25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Quest Diagnostics Facing Lawsuit for Disclosing Medical Information to Third Party Debt Collectors

Quest Diagnostics and its revenue operations management company, Optum360, were affected by the 2019 cyberattack on the medical billing collection company, American Medical Collection Agency (AMCA). Almost 12 million Quest Diagnostics patients had their protected health information exposed in the incident. Following the attack, Quest Diagnostics and Optum360 faced several class action lawsuits over the data breach, and the legal problems are continuing. Another lawsuit has been filed against Quest Diagnostics and Optum360, not for the data AMCA breach itself, but for the decision to provide confidential medical information to AMCA and other third-party debt collectors, which the lawsuit alleges did not need to be provided to those third parties to allow them to complete their contracted duties.  The lawsuit alleges the provision of unnecessary medical information to debt collection companies is in violation of the California Confidentiality of Medical Information Act (CMIA), which mandates providers only share medical information if they obtain authorization from patients, except...

Read More

What is a HIPAA Compliant Phone Service?

A HIPAA compliant phone service is any voice communication technology that supports compliance with the Administrative Simplification Regulations of the Health Insurance Portability and Accountability Act (HIPAA) when compliance is necessary. Because there are different circumstances in which compliance with this section of HIPAA may or may not be necessary, this article explains: Who does HIPAA apply to, and when does it apply? What does HIPAA say about phone communications? What is a HIPAA compliant phone service? How to make a phone service HIPAA compliant. Conclusion: Be sure to use a HIPAA compliant phone service. Who Does HIPAA Apply To, and When Does It Apply? The Administrative Simplification Regulations of HIPAA apply to health plans, health care clearinghouses, and healthcare providers (“covered entities”) that conduct electronic transactions for which the Department of Health and Human Services (HHS) has published standards. The standards can be found in Part 162 of the Administrative Simplification Regulations. Some Administrative Simplification Regulations of HIPAA...

Read More

176,200 Ortho Alaska Patients Affected by Data Breach

OrthoAlaska has recently notified the HHS’ Office for Civil Rights (OCR) about a HIPAA data breach that has affected 176,203 patients. At present, little is known about the data breach other than it being a hacking/IT incident in which patient information was exposed or stolen. There is currently no mention of the data breach on the OrthoAlaska website. The data exposure could potentially be linked to a data breach at OrthoAlaska in October 2022 that exposed the information of former employees. In that incident, it was determined on March 3, 2023, that employee data was involved, and notifications were issued on April 3, 2023. This post will be updated when further information is obtained. Physical Therapy Patients in New York Had PHI Exposed in Cyberattack Patients of Physio Logic Chiropractic and Physical Therapy, Physio Logic Medicine, and Dr. Patty DiBlasio have had some of their protected health information exposed in a cyberattack. The cyberattack was detected on July 31, 2023, and a comprehensive investigation was launched to determine the nature and scope of the...

Read More
Big Tech and Health Data: How the Landscape is Changing
Oct09

Big Tech and Health Data: How the Landscape is Changing

The relationship between big tech and health data has been a concern for more than a decade due to fears about the monetization of individuals’ health information and the security of data. Now, federal and state regulators are taking steps to force big tech to be more transparent about what health data is collected, how it is used, and how it is protected. The relationship between big tech and health data started almost a quarter of a century ago when, in 1999, Microsoft invested $250 million into the online health and well-being website WebMD. To ensure the success of the venture, Microsoft also underwrote $150 million in doctor subscriptions and $100 million in commitments to sell advertising and sponsorships. Over the next ten years, Microsoft expanded its interest in the healthcare ecosystem with the acquisition of the integrated hospital information platform Azyxxi (now GE Caradigm), the workflow and patient safety system, Global Care Solutions, and the genetic, genomic, metabolomic, and proteomic data management solution Rosetta Biosoftware. As later-developing tech companies...

Read More

HIPAA Compliant SFTP Server

If FTP is required to transfer protected health information, healthcare providers, health plans, healthcare clearinghouses and business associates of HIPAA-covered entities must ensure their service provider uses a HIPAA compliant sFTP server. FTP is a convenient way of sending/receiving medical transcriptions, transmitting electronic medical records and test results, and for transferring files containing ePHI to cloud storage.  However, FTP communications are not secure and file transfers can easily be intercepted. Consequently, healthcare organizations and their business associates must avoid sending any protected health information over FTP. Doing so would be a violation of the HIPAA Security Rule. HIPAA Security Standard §164.306 requires covered entities to ensure the confidentiality, integrity, and availability of ePHI is safeguarded at rest and in transit. In order to send ePHI securely, HIPAA-covered entities can use a secure FTP server. A secure FTP server uses the Secure File Transfer Protocol rather than the generic file transfer protocol to send and receive files,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist