25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is the Purpose of HIPAA?
Jan08

What is the Purpose of HIPAA?

The purpose of HIPAA was originally to ensure more employees could continue to receive health insurance coverage when they were between jobs and would not be discriminated against for pre-existing conditions. Due to the costs that would be incurred by health plans – and concerns these may be passed on to plan members and employers – Congress added a second Title to the Act to combat fraud and abuse of the healthcare insurance system.  Title II also instructed the Secretary for Health and Human Services to adopts standards to simplify the administration of healthcare transactions between healthcare providers and health plans. Because – prior to HIPAA – health plans had developed their own transaction code structures, more than four hundred sets of codes existed. Determining which code applied to which payer, and translating one code to another, often delayed transactions such as eligibility checks, treatment authorizations, and payment remittances. In additional to adopting standards for healthcare transactions, the Secretary was also instructed to develop...

Read More

What Does HIPAA Stand For?

The acronym HIPAA stands for Health Insurance Portability and Accountability Act of 1996 – an Act which ultimately led to the development of standards for the privacy and security of Protected Health Information, but which originally had the objective of reforming the health insurance industry. To best fully explain what does HIPAA stand for, it is a necessary to look at the state of the health insurance industry prior to 1996. The industry had grown from a handful of companies offering accident insurance in the 1850s – and employer-sponsored disability insurance from 1911 onwards – into a multi-billion dollar business by the end of the twentieth century. However, prior to 1996, the healthcare insurance industry was governed by a hotchpotch of federal and state legislation. The reason for the hotchpotch of legislation was that, in the early days of healthcare insurance, many commercial for-profit insurance providers were considered to be “unlicensed practitioners of medicine” because they indirectly provided medical services to policy holders. To overcome this...

Read More
Business Associate Data Breach Affects 55K Bosch Choice Welfare Benefit Plan Members
Jan07

Business Associate Data Breach Affects 55K Bosch Choice Welfare Benefit Plan Members

A business associate data breach has affected 55,000 members of the Bosch Choice Welfare Benefit Plan, and a data breach has been reported by Leidos QTC Health First Rehabilitation Resources. Bosch Choice Welfare Benefit Plan On October 31, 2025, Bosch Choice Welfare Benefit Plan reported a data breach to the HHS’ Office for Civil Rights (OCR) that affected 55,000 of its members. Bosch Choice Welfare Benefit Plan is a flexible benefits program for Bosch employees in the United States that includes health, dental, vision, life, and disability insurance. While limited details have been made public about the data breach, OCR closed the investigation quickly and has shared information on the incident via its data breach portal. A vendor of one of the health plan’s business associates experienced a cybersecurity incident that involved unauthorized access to systems containing names, Social Security numbers, dates of birth, claims, health insurance information, and diagnoses/conditions. Neither Bosch nor the HHS mentioned the name of the business associate, but the HHS report on...

Read More
Judge Gives First Nod to $1M Community First Medical Center Data Breach Settlement
Jan07

Judge Gives First Nod to $1M Community First Medical Center Data Breach Settlement

A federal judge has given preliminary approval of a $1 million settlement to resolve a consolidated class action lawsuit against Community First Medical Center over a July 2023 data breach. An unauthorized third party accessed the network of the Chicago, IL, medical center on July 12, 2023, and viewed or acquired files containing the protected health information of approximately 216,000 patients, including names, contact information, Social Security numbers, and Medicare numbers. Fifteen class action lawsuits were filed against Community First Medical Center over the data breach. As the lawsuits had overlapping claims, they were consolidated into a single action – Pacheco, et al. v. Community First Healthcare of Illinois, Inc. d/b/a Community First Medical Center – in the Circuit Court of Cook County, Illinois. The lawsuits alleged that Community First Healthcare of Illinois, doing business as Community First Medical Center, failed to implement reasonable and appropriate cybersecurity measures, resulting in a data breach, and engaged in deceptive business practices. The...

Read More
HIPAA and Privacy Act Training
Jan06

HIPAA and Privacy Act Training

When a federal agency provides healthcare services, there may be circumstances in which members of the federal agency’s workforce and onsite contractors are required to be provided with both HIPAA and Privacy Act training. In addition, as an increasing number of states enact their own privacy laws, there may also be occasions when employees of state agencies require HIPAA and Privacy Act training, and state law training. The Privacy Act of 1974 governs the collection, use, storage, and sharing of personally identifiable information maintained by federal agencies. Under the Act, U.S. citizens have the right to request a copy any data held about them and request that any errors are corrected, federal agencies must only collect data “relevant and necessary” to accomplish the purpose for which it is being collected, and sharing data between agencies is restricted and allowed only under certain conditions. People acquainted with the Health Insurance Portability and Accountability Act will find these privacy provisions familiar as they closely resemble Patients’ Rights under...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist