25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

LockBit Ransomware Gang Claims Responsibility for Attack on Saint Anthony Hospital

The LockBit ransomware gang has added Chicago’s Saint Anthony Hospital to its data leak site and is demanding a ransom payment of almost $900,000 from the nonprofit hospital to prevent the release of the stolen data. Earlier this week, Saint Anthony Hospital confirmed that it was still investigating the attack, which was detected on December 18, 2023. Saint Anthony Hospital took immediate action to secure its network to prevent further unauthorized access and an investigation was launched to determine the nature and scope of the unauthorized activity. The prompt action taken by the hospital in response to the attack allowed care to continue to be provided to patients without disruption. The investigation confirmed on January 7, 2024, that an unknown, unauthorized third party had copied files from its network on December 18, 2023, which contained patient information. Those files are being reviewed to determine the number of patients affected and the types of information involved, and that process is ongoing. At this stage, Saint Anthony Hospital is unable to say how many individuals...

Read More
What is Hospital Regulatory Compliance?
Feb02

What is Hospital Regulatory Compliance?

Hospital regulatory compliance means complying with the applicable standards of federal regulations such as HIPAA and OSHA, the conditions for participation in Medicare, and any state, local, or industry regulations that apply to a hospital’s activities. Because there are so many regulations for a hospital to comply with, it can be difficult to keep up with the volume of regulatory changes. Depending on where a hospital is located and the nature of its activities, it may have to comply with more than a dozen sets of regulations and voluntary standards. Although there can be a high degree of crossover between the regulations, the speed at which standards are added, amended, or removed complicates hospital regulatory compliance. For example, as of January 2024, there were: Two Requests for Information, three Notices of Proposed Rulemaking, and one Proposed Rule advocating changes to HIPAA (not including Part 162). Five amendments to OSHA in the Pre-Rule stage, twelve amendments in the Proposed Rule stage, and seven amendments in the Final Rule stage. Twenty-four Proposed Rules and...

Read More
Is SparkPost HIPAA Compliant?
Feb02

Is SparkPost HIPAA Compliant?

SparkPost is not HIPAA compliant because the terms and conditions of the now rebranded service prohibit violations of “any legal, regulatory, self-regulatory, governmental, statutory requirements of codes of practice”. As SparkPost lacks the safeguards to comply with HIPAA, any use of the service that discloses Protected Health Information (PHI) would be a violation of HIPAA. SparkPost is an email service that enables customers to automate email processes (i.e., welcome emails), develop multi-step email campaigns, and send targeted bulk emails based on customer behaviors. Since the brand’s acquisition by MessageBird in April 2021, customers have also been able to take advantage of SMS marketing, WhatsApp marketing, and social media marketing capabilities. The service’s appeal is likely to increase in the coming months following the announcement that MessageBird is being rebranded as Bird.com and reducing its pricing to below that of its main U.S. rivals. The motive behind the rebranding exercise is rumored to be an attempt to get a bigger foothold in the U.S. market for the...

Read More
What Does HHS OIG Stand For?
Feb02

What Does HHS OIG Stand For?

The initials HHS OIG stand for the U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) – the largest civilian Office of Inspector General within the Federal government, with approximately 1,570 auditors, investigators, and evaluators overseeing the Department of Health and Human Services’ $2 trillion portfolio of programs. The HHS OIG was the first civilian Office of Inspector General to be established in 1976 at a time when the Department of Health and Human Services was known as the Department of Health, Education, and Welfare. The Department’s name changed in 1979 when its education functions were transferred to the newly created Department of Education, but remained the same in 1995 when the responsibility for social welfare was transferred to the independent Social Security Administration. What Does HHS OIG Stand For in Terms of Mission? Under the Inspector General Act of 1978, what HHS OIG stands for in terms of mission is two-fold. Its first mission is to protect the integrity of HHS programs and well-being of program beneficiaries. This...

Read More
Is Facebook Messenger HIPAA Compliant?
Feb01

Is Facebook Messenger HIPAA Compliant?

Facebook Messenger is not HIPAA compliant and cannot be used to collect or disclose Protected Health Information (PHI) unless a patient who is the subject of the PHI has requested to communicate via the messaging app. Even in these circumstances, precautions must be taken to prevent impermissible disclosures of PHI. Facebook Messenger is a popular messaging app through which individuals and groups can chat, call, and video each other. In the healthcare industry, the Facebook Messenger for Business service can be used to raise public awareness about health issues, tackle misinformation, promote citizen engagement, and communicate emergency situations or critical incidents. However, personal messaging between healthcare providers and individual patients is not permitted by HIPAA when messages include PHI. This is because Facebook Messenger does not meet the requirements to be a business associate, and has “persistent access” to PHI (even when messages are encrypted), so is not exempted from HIPAA compliance under the Conduit Exception Rule. Is it Possible to Make Facebook Messenger...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist