NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Improve Patient Satisfaction With Enhanced Payment Options

Offering modern HIPAA compliant patient payment solutions provides a better customer experience for patients, encourages timely payment and is proven to bring financial savings and improved operational efficiency to any size of healthcare practice. Adding multiple up-to-date payment options leads to improvements in satisfaction and retention levels. For example, making it convenient for patients to pay from their phones by automatically communicating balances and payment options by text and email, practice staff will spend on average 30% less time on payment collection and posting. Plus the practice will see a significant reduction in its accounts receivable numbers. Non-Payment Is Bad For Both Patients And Healthcare Providers Non-payment is known to be one of the main reasons why patients switch healthcare providers. Patients can become anxious when they owe money and frustrated if they find it difficult to make a payment. Digital patient payment solutions that can be easily integrated with all existing practise management systems make it more convenient for patients to settle...

Read More
Is Zoho HIPAA Compliant?
Jan26

Is Zoho HIPAA Compliant?

Zoho is HIPAA compliant for the majority of its services, but organizations should be alert to services that are not HIPAA compliant and to integrations that may have to be disabled to prevent Protected Health Information (PHI) being disclosed to non-compliant applications. In addition, it is important to be aware that no Zoho service is HIPAA compliant by default. All Zoho HIPAA compliant services must be configured to comply with the Security Rule before they can be utilized. Zoho is a provider of cloud services and web-based tools that can be subscribed to individually or as application packages. Most of the services and tools support HIPAA compliance inasmuch as they include capabilities that can be configured to comply with the Administrative and Technical Safeguards of the Security Rule. These services and tools can be used by organizations to create, collect, maintain, and transmit PHI once the Zoho Business Associate Agreement has been signed. However, there are a few services and tools that do not appear to be covered by Zoho’s SOC 2 and HIPAA compliance report (i.e.,...

Read More
Columbus Regional Healthcare System Reports 133K Record Data Breach
Jan26

Columbus Regional Healthcare System Reports 133K Record Data Breach

Columbus Regional Healthcare System in Whiteville, NC, has notified the Maine Attorney General about a cybersecurity incident involving the theft of patient data. Unauthorized individuals had access to its network between May 19, 2023, and May 21, 2023, during which time files were removed from its network. The file review was completed on December 28, 2023, and individual notifications have now been mailed to the affected individuals. The types of information involved varied from individual to individual and may have included names in combination with one or more of the following: Social Security number, date of birth, driver’s license number, state identification number, passport number, alien registration number, financial account information, medical information (date(s) of service, treatment/diagnosis information, medical record number, patient account number, and/or prescription information) and/or health insurance policy information. The Notification to the Maine Attorney General indicates 132,887 individuals were affected. The healthcare system said no evidence has been...

Read More
Is Postmark HIPAA Compliant?
Jan25

Is Postmark HIPAA Compliant?

Postmark is not HIPAA compliant and cannot be used by HIPAA covered organizations to send emails containing Protected Health Information (PHI) unless the subject of the PHI has provided an authorization allowing the disclosure of their PHI. While this scenario is unlikely for bulk mail, there are occasions when a non-compliant service can be used for “consented” transactional emails. Postmark (also known as Postmark App) is an email service provider that provides SMTP services to improve the delivery speed and delivery rates of bulk email (i.e., marketing emails, newsletters, etc.), and the accountability of transactional emails (i.e., welcome emails, password reset emails, etc.). Email service providers such as Postmark can be valuable to organizations that want to run large email promotions, but who need to keep their own mail servers free for operational purposes. With regards to the question is Postmark HIPAA compliant, the email service only needs to be HIPAA compliant if outbound emails contain PHI. When marketing emails, newsletters, and other general healthcare bulletins...

Read More

1.3 Million-Record Database of Netherlands COVID-19 Testing Lab Exposed Online

A medical laboratory in the Netherlands that served as a COVID-19 testing facility has left a database exposed on the Internet that contained the sensitive data of almost 1.3 million individuals including names, dates of birth, appointment details, email addresses, COVID-19 testing information, and passport numbers. The exposed database was found by Jeremiah Fowler, co-founder of Security Discovery and security researcher at vpnMentor. The database did not require any authentication to access and the entire database could be accessed by anyone who knew the path name. The database included an estimated 1,285,277 records, including 118,441 certificates, 506,663 appointments, 660,173 testing samples, and a small number of internal application files. The database also contained thousands of QR codes that linked to web pages that included appointment details and email addresses. The documents had the name and logo of a now inaccessible website, Coronalab.eu, which belongs to Coronalab. Coronalab is owned by the Amsterdam-based ISO-certified laboratory, Microbe & Lab, one of the top...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist