm to the United States by providing the sensitive information of U.S. citizens associated with the U.S. government and military to Russia. The disclosures started on August 17, 2022, when information was passed to an individual who they believed to be a Russian agent. The disclosures served as confirmation of Henry’s secret-level security clearance and the couple’s...

Read More
Critical Vulnerabilities Identified in Baxter Welch Allyn Products
May31

Critical Vulnerabilities Identified in Baxter Welch Allyn Products

Two critical vulnerabilities have been identified in Baxter Welch Allyn products – The Welch Allyn Product Configuration Tool and Welch Allyn Connex Spot Monitor. Baxter identified a critical flaw that affects versions 1.9.4.1 and prior versions of the Welch Allyn Product Configuration Tool. The flaw – tracked as CVE-2024-5176 – is due to insufficiently protected credentials and has been assigned a CVSS v3.1 base score of 9.6 and a CVSS v4 score of 9.4. According to Baxter, “any credentials that were used for authentication or input while using the Welch Allyn Configuration Tool have the potential to be compromised and should be changed immediately.” Baxter has not found any evidence to suggest that the flaw has been exploited in the wild and plans to release a new software update to address the flaw. When the update is released, it will fix the flaw and no action will be required; however, the updated version – 1.9.4.2 – is not due to be released until Q3, 2024. In the meantime, the Welch Allyn Configuration Tool has been removed from public access. If customers...

Read More
Why Personal Email Accounts are not HIPAA Compliant
May31

Why Personal Email Accounts are not HIPAA Compliant

Personal email accounts are not HIPAA compliant because it is necessary to have a Business Associate Agreement in place with the email service provider before including Protected Health Information in the content of an email, and email service providers will not enter into Business Associate Agreements with personal customers. When you send an email from any type of email service hosted by a third party email service provider (i.e., Gmail, Outlook, Yahoo, etc.), the email travels from your device to your provider’s mail server. When it reaches your provider’s server, it is either stored on the server until the recipient logs into their account, or – if the recipient uses a different email service – forwarded to their provider’s server, where it is stored until the recipient logs into their account. In both scenarios, your email service provider is conducting a service on your behalf by storing and facilitating the delivery of your email. If you are a HIPAA covered entity, and your email contains Protected Health Information (PHI), your provider qualifies as a business associate and...

Read More
Impact of Hospital Ransomware Attacks on Neighboring Hospitals
May30

Impact of Hospital Ransomware Attacks on Neighboring Hospitals

A ransomware attack on a hospital involves the encryption of computer networks, rendering essential systems and data unavailable. Hospitals have to investigate the attack, identify how their network was breached, rebuild systems, and restore data safely and securely. That process takes time, and during the recovery, systems remain unavailable. The downtime can last anywhere from a few days to several weeks. Ransomware attacks on hospitals have been increasing. Between 2016 and 2021, there were more than 370 ransomware attacks on US clinics, hospitals, and other healthcare organizations, with attacks doubling over that period. Attacks have continued to increase since 2021, with a sizeable increase in 2023. As has been made clear by the ransomware attack on Ascension, the disruption caused can be considerable. The Ascension attack took many hospital IT systems out of action, resulting in diagnosis and treatment delays, canceled appointments and surgeries, and emergency departments being placed on divert. The effects of a ransomware attack are not only felt at the hospital that...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist