25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is a HIPAA Compliant Cloud Drive?
Nov28

What is a HIPAA Compliant Cloud Drive?

A HIPAA compliant cloud drive is a cloud-based file storage service that has the capabilities to support HIPAA compliance, that is configured to comply with the standards of the HIPAA Security Rule, and that is used compliantly by trained members of the workforce. Since the passage of HIPAA, many healthcare organizations have adopted cloud-based services; and, when these are used to create, receive, maintain, or transmit Protected Health Information, it is important they comply with HIPAA. HIPAA and Cloud Computing The Health Insurance Portability and Accountability Act was enacted just as the use of cloud-based services started to gain popularity in the 1990s. However, it was not until the early 2000s that cloud computing really took off – although healthcare organizations were slow to embrace the cloud. The situation is very different today. According to Market Data Forecast, in 2022 the healthcare cloud computing market was worth $5.22 billion and it is expected to reach $201.1 billion by 2032. 90% of healthcare organizations are already using cloud-based services or plan...

Read More

Multiple Healthcare Providers Affected by Thanksgiving Ransomware Attack

Cyber actors often time their attacks to coincide with holiday periods when IT staffing levels are likely to be reduced to increase the probability of being able to access networks and exfiltrate data undetected, especially during Thanksgiving weekend. This year is no exception. Several healthcare providers have announced that they are currently investigating potential cyberattacks that were detected on or just before Thanksgiving Day. Initially, the cause of the outages was unclear but it has since been determined that this was a ransomware attack on Ardent Health Services. At such an early stage in the investigations, it is unclear if patient data has been exposed or stolen. UT Health East Texas, Texas Tyler, TX-based UT Health East Texas, the operator of 10 hospitals and more than 90 healthcare clinics in East Texas, has confirmed that it experienced a network outage on Thursday, November 24, 2023. Steps were immediately taken to lock down its network to prevent any further unauthorized access. Without access to critical IT systems, ambulances were put on divert; however, care...

Read More

Mission Community Hospital Alerts Patients About May 2023 Cyberattack

Mission Community Hospital, an acute care hospital serving the patients of the San Fernando Valley in California, has started notifying patients that some of their personal and protected health information was exposed in a May 2023 cyberattack. Unauthorized access to its network was discovered on May 1, 2023, and the forensic investigation determined that an unauthorized third party accessed its network the same day, including files that contained patient data. The review of the files revealed they contained names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, health insurance plan member IDs, claims data, and clinical information related to the care received at Mission Community Hospital. Affected individuals have been offered a complimentary one-year membership to a credit monitoring and identity theft protection service. Mission Community Hospital said it has implemented additional safeguards and technical security measures to further protect and monitor its systems. The HHS’ Office for Civil Rights breach portal...

Read More

3 in 5 Patients Accessed Health Records Online or Via Apps in 2022

According to the HHS’ Office of the National Coordinator for Health IT (ONC) there has been a significant increase in the number of patients who are accessing their medical records through patient portals or smartphone apps. Providing patients with easy access to their electronic health records empowers them to make informed decisions about their health and track their progress toward health-related goals, which translates into better patient outcomes. According to the ONC, other benefits include decreased healthcare costs and stronger patient-physician relationships. In 2022, around three in five individuals who were offered access to their health records via an app or patient portal chose to access them, which is a 46% increase from 2020. In 2022, around three in four patients were offered either online access to their medical records or app-based access, which is a 24% increase from 2020. More than half of patients who were offered access viewed their health records at least three times, with one in six individuals accessing their records on six or more occasions. Only one in...

Read More
What to do if Accused of a HIPAA Violation
Nov24

What to do if Accused of a HIPAA Violation

What you should do if accused of a HIPAA violation can depend on the nature of the violation, whether you work for an organization covered by HIPAA, what your role in the organization is, who is making the accusation, and what their role is. Whatever the circumstances, it is important that you do not ignore the accusation; and, if in any doubt about its validity, seek advice. Individuals and organizations can be accused of a HIPAA violation in multiple circumstances. For example, a trainee nurse could be advised by a senior colleague that something they have unwittingly done is a violation of HIPAA, an IT Department could be alerted to software violating HIPAA by a HIPAA Security Officer, or a covered entity could be accused of a HIPAA violation by a patient who has been unable to obtain a copy of their PHI in a timely manner. Further accusations of HIPAA violations can originate from reliable sources such as HHS´ Office for Civil Rights, or from unreliable sources such as a blog post written by an author who does not understand what HIPAA is or who it applies to. Indeed,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist