25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Value in Health Care Act Seeks to Extend Medicare Payment Incentives for APMs
Jul28

Value in Health Care Act Seeks to Extend Medicare Payment Incentives for APMs

On July 27, 2023, the bipartisan Value in Health Care Act was introduced and seeks to extend the 5% Medicare payment incentives for advanced Alternative Payment Models (APMs) under the Medicare Access and CHIP Reauthorization Act (MACRA), which are due to expire at the end of the year. The Value in Health Care Act was introduced by Reps. Darin LaHood, (R-IL); Suzan DelBene, (D-WA).; Brad Wenstrup, (R-OH); Earl Blumenauer, (D-OR); and Kim Schrier, (D-WA) to ensure that APMs continue to produce high-quality care for the Medicare program and its beneficiaries. The sponsors of the bill explained that value-based care programs have a successful track record of improving outcomes and reducing costs. Some APMs have helped to provide billions of dollars in savings for taxpayers in the past decade and accountable care organizations (ACOs) alone have saved Medicare more than $17 billion while improving quality. One of the problems, however, is that rules implemented to the ACO programs have limited the number of participating providers. While the aim of MACRA was to speed up the transition...

Read More

Health3PT Shares Best Practices for Improving Third Party Risk Management in Healthcare

The Health 3rd Party Trust Initiative (Health3PT) has published the findings of a recent survey of HIPAA-covered entities and their business associates that explored the current state of third-party cyber risk management in healthcare and identified some of the key challenges faced by HIPAA-regulated entities. Supply chain vendors and service providers introduce risks that need to be identified, managed, and reduced to a low and acceptable level; however, the methods used to manage third-party risks are often burdensome and inadequate. According to the survey, which was conducted on 59 HIPAA-covered entities and 128 business associates, significant resources and money are committed to managing third-party risk but 68% of covered entities and 79% of business associates say third-party risk management (TPRM) processes are inefficient and 60% of HIPAA-covered entities and 72% of business associates think TPRM is not effective at preventing data breaches. 55% of healthcare organizations have experienced a data breach in the past year through a third party, and 90% of the most...

Read More

98,000 UT Southwestern Medical Center Patients Affected by MOVEit Cyberattack

UT Southwestern Medical Center (UTSW) has recently confirmed that the protected health information of 98,437 patients was stolen in a cyberattack on May 28, 2023. The Clop ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer solution, gained access to UTSW’s MOVEit server, and exfiltrated files that contained names, medical record numbers, dates of birth, medication names, medication dosages, prescribing provider names. A subset of the affected individuals also had their Social Security numbers stolen. UTSW was notified about the attack by Progress Software on May 30, 2023, and the exploited vulnerability was immediately patched. The German cybersecurity firm KonBriefing has recently announced that its data shows at least 455 organizations were attacked in this campaign, and at least 23 million individuals were affected. The Clop group has recently started posting victim data on its clear web data leak site. Family Vision of Anderson Suffers Ransomware Attack Family Vision of Anderson in South Carolina was the victim of a May 2023...

Read More

Norton Healthcare Facing Class Action Lawsuit Over BlackCat Cyberattack

Norton Healthcare, a Kentucky-based operator of more than 140 clinics and hospitals in Kentucky and Southern Indiana, is facing a class action lawsuit over a May 2023 cyberattack and data breach. Norton Healthcare has only disclosed limited information about the attack; however, the BlackCat ransomware group announced that it was behind the cyberattack and leaked some of the data stolen from Norton Healthcare on its data leak site. The stolen information included names, addresses, email addresses, dates of birth, Social Security numbers, government identification ID numbers, driver’s license numbers, payment/financial institution information, health insurance providers, medical treatment information, medical diagnoses, medications, medical images, and lab test results. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting 501 individuals, and was later updated to 2,500,000 individuals. On July 21, 2023, a class action lawsuit was filed in U.S. District Court on behalf of plaintiff Lanisha Malone and similarly situated individuals who had their sensitive...

Read More
Majority of Americans Mistakenly Believe Health App Data is Covered by HIPAA
Jul26

Majority of Americans Mistakenly Believe Health App Data is Covered by HIPAA

There is a common misconception that the Health Insurance Portability and Accountability Act (HIPAA) applies to health apps; however, the majority of health apps are not covered by HIPAA nor is the health information collected, stored, or transmitted by the apps. HIPAA applies to HIPAA-covered entities – healthcare providers, health plans, and healthcare clearinghouses – and vendors used by those entities, which are classed as business associates. While health apps may collect some of the exact same health data that is maintained by HIPAA-covered entities, the information collected by health apps is not subject to the same privacy and security standards. As such, health information collected by health apps may be transmitted to third parties, sold, or used for purposes that are not permitted under HIPAA. According to a recent ClearDATA Harris Poll survey of 2,000 U.S. adults, 68% of respondents said they were very or somewhat familiar with HIPAA, yet 81% of respondents believed that the health data collected by digital health apps is covered by HIPAA and subject to its...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist