25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Ann & Robert H. Lurie Children’s Hospital Responding to Cyberattack

On February 1, 2024, Ann & Robert H. Lurie Children’s Hospital in Chicago announced on its website and social media channels that it is responding to a cybersecurity incident and has been forced to take its network systems offline. The cyberattack has been reported to law enforcement agencies and Lurie Children’s is working collaboratively with those agencies and third-party cybersecurity experts to investigate the attack and bring network systems back online as soon as it is safe to do so. The 360-bed acute care hospital is a leading provider of pediatric care in Illinois and one of the biggest children’s healthcare providers in the Midwest, serving 239,000 children each year. The cyberattack has disrupted normal operations and caused delays to medical care for certain patients, with ultrasound and CT scan results temporarily unavailable. Some appointments and elective procedures have been canceled to ensure patient safety. The hospital has confirmed that its emergency services are unaffected, and it is operating under a first-come, first-served approach and is...

Read More
Paubox Launches HIPAA Compliant Online Forms
Feb05

Paubox Launches HIPAA Compliant Online Forms

Paubox, the market leader in HIPAA-compliant email, has added a new feature to the Paubox Email Suite that allows HIPAA-regulated entities to create secure, HIPAA-compliant online forms for collecting patient data. Healthcare providers need to collect information from patients and the easiest and most efficient way to do so is by using an online form. Patients can be sent a link to a form that they can access on their mobile devices and can quickly and efficiently provide the required information. They can share files and attach images to help their provider better prepare for an appointment, which can shorten appointment times and allow providers to see more patients. Online forms streamline information collection and can be used for getting feedback, arranging telehealth services, collecting insurance information, and obtaining consent. Before any online form can be used by a HIPAA-regulated entity, they must ensure that the forms are HIPAA-compliant and securely collect, store, and transmit patient data. The providers of online forms are classed as business associates and their...

Read More
Why a Gap Analysis in Healthcare is Far from Straightforward
Feb02

Why a Gap Analysis in Healthcare is Far from Straightforward

In the context of regulatory compliance, a gap analysis in healthcare is an assessment of the required level of regulatory compliance compared to the existing level of regulatory compliance. A gap analysis has the objective of identifying what measures need to be implemented in order to achieve the required level of regulatory compliance. However, a gap analysis in healthcare is far from straightforward. Organizations in the healthcare sector have to comply with multiple federal, state, and industry regulations. They may also be required to comply with voluntary standards to maintain a professional accreditation. Some regulations complement each other. Other regulations conflict with each other. In some cases, regulations can apply to some areas of an organization’s operations – but not others. For example, the Colorado Privacy Act does not apply to “Protected Health Information that is collected, stored, and processed by a covered entity or its business associates”, but it does apply to any other information collected, stored, or maintained by a covered entity or business...

Read More
FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies
Feb02

FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies

The Federal Trade Commission (FTC) has ordered South Carolina-based Blackbaud to implement a raft of security measures and enforce its data retention policies to ensure that customer data is not retained any longer than it is needed. Blackbaud is a customer relationship management software provider, whose software is used by 35,000 fundraising entities, including many nonprofit healthcare organizations to increase philanthropic revenue. In early 2020, a hacker used a Blackbaud customer’s login name and password to access the customer’s Blackbaud-hosted database. Once access was gained, the hacker was able to move laterally by exploiting security vulnerabilities to access multiple Blackbaud-hosted environments and remained undetected in Blackbaud’s environment for 3 months. Over those 3 months, the hacker exfiltrated a vast amount of unencrypted data from tens of thousands of customers, which included the personal and protected health information of millions of individuals. The stolen data included names, contact information, medical information, health insurance information, Social...

Read More
Is GoToMeeting HIPAA Compliant?
Feb02

Is GoToMeeting HIPAA Compliant?

GoToMeeting is HIPAA compliant and can be used by covered entities and business associates to collect, disclose, and transmit Protected Health Information (PHI) provided the organization enters into a Business Associate Agreement with the software provider. Thereafter, there is very little configuration or training required to use the platform in compliance with HIPAA. GoToMeeting is an online meeting and video conferencing platform offered by LogMeIn. The platform is one of many video conferencing and desktop sharing platforms that can improve communication and collaboration in the healthcare industry; but before any solution of this nature can be used to collect, disclose, or transmit PHI, it is important the solution is HIPAA compliant. Is GoToMeeting HIPAA Compliant? GoToMeeting is HIPAA compliant inasmuch as the platform includes all the capabilities required to support HIPAA compliance regardless of the plan subscribed to. Most capabilities are compliant by default, and system administrators should only have to configure the access controls and disable the feature that could...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist