NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Intercom HIPAA Compliant?
Jan24

Is Intercom HIPAA Compliant?

Intercom is HIPAA compliant and can be used to collect, store, and process electronic Protected Health Information (ePHI) provided organizations subscribe to an “Expert” business plan and agree to the terms of Intercom’s Business Associate Agreement. Thereafter, it is important the software is configured to support HIPAA compliance and that users are trained to operate Intercom in compliance with HIPAA. Intercom is a customer service and engagement solution that enables organizations to provide top-quality support for customers via multiple communication channels. Depending on which business plan an organization subscribes to, the platform can provide proactive support with in-context messaging, an AI-powered workspace, and automated workflows. At the highest “Expert” level, Intercom includes advanced collaboration, security, and reporting tools for large support teams. For organizations in the healthcare sector, customer service and engagement solutions such as Intercom can significantly reduce the volume of resources required to run an efficient support center while providing...

Read More
What is a Healthcare Compliance Plan?
Jan24

What is a Healthcare Compliance Plan?

A healthcare compliance plan is a document that outlines the compliance obligations of a healthcare organization, lists what measures already exist to fulfil the compliance obligations, identifies gaps in compliance, and determines what measures are required to fill the gaps. A healthcare compliance plan is a valuable tool for organizations subject to multiple federal, state, local, and industry regulations because it can deduplicate compliance requirements and enhance compliance efficiency. Most healthcare organizations are subject to multiple federal, state, local, and industry regulations. In addition, most comply with voluntary standards to achieve or maintain accreditation. If an organization attempted to comply with each regulation and standard individually, it would likely never likely achieve a state of compliance due to number of duplicated regulations, provisions that preempt provisions of other regulations, multiple training requirements, and the speed at which regulations and standards change. A healthcare compliance plan can simplify compliance planning by combining...

Read More
HC3 Warns of Threat of Unauthorized Remote Access via ScreenConnect Tool
Jan23

HC3 Warns of Threat of Unauthorized Remote Access via ScreenConnect Tool

The ScreenConnect remote access tool has been abused by a threat actor to gain access to the networks of organizations in the healthcare and public health (HPH) sector. According to a sector alert from the Health Sector Cybersecurity Coordination Center (HC3), between October 28 and November 8, 2023, an unknown threat actor abused a locally hosted ScreenConnect instance to gain remote access to victims’ networks. Once access was gained, the threat actor installed further remote access tools including SecureConnect and AnyDesk instances to allow persistent access to victims’ networks. Researchers at the cybersecurity company Huntress identified two attacks on distinct healthcare organizations and the threat actor’s activity suggests network reconnaissance was being conducted in preparation for attack escalation. On November 14, the vendor of ScreenConnect said the threat actor gained access to an unmanaged on-premises instance of ScreenConnect that had not been updated since 2019. The ScreenConnect vendor said the organizations affected had gone against recommended best...

Read More
White House Announces New Actions in Response to Roe v. Wade
Jan23

White House Announces New Actions in Response to Roe v. Wade

To mark what would have been the 51st anniversary of Roe v. Wade, the White House Task Force on Reproductive Healthcare issued a fact sheet announcing new actions to strengthen access to contraception and medication abortions, and ensure that patients receive the emergency medical care they need. The Task Force explained that the overturning of Roe v. Wade resulted in extreme state abortion bans. “These dangerous state laws have caused chaos and confusion, as women are being turned away from emergency rooms, forced to travel hundreds of miles, or required to go to court to seek permission for the health care they need,” wrote the Task Force. The fact sheet explains some of the actions that have been taken by federal agencies in response to President Biden’s three Executive Orders and a Presidential Memorandum on access to reproductive health care, strengthening access to contraception and affordability for women with health insurance, reinforcing obligations to cover affordable contraception, educating patients and care providers about rights and obligations for emergency medical...

Read More
FTC Proposes Settlement Prohibiting InMarket from Selling Consumers’ Precise Location Data
Jan23

FTC Proposes Settlement Prohibiting InMarket from Selling Consumers’ Precise Location Data

The Federal Trade Commission (FTC) has proposed a settlement with the digital marketing platform provider and data aggregator InMarket Media LLC that resolves allegations the company’s business practices violated the Federal Trade Commission (FTC) Act. According to the FTC complaint, InMarket Media obtains vast amounts of consumer data including information from mobile devices about consumers’ movements, purchasing habits, demographic data, and information on their socioeconomic background. InMarket Media retains consumer data for 5 years and uses that data to facilitate targeted advertising on consumers’ mobile devices through its InMarket Software Development Kit (SDK). InMarket Media categorizes consumers into advertising audiences and allows its clients to target consumers on third-party advertising platforms. The FTC alleges that InMarket Media failed to notify consumers that their personal data will be used to serve targeted advertisements and did not verify that mobile applications that incorporate the InMarket SDK have notified consumers about such uses of their...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist