NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Google Pay HIPAA Compliant?
Jan12

Is Google Pay HIPAA Compliant?

Google Pay does not have to be HIPAA compliant because the text of HIPAA exempts entities from HIPAA compliance if they engage in “authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments for a financial institution.” This exemption was confirmed by the Department of Health and Human Services in the preamble to the Final Omnibus Rule in 2013. Because of the exemption, there is no requirement to make Google Pay HIPAA compliant or enter into a Business Associate Agreement with Google before the service can be used by covered entities and business associates to collect payments from patients and plan members. Covered entities and business associates can also use Google Pay to conduct B2B financial transactions. What is Google Pay? Google Pay is a digital payment facilitator. The service enables users to make payments from cards stored in their Google Wallet online, in app, or in-store from a mobile phone, tablet, or Smartwatch with Near-Field Communication (NFC) capabilities. Users can also use the service to send and receive peer-to-peer...

Read More

What is a Healthcare Compliance Program?

A healthcare compliance program is a process of implementing policies and procedures that have been developed to support compliance with federal, state, local, and industry regulations and voluntary standards in the healthcare industry. Because organizations have different compliance obligations, there is no one-size-fits-all healthcare compliance program. However, most compliance programs have the same seven elements: 1. Implement policies, procedures, and standards of conduct. Because healthcare organizations’ compliance activities do not start from scratch (because some privacy or security measures already exist), most compliance programs begin with a healthcare compliance plan. The plan is developed by listing which regulations and standards are applicable to an organization’s activities, assessing the effectiveness of existing compliance measures, and developing a plan to fill the gaps in compliance and other threats or vulnerabilities. 2. Designate a compliance officer and/or compliance team. Several regulations (i.e., HIPAA) require healthcare organizations to designate a...

Read More
What is OIG in Healthcare?
Jan11

What is OIG in Healthcare?

OIG in healthcare stands for the Department of Health and Human Services (HHS) Office of Inspector General (OIG) – the Office within the HHS responsible for reducing waste, fraud, and abuse in HHS programs and improving efficiency. The Office is the largest OIG in any Federal Department, and employs more than 1,650 auditors, evaluators, and investigators, who are supported by teams of staff with legal, technological, and analytical experience. The Background to the Office of Inspector General The Office of Inspector General for the Department of Health, Education, and Welfare (as the HHS OIG was known as at the time) was created in 1976 to “supervise, coordinate, and provide policy direction for auditing and investigative activities relating to programs and operations of the Department”. The Office was also tasked by Congress to detect and prevent fraud and abuse in programs financed by the Department, and to promote efficiency within the Department. One of the first tasks undertaken by the newly created OIG in healthcare was to establish the OIG HHS Exclusions List as required by...

Read More

Assessing Healthcare Compliance Gaps

Assessing healthcare compliance gaps can be challenging due to first having to identify which healthcare regulations and standards an organization is required to comply with before it is possible to compare the required state of compliance with the existing state of compliance in order to identify where gaps exist. Organizations in the healthcare industry have to comply with many different federal, state, and industry laws. They may also choose to adopt voluntary standards to maintain a professional accreditation or to demonstrate a good faith effort to be compliant. Due to the number of laws, standards, and other regulations, there are many examples of when compliant efforts can conflict with each other or duplicate each other. The number of conflicts and duplications can make assessing healthcare compliance gaps challenging. In addition, one of the most important laws affecting healthcare compliance – HIPAA – includes a clause that permits a “flexibility of approach” when deciding which security measures to implement. This clause could exempt an organization from complying with...

Read More

PHI Exposure Reported by Lone Peak Physical Therapy and First Choice Dental

Patient Records Potentially Viewed at Lone Peak Physical Therapy Lone Peak Physical Therapy, the operator of 10 physical therapy centers in Montana, had a break-in at its Bozeman billing office and clinical space on October 21, 2023. The robbery was detected on Monday, October 23, 2023, when staff returned to work. The robbery was reported to law enforcement and an inventory was conducted to determine which items had been stolen. They included a safe containing patient payments, billing information, and laptop computers. The laptop computers were encrypted so data on those devices cannot be accessed, nor can they be used to access the network. If the intruder attempts to pawn any of the stolen data, the Gallatin County Sheriff’s Department will be notified. There were locked filing cabinets in the office that contained hard copies of patient records. Lone Peak Physical Therapy said none of the hard copies appear to have been removed, but it is not possible to tell if any of those files were viewed. The files contained the records of 5,809 patients and out of an abundance of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist