25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Google Voice HIPAA Compliant?
Sep06

Is Google Voice HIPAA Compliant?

Google Voice is HIPAA compliant and can be used to collect, store, or share PHI provided the service is used as part of a business Workspace or Cloud Identity plan and a Business Associate Addendum is signed with Google. The free consumer version of the service should not be used to collect or share PHI as this version lacks the controls to support HIPAA compliance. Is Google Voice HIPAA Compliant? Google Voice is a popular and convenient telephony service that includes voicemail, voicemail transcription to text, the ability to send text messages free of charge, and many other useful features. Due to its capabilities, it is unsurprising that many healthcare professionals would like to use the service at work, as well as for personal use. In order for any service to be used in healthcare to collect, store, or share protected health information (PHI), it must include several capabilities that can be configured to support HIPAA compliance. There would need to be access and authentication controls, audit controls, integrity controls, and transmission security for messages sent through...

Read More
What Does OSHA Do?
Sep05

What Does OSHA Do?

The Occupational Safety and Health Administration (OSHA) is a federal agency within the U.S. Department of Labor that is responsible for the regulation and enforcement of workplace safety and health standards, and the provision of training and outreach to educate workers and employers on best safety and health practices. This article answers the questions what does OSHA do about: Developing Safety Standards Requiring Hazard Communications Recordkeeping and Reporting Training and Outreach Enforcing OSHA Standards Emergency Preparedness and Response Protecting Whistleblowers from Retaliation What Does OSHA Do about Developing Safety Standards When OSHA was first established in 1971, it was instructed to adopt standards for workplace safety and health within two years. Due to the tight timeframe, the agency started by adopting existing standards from sources such as the American National Standards Institute and the National Fire Protection Administration, and states that had existing safety and health programs. Once a base of standards had been adopted, OSHA set about developing new...

Read More
Healthcare Facilities Symposium and Expo: September 19-21, Charlotte, NC
Sep05

Healthcare Facilities Symposium and Expo: September 19-21, Charlotte, NC

The annual Healthcare Facilities Symposium and Expo will take place at the Charlotte Convention Center in North Carolina, September 19-21. The event is one of the country’s largest shows dedicated to healthcare design and facilities and is now in its 36th year. Each year, the event is attended by architects, designers, engineers, contractors, healthcare providers, and government agencies who share their research and ideas and provide fresh perspectives on the ever-changing healthcare industry. Attendees will be able to attend compelling keynote presentations, networking events, and informative sessions. The educational and insightful sessions, case studies, and keynotes are meant to inspire and improve current and future healthcare facilities. There will be more than 60 sessions over the 3-day event where attendees can hear from architects, engineers, contractors, and healthcare providers, and gain takeaways to implement in their current and upcoming projects, as well as earn up to 15.25 CEUs from the AIA, IDCEC and EDAC. The sessions will span multiple topics including Pediatrics,...

Read More
Employee Health Plan Data Exposed in Forever 21 Data Breach
Sep04

Employee Health Plan Data Exposed in Forever 21 Data Breach

Fashion retailer Forever 21 has notified the Maine Attorney General of a data breach in which the health plan data of 539,207 current and former employees was exposed. Breach notification letters are being sent to everyone potentially affected by the breach. However, the letters reveal little about the nature of the attack or what specific data was exposed. According to the notification published on the Maine Attorney General website, Forever 21 experienced an “external system breach” between January 5 and March 21, 2023. The nature of the information breached is “name or other personal identifier in combination with Social Security number”, and identity theft services are being offered to those potentially affected. The notification also includes a link to the company’s breach notification letter to potentially affected individuals. The letter provides limited information about the nature of the attack or what specific data was exposed, stating that an unauthorized third party “accessed certain Forever 21 systems” and “obtained select files from certain Forever 21 systems”. With...

Read More

Essential Elements of the MSP Security Stack

Managed service providers are being increasingly used by healthcare providers to help them achieve HIPAA Security Rule compliance. Here we explore the essential elements of the MSP security stack that are needed to meet the needs of healthcare organizations. Growing Demand for MSP Security Services The healthcare industry has long been a target for cybercriminals and cyberattacks and data breaches are increasing each year, with threat actors developing increasingly sophisticated ways of breaching defenses and gaining access to sensitive healthcare data. To protect against these threats, healthcare organizations need to adopt a defense-in-depth strategy, where multiple cybersecurity solutions are deployed to protect their network, applications, and data, along with monitoring solutions to rapidly detect breaches of their defenses. They also need to implement and test an incident response plan for when hackers succeed. That is a massive job for any healthcare organization and one that many small- and medium-sized healthcare organizations struggle with. It is therefore no surprise...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist