25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Who Should HIPAA Complaints be Directed to Within the Covered Entity?

HIPAA complaints made to a covered entity should be directed to the organization’s Privacy Officer regardless of whether the complaint has been made by a member of the public who believes their privacy rights have been violated or by a member of the workforce reporting an internal violation. The process for members of the public should be included on the organization’s Notice of Privacy Practices, but the process for reporting potential HIPAA violations internally can differ. Reporting Potential HIPAA Violations Internally During your HIPAA training, you should have been told who should HIPAA complaints be directed to within the HIPAA covered entity, and the procedures to follow for making complaints about potential HIPAA violations. Generally speaking, the HIPAA violation should be reported to the person in your organization who is responsible for HIPAA compliance, which is typically your Privacy Officer or CISO. You may feel more comfortable reporting the incident to your supervisor. All HIPAA violations, even HIPAA violations that seem relatively minor, should be reported. They...

Read More

HHS Publishes Healthcare Sector Cybersecurity Strategy

On Wednesday, the U.S. Department of Health and Human Services published a concept paper that outlines the HHS’s cybersecurity strategy for the healthcare sector. The paper details the steps that the HHS has already taken to improve cybersecurity in the healthcare sector and the steps the HHS has planned for improving cyber resiliency and protecting patient safety. The Healthcare Sector Cybersecurity Strategy builds on the Biden administration’s National Cybersecurity Strategy and focuses specifically on strengthening resilience for hospitals, patients, and communities threatened by cyberattacks. The healthcare sector has seen a massive increase in cyberattacks in recent years, with large data breaches increasing by 93% from 2018 to 2023 and ransomware attacks increasing by 278% over the same period. These attacks have resulted in extended stays in hospitals, poorer patient outcomes, delays to diagnosis and treatment, and diversions to other healthcare facilities. These adverse impacts have put patient safety at risk yet they are largely preventable. “Since entering office, the...

Read More
CarePointe ENT Settles HIPAA Lawsuit with Indiana Attorney General
Dec06

CarePointe ENT Settles HIPAA Lawsuit with Indiana Attorney General

In late September 2023, Indiana Attorney General Todd Rokita filed a lawsuit against CarePointe ENT over a ransomware attack and data breach that affected 48,742 individuals. A settlement has been reached that will see CarePointe pay $125,000 to resolve alleged violations of the Health Insurance Portability and Accountability (HIPAA) Act and state data privacy and security laws. CarePointe ENT operates three ear, nose, throat, sinus, and hearing centers in Merrillville, Munster & Hobart in Northwest Indiana. On June 25, 2021, CarePointe ENT experienced a ransomware attack which resulted in files being encrypted and data being exfiltrated. The stolen data included names, addresses, dates of birth, Social Security numbers, medical insurance information, and health information. Affected individuals were notified about the data breach in August 2021. AG Rokita launched an investigation into the attack to determine if CarePointe ENT had complied with its obligations under HIPAA and state laws. Despite claiming that it was committed to safeguarding patient information, CarePointe ENT...

Read More
Is Google Sheets HIPAA Compliant?
Dec06

Is Google Sheets HIPAA Compliant?

Google Sheets is HIPAA compliant and can be used to create, manage, and share spreadsheets containing Protected Health Information (PHI) provided organizations subscribe to a Google Workspace plan that supports HIPAA compliance and Google Drive is configured to control access to files saved as Google Sheets. In addition, system administrators are required to review and accept Google’s Business Associate Addendum to the Workspace Service Agreement. Under HIPAA Rules, healthcare organizations are required to implement safeguards to ensure the confidentiality, integrity, and availability of PHI. While it is straightforward to implement controls internally to keep data secure, oftentimes third parties are contracted to provide services that require access to PHI. They too must abide by HIPAA Rules covering privacy, security, and breach notifications. A third-party that requires access to PHI – or copies of health data – to perform services on behalf of a covered entity is considered a business associate. A covered entity and business associate must enter into a contract – a...

Read More
Is doxy.me HIPAA Compliant?
Dec06

Is doxy.me HIPAA Compliant?

On paper, doxy.me is HIPAA compliant and – subject to an organization subscribing to a business plan that supports HIPAA compliance – can be used to create, receive, store, and share Protected Health Information. However, concerns exist about the vendor’s understanding of HIPAA compliance and that the platform is unreliable for delivering quality patient care. Doxy.me is telemedicine platform that enables healthcare professionals to communicate remotely with patients via video, audio, and secure text messaging. The platform has been designed for ease-of-use, and – when subscribed to the premium service – healthcare professionals can take advantage of text and email notifications, secure payments, screen sharing, and group calling. In the context of is doxy.me HIPAA compliant, the perception a user might get from reviewing the HIPAA compliant video conferencing page on the doxy.me website is that it is. The page provides an explanation of the HIPAA requirements (albeit incorrect) and a list of capabilities that appears to fulfil these requirements. Doxy.me will also...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist