25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Why a Gap Analysis in Healthcare is Far from Straightforward
Feb02

Why a Gap Analysis in Healthcare is Far from Straightforward

In the context of regulatory compliance, a gap analysis in healthcare is an assessment of the required level of regulatory compliance compared to the existing level of regulatory compliance. A gap analysis has the objective of identifying what measures need to be implemented in order to achieve the required level of regulatory compliance. However, a gap analysis in healthcare is far from straightforward. Organizations in the healthcare sector have to comply with multiple federal, state, and industry regulations. They may also be required to comply with voluntary standards to maintain a professional accreditation. Some regulations complement each other. Other regulations conflict with each other. In some cases, regulations can apply to some areas of an organization’s operations – but not others. For example, the Colorado Privacy Act does not apply to “Protected Health Information that is collected, stored, and processed by a covered entity or its business associates”, but it does apply to any other information collected, stored, or maintained by a covered entity or business...

Read More
FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies
Feb02

FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies

The Federal Trade Commission (FTC) has ordered South Carolina-based Blackbaud to implement a raft of security measures and enforce its data retention policies to ensure that customer data is not retained any longer than it is needed. Blackbaud is a customer relationship management software provider, whose software is used by 35,000 fundraising entities, including many nonprofit healthcare organizations to increase philanthropic revenue. In early 2020, a hacker used a Blackbaud customer’s login name and password to access the customer’s Blackbaud-hosted database. Once access was gained, the hacker was able to move laterally by exploiting security vulnerabilities to access multiple Blackbaud-hosted environments and remained undetected in Blackbaud’s environment for 3 months. Over those 3 months, the hacker exfiltrated a vast amount of unencrypted data from tens of thousands of customers, which included the personal and protected health information of millions of individuals. The stolen data included names, contact information, medical information, health insurance information, Social...

Read More
Is GoToMeeting HIPAA Compliant?
Feb02

Is GoToMeeting HIPAA Compliant?

GoToMeeting is HIPAA compliant and can be used by covered entities and business associates to collect, disclose, and transmit Protected Health Information (PHI) provided the organization enters into a Business Associate Agreement with the software provider. Thereafter, there is very little configuration or training required to use the platform in compliance with HIPAA. GoToMeeting is an online meeting and video conferencing platform offered by LogMeIn. The platform is one of many video conferencing and desktop sharing platforms that can improve communication and collaboration in the healthcare industry; but before any solution of this nature can be used to collect, disclose, or transmit PHI, it is important the solution is HIPAA compliant. Is GoToMeeting HIPAA Compliant? GoToMeeting is HIPAA compliant inasmuch as the platform includes all the capabilities required to support HIPAA compliance regardless of the plan subscribed to. Most capabilities are compliant by default, and system administrators should only have to configure the access controls and disable the feature that could...

Read More

LockBit Ransomware Gang Claims Responsibility for Attack on Saint Anthony Hospital

The LockBit ransomware gang has added Chicago’s Saint Anthony Hospital to its data leak site and is demanding a ransom payment of almost $900,000 from the nonprofit hospital to prevent the release of the stolen data. Earlier this week, Saint Anthony Hospital confirmed that it was still investigating the attack, which was detected on December 18, 2023. Saint Anthony Hospital took immediate action to secure its network to prevent further unauthorized access and an investigation was launched to determine the nature and scope of the unauthorized activity. The prompt action taken by the hospital in response to the attack allowed care to continue to be provided to patients without disruption. The investigation confirmed on January 7, 2024, that an unknown, unauthorized third party had copied files from its network on December 18, 2023, which contained patient information. Those files are being reviewed to determine the number of patients affected and the types of information involved, and that process is ongoing. At this stage, Saint Anthony Hospital is unable to say how many individuals...

Read More
What is Hospital Regulatory Compliance?
Feb02

What is Hospital Regulatory Compliance?

Hospital regulatory compliance means complying with the applicable standards of federal regulations such as HIPAA and OSHA, the conditions for participation in Medicare, and any state, local, or industry regulations that apply to a hospital’s activities. Because there are so many regulations for a hospital to comply with, it can be difficult to keep up with the volume of regulatory changes. Depending on where a hospital is located and the nature of its activities, it may have to comply with more than a dozen sets of regulations and voluntary standards. Although there can be a high degree of crossover between the regulations, the speed at which standards are added, amended, or removed complicates hospital regulatory compliance. For example, as of January 2024, there were: Two Requests for Information, three Notices of Proposed Rulemaking, and one Proposed Rule advocating changes to HIPAA (not including Part 162). Five amendments to OSHA in the Pre-Rule stage, twelve amendments in the Proposed Rule stage, and seven amendments in the Final Rule stage. Twenty-four Proposed Rules and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist