25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Zendesk HIPAA Compliant?
Feb01

Is Zendesk HIPAA Compliant?

Zendesk is HIPAA compliant for covered services in HIPAA-enabled Service Plans, provided organizations agree to the terms of Zendesk’s Business Associate Agreement and configure services to comply with Zendesk’s Security Configuration Requirements. Depending on how the platform is used, it may also be necessary to disable third party apps and integrations, or enter into separate Business Associate Agreements with third party software vendors. Zendesk is a customer experience platform that was originally designed as a customer service solution but now also includes sales, customer management, and workforce productivity services. By default, Zendesk is not HIPAA compliant because it prohibits customers from storing or transmitting  Protected Health Information (PHI) under §2.3 of the Main Services Agreement unless “expressly agreed to otherwise by Zendesk in writing”. However, because many customers want to use the platform to create, collect, store, or transmit PHI, Zendesk provides a number of options for overcoming this prohibition. These include subscribing to a HIPAA-enabled...

Read More

Healthcare Compliance Program Policies and Procedures

Healthcare compliance program policies and procedures should consist of a combination of policies and procedures mandated by federal, state, and local regulations, and policies and procedures implemented in response to a risk assessment or other corporate activity. There are no “one-size-fits-all” policies and procedures for healthcare compliance programs. Healthcare compliance programs are essential for ensuring organizations comply with all federal, state, and local regulations applicable to their activities, industry best practices, and voluntary standards. Key to the effectiveness of a healthcare compliance program are policies and procedures that instruct workforce members how to perform their functions within the boundaries of the program and how to respond to specific events. Most federal, state, and local regulations have policy and procedure requirements. However, while some are direct requirements, others are indirect requirements. For example, in the HIPAA Privacy Rule there is only one direct requirement – to implement policies and procedures limiting requests...

Read More
Security Breaches in Healthcare in 2023
Jan31

Security Breaches in Healthcare in 2023

  Report: Security Breaches in Healthcare (Direct Download PDF, 1.9MB, 16 pages)   An unwanted record was set in 2023 with 725 large security breaches in healthcare reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), beating the record of 720 healthcare security breaches set the previous year. Aside from 2015, the number of reported security breaches in healthcare has increased every year although the rate of increase is slowing and 2024 could see the healthcare industry start to turn the corner. As the chart shows, healthcare security breaches are occurring twice as often as in 2017/2018, with two large healthcare data breaches reported each day on average in 2023. Just a few years ago it was alarming that large healthcare data security breaches were being reported at a rate of one a day. Little did we know how bad the situation would get in such a short space of time. Cybersecurity Training for Healthcare Employees Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually...

Read More
Interview: Ty Allen, Founder & CEO, SocialClimb
Jan31

Interview: Ty Allen, Founder & CEO, SocialClimb

  The HIPAA Journal has spoken with Ty Allen, Founder & CEO of SocialClimb. SocialClimb offers a comprehensive, HIPAA-compliant healthcare marketing platform that aligns with the goals of healthcare organizations of all types and sizes. Tell the readers about your career in the healthcare industry I have been building marketing software for years and focused on healthcare marketing software beginning in 2016. I had not previously been in the healthcare space, but quickly discovered that it aligns with my passion for building innovative products that deliver real value. SocialClimb delivers the most comprehensive suite of healthcare marketing tools in an easy-to-use platform, making it easier for doctors to connect with patients in need. What are the main challenges in your position? With HIPAA regulations on the forefront of every healthcare professional’s mind, many organizations are hesitant to implement any form of digital marketing. The challenge we primarily face is educating customers on the importance of marketing and the opportunities available. Healthcare is a...

Read More
Is Mandrill HIPAA Compliant?
Jan31

Is Mandrill HIPAA Compliant?

Mandrill is not HIPAA compliant and cannot be used by HIPAA covered entities or business associates to send transactional emails that contain Protected Health Information (PHI) as the service does not support user compliance with HIPAA. In addition, Mandrill’s parent company – Mailchimp – will not enter into Business Associate Agreements with customers. Mandrill is a transactional email service that can be used as part of the Mailchimp platform to send “transactional” emails – emails that are triggered by events such as an account creation (welcome email), the placement of an order (order confirmation), support enquiries (acknowledgement of enquiry), and password reset requests. Transactional emails do not usually use or disclosure PHI because names and email addresses are not considered PHI under HIPAA  when they are maintained in a separate database from individually identifiable health information. If this were the case with Mandrill, the answer to the question is Mandrill HIPAA compliant would be it doesn’t have to be because the service is not using or disclosing PHI. However,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist