25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Tens of Thousands of Patients Affected by Two Business Associate Data Breaches
Jan19

Tens of Thousands of Patients Affected by Two Business Associate Data Breaches

Mid Michigan Medical Billing Service, a Flint, MI-based revenue cycle management company that provides billing support services to HIPAA-covered entities, has fallen victim to a cyberattack that exposed the sensitive data of patients of its healthcare clients. Suspicious network activity was identified on March 27, 2025, and the forensic investigation confirmed that an unauthorized third party accessed and copied data from its network. The affected data was reviewed to determine the types of information involved and the affected individuals. Mid Michigan Medical Billing Service then notified the affected covered entity clients and worked with them to provide notice to the affected individuals. The Qilin ransomware group claimed responsibility for the attack. The file review confirmed that the protected health information of 28,185 individuals had been exposed in the cyberattack. The compromised data varied from individual to individual and may have included names in combination with one or more of the following: date of birth, driver’s license/ government issued identification...

Read More
Is Google Workspace HIPAA Compliant?
Jan19

Is Google Workspace HIPAA Compliant?

Google Workspace is HIPAA compliant for services that have “included functionality”, provided HIPAA-covered organizations subscribe to a Workspace Plan that supports HIPAA compliance and configure the services to comply with the HIPAA Security Rule. To make Google Workspace HIPAA compliant, it is also necessary to agree to Google’s Business Associate Addendum (BAA) to the Terms of Service Agreement. Google Workspace – formally known as G Suite –  is a collection of productivity and communication services. The services can be used independently or integrated with each other to streamline workflows and enhance collaboration. Workspace is a popular choice for organizations in the healthcare industry because most users already have experience of services such as Gmail and Drive. Most other Workspace services have familiar controls and are intuitive to use. However, most organizations in the healthcare industry are required to comply with HIPAA. HIPAA is a federal law which led to the development of privacy and security standards for “Protected Health Information” (PHI). The...

Read More
What are the HIPAA Laws in Texas?
Jan19

What are the HIPAA Laws in Texas?

The HIPAA laws in Texas are the same as they are anywhere else in the country because HIPAA sets a federal floor of privacy standards for healthcare information – not a federal ceiling. HIPAA does not prevent states from enacting legislation with stronger privacy protections; and, under HIPAA’s preemption framework, state laws that are more protective of individual privacy apply rather than the equivalent provision of HIPAA. Most states have enacted legislation with provisions that apply rather than the equivalent provision of HIPAA. Often these relate to activities that are permitted by HIPAA but not required – for example, when a state mandates reporting non-accidental injuries. In other cases, state laws may require faster responses to patient access requests or relate to a particular area of healthcare – for example, HIV/AIDS test results. What is Different about the HIPAA Laws in Texas What is different about the HIPAA laws in Texas – and the state laws that overlay them – is that while most states limit the applicability of their healthcare privacy laws to...

Read More
What is a HIPAA Audit Checklist?
Jan18

What is a HIPAA Audit Checklist?

A HIPAA audit checklist is a document covered entities and business associates should use to audit compliance with the standards of the HIPAA Administrative Simplification Regulations applicable to their operations. An internal HIPAA audit checklist differs from an external HIPAA audit checklist inasmuch as an external HIPAA audit checklist is designed to meet specific criteria of the OCR audit protocol, CMS’ compliance review program, or a third-party’s certification requirements. By comparison, an internal HIPAA audit checklist is a comprehensive document that covers all areas of an organization’s compliance obligations. However, as different organizations have different compliance obligations, there is no “one-size-fits-all” internal HIPAA audit checklist. Get The HIPAA Audit Checklist Free and Immediate Download Please enable JavaScript in your browser to complete this form.Business Email *Name *FirstLastWork Number *Company Name *Number of EmployeesNumber of Employees1 - 5051 - 500501+Download Free Checklist Delivered via email so please ensure you enter your...

Read More
What is the Best EHR for Mental Health?
Jan18

What is the Best EHR for Mental Health?

The best EHR for mental health is a purpose-designed behavioral health platform that supports psychotherapy and psychiatry workflows, captures structured clinical data with standard instruments, and integrates prescribing, telehealth, labs, billing, registration, and supervision in a single HIPAA-aligned system. Criteria For Mental Health EHR Selection “Best” in a mental health context means the system fits behavioral health care delivery without relying on extensive customization that creates inconsistent documentation, variable data capture, and fragmented operational workflows. A purpose-designed mental health EHR aligns the clinical record with common treatment patterns such as longitudinal care, frequent follow ups, multi disciplinary coordination, and mixed modality services including in person and remote visits. It also supports psychiatric medication management with documentation that reflects monitoring requirements and structured symptom tracking. Features of the Best Mental Health EHRs An EHR selected for mental health should include integrated e-prescribing that...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist