NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS-OIG Excludes Theranos Founder and CEO from Federal Health Programs for 90 Years
Jan23

HHS-OIG Excludes Theranos Founder and CEO from Federal Health Programs for 90 Years

The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has added the founder and CEO of the health technology firm Theranos, Inc. to the OIG exclusions list, which means Elizabeth Holmes is prohibited from participation in Federal health care programs for 90 years. The Theranos Scandal Theranos was a blood testing startup founded by Elizabeth Holmes in 2003. The company claimed to have developed revolutionary technology that could be used to perform hundreds of blood tests from a single blood sample. Instead of requiring a vial of blood, the technology could perform more than 200 blood tests using a single pinprick of blood. The company claimed its technology automated blood testing and that tests were inexpensive and fast. Holmes was able to raise $700 million in investment and the company was valued at around $9 billion at its peak, with Holmes owning more than half of the company’s shares. The Wall Street Journal Pulitzer Prize-winning journalist John Carreyrou received a tip that the company’s technology was not what it claimed to be. Carreyrou...

Read More
Is HIPAA Training a Federal Requirement?
Jan23

Is HIPAA Training a Federal Requirement?

Yes, HIPAA training is mandated by the Health Insurance Portability and Accountability Act (HIPAA) and is a federal requirement for healthcare providers, insurance companies, and their business associates in the United States to ensure the confidentiality, integrity, and security of protected health information. HIPAA training is mandated by both the HIPAA Privacy Rule (45 CFR § 164.530) and the HIPAA Security Rule (45 CFR § 164.308(a)(5)), requiring healthcare entities to provide regular, role-specific training on handling protected health information (PHI) and electronic PHI (ePHI) to all workforce members, ensuring ongoing awareness and compliance with privacy and security measures. HIPAA Training Required under HIPAA Privacy Rule (45 CFR § 164.530) The HIPAA Privacy Rule mandates that covered entities – which include healthcare providers, health plans, and healthcare clearinghouses – must train all members of their workforce on the policies and procedures with respect to PHI. The HIPAA training must be provided to each new member of the workforce within a reasonable period...

Read More
Is HelloFax HIPAA Compliant?
Jan22

Is HelloFax HIPAA Compliant?

HelloFax is HIPAA compliant provided organizations subscribe to a “Standard” or “Premium” business plan with Dropbox Sign, agree to the terms of the Dropbox Sign Business Associate Agreement, and configure the digital fax service to comply with the Administrative and Technical Safeguards of the Security Rule. In addition, it may also be necessary to train HelloFax users on permissible disclosures of Protected Health Information (PHI) and the Minimum Necessary Standard. In 2019, HelloSign – the parent company of HelloFax – was acquired by Dropbox. The digital fax service was rebranded Dropbox Fax and included in the new Dropbox Sign suite of products.  However, due to the popularity of HelloFax prior to the acquisition of its parent company, the former name is often still used to identify the service. Indeed, the FAQ section of the Dropbox Fax web page, HelloFax is referenced in all the answers to the frequently asked questions. Is Dropbox Fax/HelloFax HIPAA Compliant? When subscribed to as part of a “Standard” or “Premium” Dropbox Sign business plan (*), Dropbox Fax/HelloFax has...

Read More
Is Twilio SendGrid HIPAA Compliant?
Jan22

Is Twilio SendGrid HIPAA Compliant?

Twilio SendGrid is not HIPAA compliant and cannot be used to send email communications containing Protected Health Information (PHI) as to do so would not only be a violation of HIPAA but also a violation of SendGrid’s Terms of Service. However, SendGrid can be used by healthcare organizations to send general healthcare-related communications and marketing campaigns. SendGrid is a versatile email communication platform with multiple features to help organizations automate transactional communications and run effective email marketing campaigns. Since 2019, SendGrid has been part of the Twilio product family and available as a standalone email platform or as part of an integrated customer engagement solution. Making the Use of Twilio SendGrid HIPAA Compliant Although Twilio does offer some HIPAA Eligible Products and Services, SendGrid is not among them. SendGrid states on its website that the platform does not natively support HIPAA compliant data transmission and refers visitors to a clause in its Terms of Service that prohibits customers from “using the service for any purpose or...

Read More

HIPAA Compliance and Healthcare Information

Storing and Communicating Healthcare Information in Compliance with HIPAA When the Final Omnibus Rule enacted regulations within the Health Insurance Portability and Accountability Act (HIPAA) in 2013, it raised issues for healthcare organizations and other covered entities about HIPAA compliance and healthcare information storage and communication. In a healthcare environment in particular, the increased use of mobile devices in the workplace has driven efficiency and accelerated communications. However the new regulations concerning storing and communicating healthcare information in compliance with HIPAA effectively mean that “traditional” channels of mobile communication – such as email and SMS – are no longer considered secure. The Significance of the HIPAA Security Rule Most of the relevant legislation regarding HIPAA compliance and healthcare information is contained within the HIPAA Security Rule. The HIPAA Security Rule includes specific physical, technical and administrative safeguards to prevent healthcare information from being compromised when it is at rest...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist