25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Settles HIPAA Right of Access Investigation with Phoenix Healthcare for $35,000
Mar29

OCR Settles HIPAA Right of Access Investigation with Phoenix Healthcare for $35,000

The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced that a $35,000 settlement has been reached with Phoenix Healthcare to resolve a HIPAA Right of Access violation. This is the 47th investigation of a HIPAA Right of Access case to result in a financial penalty. The HIPAA Right of Access provision of the HIPAA Privacy Rule requires patients or their personal representatives to have timely access to their health information. Access/copies of the requested information must be provided within 30 days of the request being received. OCR received a complaint from a daughter whose mother was a patient of Phoenix Healthcare, an Oklahoma multi-facility organization that provides nursing care. The daughter was the personal representative of her mother and had not been provided with timely access to her mother’s medical records. The daughter requested the records on multiple occasions and had to wait almost a year to receive the requested data. The requested records were provided 323 days after the initial request was made. The daughter reported the...

Read More

MFA Bypassed in Cyberattack on L.A. County Department of Mental Health

Cyberattacks and data breaches have been reported by the L.A. County Department of Mental Health, Healthfirst, Wyndemere Senior Care, Risas Dental & Braces, and Baylor College of Medicine. Los Angeles County Department of Mental Health The Los Angeles County Department of Mental Health has recently notified the California Attorney General about a breach of an employee’s email account. The email account had multi-factor authentication (MFA) in place; however, MFA was bypassed. The cyber threat actors bypassed MFA using a technique known as push notification spamming, where a user is sent multiple MFA push notifications to their mobile device in the hope that they will eventually respond. The employee did respond, resulting in their email account being compromised. According to the Department of Mental Health, the attack stemmed from a breach at the City of Gardena Police Department (GDP). “GPD’s email exchanges with the Department of Mental Health (DMH) allowed the malicious actor or actors to send an email to a DMH employee and get access to that employee’s...

Read More
Is Uber Health HIPAA Compliant?
Mar29

Is Uber Health HIPAA Compliant?

Uber Health is HIPAA compliant and can be used by healthcare providers to organize transport for patients or to arrange deliveries of groceries, over-the-counter items, and filled prescriptions – subject to healthcare providers that qualify as covered entities (or that work for a covered entity) agreeing to the terms of Uber Health’s Business Associate Addendum. . What is Uber Health? Uber Health consists of an online dashboard that healthcare providers can use to schedule transport for patients or organize deliveries. Provided the patient has a mobile phone, he/she will receive a notification about the collection and drop off location via text message. In contrast to the standard Uber service, Uber Health does not require the use of a smartphone app. By using Uber Health, healthcare providers can potentially reduce the number of no shows and ensure more patients turn up on time for their appointments. Rides can be scheduled when the patient is in a facility, ensuring they have transport arranged for follow up appointments. The service could also be used for caregivers and...

Read More

Kentucky Senate Advances Children’s Medical Record Access Bill

HIPAA gives parents the right to access the medical records of their minor children but Kentucky lawmakers want to make sure that parents can access their children’s entire medical records and prevent healthcare providers from withholding information about treatment that does not, under state law, require parental consent. House Bill 174 was sponsored by Representatives Rebecca Raymer (R), Danny Bentley (R), Chris Fugate (R), John Hodgson (R), and Michael Lockett (R).  The bill adds a new section to current state law (KRS, Chapter 422) that establishes standards and procedures for access to copies of the medical records of patients under 18 years by the minor’s personal representatives – individuals who under state law have the authority to make health care decisions for a patient or a parent of the patient – provided the disclosure of those records is not prohibited by the Health Insurance Portability and Accountability Act (HIPAA). The bill was presented to the House by Sen. Donald Douglas (R), who explained that while HIPAA gives personal representatives/parents the right to...

Read More
CISA Proposes Cyberattack Reporting Rules for Critical Infrastructure Entities
Mar28

CISA Proposes Cyberattack Reporting Rules for Critical Infrastructure Entities

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has proposed a rule that implements cyberattack and ransom payment reporting requirements for critical infrastructure entities, as required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). In March 2022, CIRCIA was signed into law by President Biden, one of the requirements of which was for CISA to develop and implement new regulations that require critical infrastructure entities, including hospitals and health systems, to report covered cyber incidents and ransomware payments to CISA. The purpose of the reporting is to provide CISA with timely information about cyberattacks to allow resources to be rapidly deployed and assistance provided to support victims of cyberattacks and allow CISA to rapidly identify cyberattack trends and disseminate information to help network defenders prevent further attacks. When developing the new requirements, CISA consulted with various entities, including the Sector Risk Management Agencies, the Department of Justice,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist