25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Phishing Training for Employees
Dec13

Phishing Training for Employees

Phishing training for employees is important for HIPAA compliance because it prepares employees for the online threats they are most likely to encounter and provides them with the skills to be able to identify phishing emails and prevent this common cause of data breaches. Security Awareness Training is a Requirement for HIPAA Security Rule Compliance The HIPAA Security Rule directly mandates that HIPAA-covered entities and their business associates implement a security awareness training program. The extent to which the healthcare industry is being targeted by cybercriminals – and the number of data breaches that are now occurring – makes security awareness training more important than it ever has been. HIPAA is light on detail when it comes to the topics that should be covered in security awareness training. At the time when the Security Rule was finalized, the threat landscape was very different. Had the HIPAA Security Rule been more specific, it would have been necessary to update the regulation multiple times over the past two decades. The content of security awareness...

Read More

Is Text Messaging HIPAA Compliant?

Text messaging is not HIPAA compliant, and unencrypted SMS messages should not be used for communicating ePHI unless a patient has initiated contact by SMS or requested provider-patient communications by text message – in which case healthcare providers can use text messaging provided reasonable safeguards are implemented. Given its ease of use, many healthcare organizations and professionals may wonder is text messaging HIPAA compliant. The answer is generally “no,” but there are exceptions. It is important for members of the workforce to receive HIPAA training on when it is permissible to use and disclose Protected Health Information (PHI) and the ways in which PHI can be used and disclosed – including SMS text messaging as it is likely every workforce member has access to a device with SMS messaging capabilities. Although there are circumstances in which SMS text messaging can be HIPAA compliant, they are few and far between – making it safer for covered entities to prohibit texting electronic Protected Health Information (ePHI) rather than risk a penalty...

Read More
Missouri Attorney General Files Lawsuit in Response to WU Refusal to Provide Transgender Patients’ Records
Dec13

Missouri Attorney General Files Lawsuit in Response to WU Refusal to Provide Transgender Patients’ Records

The Missouri Attorney General has filed a counterclaim in response to a lawsuit filed by Washington University (WU) over the legal basis of civil investigative demands for documentation about medical procedures performed on transgender patients. WU is refusing to provide records from its Transgender Center that contain patient information, which the Missouri Attorney General claims are essential to the investigation. Missouri Attorney General, Andrew Bailey, issued civil investigative demands for documentation in February 2023 pursuant to an investigation of the Washington University Transgender Center, including records of patients who received treatment. The investigation was initiated in response to allegations by a whistleblower that the clinic had administered experimental drugs, puberty blockers, and cross-sex hormones without sufficient assessments and also pressured parents into giving consent. WU strongly denies the allegations. Washington University complied with the investigative demand and provided documentation but did not provide patient records as it did not believe...

Read More
Is DocuSign HIPAA Compliant?
Dec13

Is DocuSign HIPAA Compliant?

DocuSign is HIPAA compliant provided organizations subscribe to a plan that supports HIPAA compliance and provided the capabilities of the electronic signature software are configured to comply with the HIPAA Security Rule. Healthcare organizations and providers will also need to configure access controls to comply with CMS’ Medicare Electronic Signature Requirements. What is DocuSign? DocuSign is a San Francisco-based provider of electronic signature technology and transaction management services. Via DocuSign, organizations can accelerate patient intake, medical consents, and HIPAA authorizations. Organizations can also send documents to patients, contracts to suppliers, and agreements to business associates for remote signing. However, if the service is used in connection with any electronic protected health information, DocuSign would be classed as a business associate. HIPAA requires all business associates to enter into a HIPAA-compliant business associate agreement with covered entities prior to being provided with or given access to ePHI. Is DocuSign HIPAA Compliant? Rather...

Read More
Healthplex Settles Data Breach Investigation with NY Attorney General for $400,000
Dec13

Healthplex Settles Data Breach Investigation with NY Attorney General for $400,000

The New York Attorney General has agreed to settle alleged violations of New York’s data security and consumer protection laws with Healthplex, one of New York’s largest providers of dental insurance. Healthplex has agreed to pay a penalty of $400,000 to resolve the investigation with no admission of wrongdoing. Attorney General Letitia James launched an investigation of Healthplex after being notified about a breach of the personal and protected health information of 89,955 individuals, including 62,922 New York residents to determine if Healthplex had complied with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) and New York’s data security and consumer protection laws. The data breach occurred on or around November 24, 2021, and was the result of an employee responding to a phishing email and disclosing her account credentials. The account contained more than 12 years of emails, some of which included customer enrolment information. Credentials alone should not be sufficient to gain access to email accounts; however, Healthplex had not...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist