25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Optum Medical Care of New Jersey Settles OCR HIPAA Right of Access Investigation

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged violations of the HIPAA Privacy Rule with Optum Medical Care of New Jersey for $160,000. Optum Medical Care of New Jersey, formerly known as Riverside Medical Group and Riverside Pediatric Group, is a private multi-specialty physician group with approximately 150 locations in New Jersey and Southern Connecticut. In the Fall of 2021, OCR received six complaints from individuals who had not been provided with their records after sending a request to Optum Medical Care. The requests were to obtain a copy of an individual’s own records or requests from parents for copies of their minor children’s records. The HIPAA Privacy Rule gives individuals the right to obtain a copy of their medical records and those of their minor children. When a request is received by a HIPAA covered entity, the records must be provided within 30 calendar days, although under certain limited circumstances, a 30-day extension is possible. OCR launched an investigation in February 2022 in response to the...

Read More
Is Marketo HIPAA Compliant?
Dec19

Is Marketo HIPAA Compliant?

Marketo is HIPAA compliant and can be used to collect, store, analyze, and share Protected Health Information (PHI) between members of the same organization’s workforce or systems, provided the email marketing and lead management platform is used in Adobe’s Experience Cloud for Healthcare and its use is supported by a Business Associate Agreement. Marketo is a popular marketing automation platform that was acquired in 2018 by Adobe. At the time of the acquisition, Marketo was not HIPAA compliant because the previous vendor would not enter into a Business Associate Agreement with covered entities and business associates. However, Adobe has recently added the platform to its Experience Cloud for Healthcare and is marketing the platform as a HIPAA-Ready Service under its rebranded name “Marketo Engage”. What is a HIPAA-Ready Service? A HIPAA-Ready Service is any service in Adobe’s Experience Cloud for Healthcare that has additional features and functionalities to support HIPAA compliance. For example, under a standard Marketo Engage plan, organizations would have to purchase database...

Read More

HIPAA Violation Reporting

The process for HIPAA violation reporting varies according to who is reporting a HIPAA violation, the nature of the HIPAA violation, and organizational policies for making – or dealing with – internal and/or external reports of HIPAA violations. In addition, because of the different ways in which HIPAA violations can be reported (phone, email, person-to-person, etc.) there is no one-size-fits-all HIPAA compliance violation reporting procedure. There are many different types of HIPAA violations, but some are not as serious as others. For example, the failure to send periodic security reminders (an implementation specification of 45 CFR § 164.308) is a HIPAA violation, but it is unlikely to have as serious consequences as the theft of an unencrypted laptop containing the unsecured ePHI of twenty thousand patients. Consequently, a single Covered Entity or Business Associate may have several HIPAA violation reporting processes depending on the nature and potential severity of the event. Similarly, the HHS´ Office for Civil Rights – the HIPAA enforcement agency – has...

Read More

CISA Publishes Healthcare-Specific Guidance for Improving Cyber Resilience

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published healthcare sector-specific guidance on enhancing cyber resilience. The guidance is based on the findings from a two-week risk and vulnerability assessment that was performed in January 2023 at the request of a large healthcare organization that was looking to identify vulnerabilities and potential security improvements. CISA spent the first week conducting external penetration tests to identify weaknesses that could be exploited, and a week analyzing the internal network, with its assessments including web applications, databases, wireless access points, penetration tests, and phishing testing. The unnamed organization was found to have secured its network sufficiently to prevent external attacks. CISA was unable to find any vulnerabilities that could be easily exploited by malicious actors and was unable to gain access through phishing; however, several weaknesses were identified during internal penetration tests. CISA was able to exploit misconfigurations, weak passwords, and other security issues...

Read More

Delta Dental of California Data Breach: 7 Million Individuals Affected

Delta Dental of California Says 6,928,932 Individuals Affected by MOVEit Hack Delta Dental of California has recently confirmed that it was one of the victims of Clop hacking group’s mass exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer solution. Delta Dental of California, part of the Delta Dental Plans Association, provides dental insurance to 45 million people. According to the breach notification sent to the Maine Attorney General, the information of almost 7 million individuals was stolen in the attack, including members of Delta Dental of California plans and those of its affiliates. Delta Dental discovered on June 1, 2023, that the SQL injection vulnerability – CVE-2023-34362 – in the MOVEit Transfer solution had been exploited. Progress Software had released an emergency patch to fix the flaw on May 31, 2023; however, the Russia-linked Clop group exploited the flaw between May 27 and May 30, 2023, before the patch was applied and exfiltrated data from Delta Dental’s MOVEit server. On July 6, 2023, Delta Dental confirmed that plan...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist