NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Staten Island Health Center to Pay $195,000 to Terminated Whistleblower
Jan22

Staten Island Health Center to Pay $195,000 to Terminated Whistleblower

A Staten Island health center must pay $195,000 in damages and back wages to an employee who was terminated after refusing an in-person meeting during the COVID-19 pandemic out of safety concerns. The incident occurred in March 2020 when cases of COVID-19 started soaring. A Community Health Center of Richmond employee was due to attend a regularly scheduled meeting and requested the meeting be held virtually rather than in person due to the risk of infection. The meeting was due to be held in a windowless room at the health center. The employee changed the format of the meeting to teleconference; however, when the CEO insisted that it must be held in person, the employee changed the format back to in-person and then didn’t attend. The employee was suspended two days later for refusing to attend the meeting and other insubordination, and in April 2020, the employee was terminated without further explanation. In response, the employee filed a complaint with the Occupational Safety and Health Administration under the whistleblower protections of the Occupational Safety and Health Act,...

Read More
HIPAA Compliant Email Marketing
Jan22

HIPAA Compliant Email Marketing

The rules for HIPAA compliant email marketing are complex, subject to multiple exceptions, and can be interpreted in a number of ways depending on the purpose of the marketing email, its content, and whether it even qualifies as a marketing email under HIPAA. Regardless of how the rules are interpreted, the platform used to send HIPAA compliant marketing emails must meet specific security requirements. According to §164.508 of the HIPAA Privacy Rule, a covered entity (or business associate “where provided” by §160.102) must obtain a valid HIPAA authorization “for any use or disclosure of Protected Health Information (PHI) for marketing”. This standard could be interpreted by some sources as implying that covered entities must obtain a valid HIPAA authorization from every intended recipient before sending a marketing email that disclosures their email address. However, this is not the case. Some forms of marketing are not covered by HIPAA, some marketing emails are exempt from the definition of marketing under HIPAA, and some types of marketing emails do not use or disclose PHI...

Read More
Is Stripe HIPAA Compliant?
Jan20

Is Stripe HIPAA Compliant?

Stripe is not HIPAA compliant and – other than its payment processing services – should not be used by covered entities and business associates to create, collect, store, or transmit Protected Health Information (PHI). Stripe does not need to comply with HIPAA for payment processing services due to HIPAA exempting financial transactions from the requirements of the Administrative Simplification Regulations. Despite the exemption, businesses may be restricted in how they can use the payment processing services due to Stripe’s Terms and Conditions. What is Stripe? Stripe is primarily a payment processing platform that enables businesses to collect payments from a customer via a wide range of payment options (credit card, ACH transfer, Apple Pay, Bitcoin, etc.). Businesses can integrate the Stripe API into an online store or app, subscribe to a plan that supports in-person card processing, and/or purchase card readers with tap to pay capabilities. As well as its payment processing activities, Stripe provides billing, identity verification, and fraud management services. The company...

Read More
Increase Staff Productivity & Reduce No-Shows With Better Patient Engagement
Jan20

Increase Staff Productivity & Reduce No-Shows With Better Patient Engagement

Healthcare organizations of any size can streamline workflows, increase staff productivity, maximize revenue and reduce no-shows by up to 90% as benefits of patient engagement technology. Patient-centric functionality enhances patient communications with automation, including appointment notification and reminders, online patient scheduling, waitlist management with last-minute cancellation fulfilment, patient experience surveys, and many other features. These can significantly enhance your patients’ perception and experience of your practice. Typically, HIPAA compliant patient engagement systems integrate easily with all existing practice management software and have a fast return-on-investment. Surveys Show Patients Appreciate Patient Engagement Technology Healthcare providers have been slow to adopt communication technology, but according to an Accenture Survey, 60% of patients prefer to use technology for patient-provider communication. This is in part because the Covid crisis altered patient behaviors and expectations of technology usage in healthcare practices. Patients...

Read More

Meridian Behavioral Healthcare Discloses 99,000-Record Data Breach

Data breaches have recently been reported by Meridian Behavioral Healthcare, Network 180, Erie VA Medical Center, and Fred Hutchinson Cancer Center. Meridian Behavioral Healthcare Meridian Behavioral Healthcare, Inc. in Florida has recently confirmed that protected health information was exposed in a security breach that was detected on August 11, 2023. Third-party cybersecurity specialists were engaged to investigate the breach and on December 4, 2023, confirmed that 98,808 individuals had been affected. Written notifications were mailed on December 22, 2023. The information exposed in the breach varied from individual to individual and may have included names, addresses, Social Security numbers, dates of birth, medical diagnosis and treatment information, health insurance information, and prescription information. Meridian Behavioral Healthcare said it is not aware of any misuse of patient data but has offered the affected individual complimentary credit monitoring services. Additional security measures have been implemented within its network, and data security policies and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist