25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

AAFP Shares Views on State of MACRA and Makes Policy Recommendations
Oct31

AAFP Shares Views on State of MACRA and Makes Policy Recommendations

The American Academy of Family Physicians (AAFP) has responded to a request for information from Congress on a potential solution to address financial uncertainties in the healthcare system associated with Medicare that have been getting progressively worse for years and were exacerbated by the COVID-19 pandemic. In 2015, the Medicare Access and CHIP Reauthorization Act (MACRA) was signed into law and replaced the sustainable growth rate (SGR) formula with the Quality Payment Program (QPP). MACRA changed Medicare’s approach to physician payment to paying providers based on quality, value, and the results of care delivered, instead of the old system that was based on the number of services provided. While the United States invests more in healthcare than many other Western countries, the United States faces poorer healthcare outcomes and has a critical shortage of healthcare providers. One of the problems that has contributed to this is the Medicare Payment System, which has failed to maintain levels of provider reimbursement that adequately incentivize high-quality care. Congress...

Read More
OSHA’s Mission is to Ensure Safe Workplaces
Oct31

OSHA’s Mission is to Ensure Safe Workplaces

OSHA’s mission is to ensure safe workplaces and, to help fulfil this mission, OSHA has the authority to develop and enforce standards that ensure safe and healthy working conditions. OSHA’s mission to ensure safe workplaces is supported by multiple initiatives. For example: OSHA provides training programs for members of the public. OSHA provides tools and resources for in-house safety training. OSHA provides on-site compliance assistance to employers. OSHA responds to safety complaints made by employees. OSHA investigates all workplace fatalities and catastrophes. OSHA receives reports of workplace injuries and illnesses. OSHA provides training grants to non-profit organizations. OSHA publishes safety and health posters, fact sheets, and advice. OSHA organizes workplace safety programs with labor groups. The Occupational Safety and Health Administration (OSHA) was created in 1971 following the passage of the Occupational Safety and Health Act (OSH Act) a year earlier. OSHA’s mission is to ensure safe workplaces in order to reduce the human and economic costs of avoidable injuries...

Read More
HHS Publishes Proposed Rule Establishing Information Blocking Disincentives for Healthcare Providers
Oct31

HHS Publishes Proposed Rule Establishing Information Blocking Disincentives for Healthcare Providers

The Centers for Medicare and Medicaid Services (CMS) at the Department of Health and Human Services (HHS) has published a long-awaited proposed rule that establishes disincentives for healthcare providers that have committed information blocking, as called for by the 21st Century Cures Act. Information blocking is classed as knowingly or unreasonably interfering with the access, exchange, or use of electronic health information, except as required by law or covered by a regulatory exception. The Cures Act requires the Office of Inspector General (OIG) to refer healthcare providers determined by OIG to have committed information blocking to the appropriate agency to be subject to appropriate disincentives using authorities under applicable Federal law, as the Secretary sets forth through notice and comment rulemaking. On June 27, 2023, the HHS OIG published its final rule that implemented information blocking penalties of $1 million per violation for health information technology (IT) developers of certified health IT and other entities offering certified health IT, health...

Read More

HIPAA-Compliant Disaster Recovery

The Health Insurance Portability and Accountability Act (HIPAA) requires healthcare organizations to develop and implement contingency plans. Contingency planning ensures that in the event of a natural or man-made disaster that disrupts operations, the business can continue to function until regular services can be resumed. A HIPAA disaster recovery plan is a critical element of contingency planning. If disaster strikes and access to systems containing patients’ protected health information is blocked, the HIPAA disaster recovery plan is implemented. The disaster recovery plan contains a set of policies and procedures to follow and assigns responsibilities to staff to ensure the fastest possible response and recovery. The HIPAA disaster recovery plan is implemented when a hospital enters into its emergency operations mode. Emergency operations mode involves following pre-defined, tested policies and procedures that ensure health information remains secure and business operations continue while systems and services are restored. Training workforce members to effect an efficient...

Read More

CISA Releases Log Management Tool for Organizations with Limited Cybersecurity Resources

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new logging tool for simplifying log management. The ‘Logging Made Easy’ (LME) tool is available free of charge and is ideal for organizations with limited resources that are looking to strengthen security and reduce their log management burden. CISA based its LME tool on technology developed by the United Kingdom’s National Cyber Security Centre (NCSC) which was decommissioned in March 2023. The technology is now being maintained by CISA and made available to a much wider audience. According to CISA, the LME is “a self-install tutorial for small organizations to gain a basic level of centralized security logging for Windows clients and provide functionality to detect attacks.” The version released by CISA includes pre-built elastic security detection rules to allow security teams to quickly respond to cyber incidents and can show users where administrative commands are being run on enrolled devices, who is using machines, and allows queries can be run based on published Tactics, Techniques, and Procedures...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist