25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

ONC Proposes New Rule to Advance Care Through Technology and Interoperability
Apr17

ONC Proposes New Rule to Advance Care Through Technology and Interoperability

The HHS’ Office of the National Coordinator of Health IT has proposed a new rule that is intended to advance care through technology and interoperability. The new rule – Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI) – implements certain provisions of the 21st Century Cures Act and makes enhancements to the ONC Health IT Certification Program. The aim of the new rule, which runs to 556 pages, is to advance interoperability, improve transparency, and support the access, exchange, and use of electronic health information which will help to promote innovation and improve data security. The updates cover the movement of health information, introduce new data standards, improve electronic case reporting to support the response to a public health emergency, ensure greater transparency of artificial intelligence algorithms, and changes to improve patient privacy. Implementing the Electronic Health Record Reporting Program The new rule implements the 21st Century Cures Act requirement to establish an EHR...

Read More

CISA Updates its Zero Trust Maturity Model

The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Zero Trust Maturity Model, the purpose of which is to help federal agencies adopt zero trust security. While the guidance is primarily intended for federal agencies, it can be used by any organization looking to improve its security posture through zero trust. The traditional approach to security involves perimeter defenses to keep unauthorized individuals out of protected internal networks, where anyone inside the network is trusted. The perimeter security model has served organizations well for many years, but it is only effective when there is a border to protect and the vast majority of IT resources and critical assets are inside that border. Today, most networks are not entirely on-premises and remote working is now common, so many trusted individuals are outside of the border. Further, with perimeter security, if the perimeter is breached, an attacker could compromise large parts of the network, IT resources, and critical data. Zero trust is based on the assumption that a...

Read More

Online Alcohol Counseling Service Provider Reports 109K-record Tracking Tool Data Breach

Monument Inc., a New York-based online alcohol addiction and treatment service provider, has recently notified almost 109,000 individuals about an impermissible disclosure of some of their personal and protected health information. The disclosure occurred due to the use of tracking code on its websites. Monument explained in its breach notification letters that an internal review was conducted in late 2022 into the use of website tracking tools after guidance was issued by the HHS’ Office for Civil Rights on pixels and other tracking tools and how they may violate the HIPAA Rules. The internal review was completed on or around February 6, 2023, and it was determined that the tools on its websites potentially transferred identifiable protected health information to third parties who were unauthorized to receive the information, as consent to disclose that information was not obtained and there were no business associate agreements with the companies that provided the tools. The tracking tools were provided by Google, Facebook (Meta), Pinterest, and Bing, and while present on the...

Read More

ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients

The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal information of 20,815 Iowans who receive Medicaid was exposed in a cyberattack at a subcontractor of one of its business associates between June 30, 2022, and July 5, 2022. Telligen performs annual assessments on Medicaid recipients for the Iowa DHSS. Telligen subcontracted part of the work to Independent Living Systems (ILS), and it was the systems of ILS that were breached. While ILS discovered the breach in July 2022, it took until February 14, 2023, for Telligen to be notified about the breach. Telligen notified the Iowa DHSS three days later on February 17, 2023. The DHSS will be sending notification letters to the affected individuals over the next few days. Independent Living Systems reported the breach to the HHS’ Office for Civil Rights using a 501 placeholder until the number of affected individuals is determined; however, the breach was reported to the Maine Attorney General as affecting more than 4 million individuals. You can read more about the...

Read More
Revised American Data Privacy and Protection Act Due to be Released
Apr14

Revised American Data Privacy and Protection Act Due to be Released

Last month, the U.S. House of Representatives’ Committee on Energy and Commerce held the third of three scheduled meetings ahead of a release of a new draft of the American Data Privacy and Protection Act (ADPPA), which is edging closer to being the first, comprehensive federal privacy legislation to be signed into law in the United States. There is a clear need for greater privacy protections for Americans. Big tech firms are collecting huge volumes of sensitive data on Americans and there are few restrictions on how consumer data can be collected, used, and shared. There is mounting concern over the collection and use of the data of minors, the serving of targeted advertisements to children and teenagers based on the personal data collected by tech firms, and the sheer volume of data that is being collected on all Americans. Currently, privacy regulations are implemented at the state level, and they can vary vastly across the country. ADPPA seeks to address this by placing restrictions on the collection and use of consumer data at the federal level and replacing the current...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist