25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Capital Health’s New Jersey Hospitals Affected by Cyberattack

Capital Health has launched an investigation into a cybersecurity incident that caused it to experience a network outage earlier in the week. Law enforcement has been notified and third-party cybersecurity experts have been engaged to determine the extent and scope of the incident. Capital Health operates two hospitals in New Jersey, Capital Health Medical Center – Hopewell and Capital Health Regional Medical Center in Trenton, as well as an outpatient facility in Hamilton Township. Capital Health’s IT team took immediate action to contain the incident and prevent further unauthorized access to its network and it is currently working around the clock to bring systems and data back online. Capital Health is operating under established downtime protocols while access to electronic systems is not possible, with patient information recorded on paper charts. Capital Health said care continues to be provided to patients and its emergency rooms have remained open, although it was necessary to make some changes to elective surgical and procedure schedules, with some patients’ surgeries...

Read More

Healthcare Workflow Management

Fine-tuning healthcare workflow management to make improvements in efficiency, productivity, and profitability can be a difficult task, but when successful, resources can be used more effectively, stress can be reduced, and patient throughput, patient satisfaction, and clinical outcomes can be significantly improved. The Importance of Healthcare Workflow Management The transition from files and charts to electronic medical record systems has helped ensure patient information is readily accessible at the point of care. EHRs are a central repository for all patient data and ensure accurate and up to date information is always available to inform healthcare decisions. EHRs have helped to improve productivity and efficiency, but EHRs alone are not the solution. Without effective healthcare workflow management and efficient and effective communications systems, it is difficult to unlock the full potential of EHRs. Healthcare workflow management to fine-tune hospital workflows is essential for removing redundancies that unnecessarily eat up hospital resources, delay the provision of...

Read More
Is PayPal HIPAA Compliant?
Nov30

Is PayPal HIPAA Compliant?

PayPal is HIPAA compliant for collecting payment from patients and plan members because HIPAA exempts entities that facilitate payments for healthcare or health plan premiums – however, PayPal is not exempted from HIPAA compliance for any other services it offers. Because PayPal will not enter into a Business Associate Agreement, covered entities should not disclose PHI when using these other services. In the text of the 1996 HIPAA Act, there is an administrative simplification provision relating to payment processing (§1179). This section states that the HIPAA Rules do not apply to banks and financial institutions when they are “authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments for health care or health plan premiums”. To eliminate questions about whether financial institutions qualify as business associates, the Department of Health and Human Services (HHS) later commented in the preamble to the Final Omnibus Rule that “the HIPAA Rules, including the business associate provisions, do not apply to financial institutions with...

Read More

Patient Workflow in a Hospital

A patient workflow in a hospital follows a patient through their entire hospital visit, from the point of admission to the point of discharge. During that healthcare journey a patient is likely to interact with many different healthcare professionals. It would not be unusual for a patient to interact with dozens of different employees in the hospital during a 7 day stay, including administration staff, nurses, physicians, and radiographers. Those healthcare professionals need to coordinate effectively throughout the patient journey in order to achieve goals for safety, quality, cost, and ensure a good patient experience. While strategies may have been adopted to ensure the smooth flow of a patient through the healthcare system, there are likely to be bottlenecks along the way that slow the patient’s journey. These bottlenecks slow down patient flow, which prevents hospitals from utilizing their resources effectively. One of the key problem areas is communication. Many hospitals are still heavily reliant on pagers and landlines to coordinate care and these outdated communication...

Read More
NY Attorney General Warns New Yorkers About Identity Theft Risk from PJ&A Data Breach
Nov30

NY Attorney General Warns New Yorkers About Identity Theft Risk from PJ&A Data Breach

At least 4 million New Yorkers in New York City and Syracuse had their sensitive information stolen in a data breach at the Nevada medical transcription service provider Perry Johnson & Associates (PJ&A). The PJ&A data breach was announced earlier this month and has affected almost 9 million individuals across the United States. While the breach has recently been announced, hackers first gained access to PJ&A’s systems in May 2023. Hackers had access to data such as names, addresses, dates of birth, medical record numbers, hospital account numbers, admission diagnosis, dates/times of service, Social Security numbers, insurance information, and medical and clinical information. This week, New York Attorney General Letitia James issued a warning to all New Yorkers who have received a data breach notification from PJ&A to take steps to protect themselves against identity theft and fraud. New York healthcare providers affected include Northwell Health, the largest healthcare provider in New York, and Crouse Health in Syracuse. When a data breach occurs at a business...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist