25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Interoperability in Healthcare
Jan05

Interoperability in Healthcare

Interoperability in healthcare means making sure information technology systems and software solutions work together seamlessly to exchange, interpret, and use data. Interoperability ensures that health data collected in one system can be made available for use in another, which can be achieved through the adoption of standards and use of data exchange models. When there is interoperability in healthcare, data can be shared internally with all people who need access to healthcare information and also externally with other healthcare providers and authorized third parties, irrespective of the systems or software they use. Unfortunately, many software solutions are developed in silos which makes it difficult for data to easily be transferred to other solutions and systems. When data exchange is possible, it often involves come manual processes, data transfer is slow, and communications are often disjointed. Interoperability in healthcare should see healthcare information systems working seamlessly together, within and across organizational boundaries. It should be possible for...

Read More
Is Google Slides HIPAA Compliant?
Jan05

Is Google Slides HIPAA Compliant?

Google Slides is HIPAA compliant and can be used to create slides and presentations containing Protected Health Information provided the service is used as part of a Google Workspace plan covered by a Business Associate Addendum and configured to restrict document sharing. It will also be necessary to include the compliant use of Google Forms in workforce training. Google Slides is a presentation editor that allows users to create slide shows, training materials, and project presentations. Because of its ease of use, Google Slides is an ideal option for users who do not regularly create slide shows or presentations and do not have a software package that offers the same functionality. Google Slides is available free of charge for personal use but personal users cannot use Google Slides in compliance with HIPAA. Using Google Slides in Compliance with HIPAA HIPAA covered entities and business associates that want to take advantage of Google Slides’ functionality can do so without any HIPAA compliance concerns provided Protected Health Information (PHI) is not used or disclosed in the...

Read More

Parathon by JDA eHealth Systems Confirms July 2023 Cyberattack

Parathon by JDA eHealth Systems, a revenue cycle management company in Naperville, Illinois, has recently notified state attorneys general that it suffered a cyberattack on July 27, 2023. In its December 22, 2023, notification to the Montana Attorney General, Parathon explained that unauthorized individuals were able to access the protected health information of patients of its clients. The types of information involved varied from individual to individual and may have included names in combination with one or more of the following: address, date of birth, and/or protected health information, including but not limited to diagnosis, claims information, and health insurance information. The notification does not state whether files were encrypted in the attack, but Parathon said data was stolen and a ransom payment was demanded. Parathon said, “We have taken all efforts possible to mitigate any further exposure of your personal information and related identity theft.” The Akira threat group claimed responsibility for the attack and added Parathan to its data leak site but has since...

Read More

What is Healthcare Governance, Risk Management, and Compliance (GRC)?

Healthcare governance, risk management, and compliance (GRC) are the three components of an interconnected framework that can help healthcare organizations better monitor and manage risks in order to support compliance with regulations, standards, and best practices. This article discusses the benefits of GRC in healthcare using HIPAA as an example. However, the GRC framework can be applied to most other regulations, standards, and best practices. Healthcare governance, risk management, and compliance are often considered to be three separate activities or activities that have a linear progression. For example, healthcare governance can be interpreted as the accountability (of a team or individual) for compliance, which is then delegated in part to those in charge of assessing and mitigating risks (nurse managers, HR, IT, legal, etc.), who then develop policies and procedures and provide workforce training. This linear approach to complying with applicable regulations, standards, and best practices can result in silos of compliance. In these silos of compliance, inconsistences in...

Read More

At Least 141 Hospitals Directly Affected by Ransomware Attacks in 2023

Last year was a particularly bad year for ransomware attacks. According to an analysis by the cybersecurity firm Emsisoft, 46 hospital systems suffered ransomware attacks in 2023, up from 25 in 2022 and 27 in 2021. Across those 46 attacks, at least 141 hospitals were directly affected and experienced disruption due to the lack of access to IT systems and patient data. It is difficult to accurately report on ransomware attacks in the healthcare sector, as many victims fail to disclose whether ransomware was used. Breach notification letters to the affected individuals and state Attorneys General often describe ransomware attacks as cyberattacks, unauthorized access, hacking incidents, security incidents, or encryption events, and as such, the number of attacks experienced in the sector is likely to be significantly understated. Emsisoft’s State of Ransomware in the U.S.: Report and Statistics 2023 reveals 2,207 U.S. hospitals, schools, and governments were directly impacted by ransomware in 2023 and many others were indirectly impacted via attacks on their supply chains. Without...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist