NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Security Breaches in Healthcare in 2023
Jan31

Security Breaches in Healthcare in 2023

  Report: Security Breaches in Healthcare (Direct Download PDF, 1.9MB, 16 pages)   An unwanted record was set in 2023 with 725 large security breaches in healthcare reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), beating the record of 720 healthcare security breaches set the previous year. Aside from 2015, the number of reported security breaches in healthcare has increased every year although the rate of increase is slowing and 2024 could see the healthcare industry start to turn the corner. As the chart shows, healthcare security breaches are occurring twice as often as in 2017/2018, with two large healthcare data breaches reported each day on average in 2023. Just a few years ago it was alarming that large healthcare data security breaches were being reported at a rate of one a day. Little did we know how bad the situation would get in such a short space of time. Cybersecurity Training for Healthcare Employees Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually...

Read More
Interview: Ty Allen, Founder & CEO, SocialClimb
Jan31

Interview: Ty Allen, Founder & CEO, SocialClimb

  The HIPAA Journal has spoken with Ty Allen, Founder & CEO of SocialClimb. SocialClimb offers a comprehensive, HIPAA-compliant healthcare marketing platform that aligns with the goals of healthcare organizations of all types and sizes. Tell the readers about your career in the healthcare industry I have been building marketing software for years and focused on healthcare marketing software beginning in 2016. I had not previously been in the healthcare space, but quickly discovered that it aligns with my passion for building innovative products that deliver real value. SocialClimb delivers the most comprehensive suite of healthcare marketing tools in an easy-to-use platform, making it easier for doctors to connect with patients in need. What are the main challenges in your position? With HIPAA regulations on the forefront of every healthcare professional’s mind, many organizations are hesitant to implement any form of digital marketing. The challenge we primarily face is educating customers on the importance of marketing and the opportunities available. Healthcare is a...

Read More
Is Mandrill HIPAA Compliant?
Jan31

Is Mandrill HIPAA Compliant?

Mandrill is not HIPAA compliant and cannot be used by HIPAA covered entities or business associates to send transactional emails that contain Protected Health Information (PHI) as the service does not support user compliance with HIPAA. In addition, Mandrill’s parent company – Mailchimp – will not enter into Business Associate Agreements with customers. Mandrill is a transactional email service that can be used as part of the Mailchimp platform to send “transactional” emails – emails that are triggered by events such as an account creation (welcome email), the placement of an order (order confirmation), support enquiries (acknowledgement of enquiry), and password reset requests. Transactional emails do not usually use or disclosure PHI because names and email addresses are not considered PHI under HIPAA  when they are maintained in a separate database from individually identifiable health information. If this were the case with Mandrill, the answer to the question is Mandrill HIPAA compliant would be it doesn’t have to be because the service is not using or disclosing PHI. However,...

Read More

Concentra Confirms Almost 4 Million Patients Affected by PJ&A Data Breach

Concentra, a Texas-based physical and occupational health provider, has confirmed it was affected by a cyberattack at its transcription service provider, PJ&A. PJ&A has already reported the breach to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as affecting almost 9 million patients; however, some PJ&A clients have chosen to report the breach to OCR themselves, including Concentra. On January 9, 2024, Concentra confirmed that the protected health information of 3,998,162 patients was compromised in the PJ&A cyberattack, bringing the total number of affected individuals up to at least 14 million. That makes it the largest healthcare data breach of 2023. That total is likely to grow further, although by how much is not currently clear as PJ&A has not publicly disclosed which clients have been affected nor the total number of records that were compromised in the attack. The Nevada-based medical transcription company and many of the affected clients are being sued over the data breach. At least 40 lawsuits have already been filed...

Read More
How to Become OSHA Compliant
Jan30

How to Become OSHA Compliant

The summarized way to become OSHA compliant is to establish which OSHA standards apply to your business, conduct a risk assessment to identify threats to safety and health, and abate identified threats as necessary. What is OSHA Compliance? OSHA compliance is complying with all applicable workplace standards promulgated by the federal Occupational Safety and Health Administration or an OSHA-approved state plan to promote safe and healthy workplaces. Most businesses are required to comply with “General Industry” standards, but there are separate standards for the agriculture, maritime, and construction industries. The OSHA standards for General Industry cover everything from safe working surfaces and workplace ventilation to exposure limits for hazardous substances and chemicals. There are also standards governing hazard communication, injury and illness recordkeeping, and workforce training. The failure to comply with any applicable safety, health, or administrative standard is a violation of OSHA. What Happens if You Violate OSHA? What happens if you violate OSHA depends on the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist