25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What to Do if You Discover a HIPAA Violation in the Workplace
Jan02

What to Do if You Discover a HIPAA Violation in the Workplace

If you discover a HIPAA violation in the workplace, what you should do depends on the nature of the violation, whether or not unsecured PHI has been impermissibly disclosed, and what the potential consequences are. You suspect there has been a HIPAA violation in the workplace, should you report the violation? If so, how should you report the potential violation and who needs to be told? Is it Necessary to Report a HIPAA Violation in the Workplace? If you think you have accidentally violated HIPAA Rules or you believe a work colleague or your employer is failing to comply with the HIPAA Rules, the potential violation(s) should be reported. Since the publication of the HIPAA Enforcement Rule, HIPAA covered entities can be financially penalized for HIPAA violations. If an uncorrected HIPAA violation is discovered during an investigation of a complaint, a data breach, or HIPAA audit, HHS’ Office for Civil Rights (OCR) may choose to pursue a financial settlement to resolve the violation. Such actions are far less likely when a violation has been discovered internally and corrected to...

Read More
What is Considered Protected Health Information Under HIPAA?
Jan02

What is Considered Protected Health Information Under HIPAA?

Health, treatment, or payment information, and any identifiers maintained with this information, is considered Protected Health Information under HIPAA if the information is created, received, maintained, or transmitted by a “covered entity” or by a “business associate”. However, because there are times when a covered entity might not maintain identifying information with health, treatment, or payment information, there is no definitive list of what is considered Protected Health Information under HIPAA. A lack of understanding about what is considered Protected Health Information under HIPAA is one of the primary reasons for HIPAA-related complaints to HHS’ Office for Civil Rights. This is not surprising, as there are times when the same information can be both protected and non-protected depending on how it is maintained. This article provides you with the full and correct definition of Protected Health Information. HIPAA rules and regulations are substantially about protecting PHI and we recommend you use our Protected Health Information Checklist to understand...

Read More
HIPAA Updates and HIPAA Changes in 2026
Jan02

HIPAA Updates and HIPAA Changes in 2026

HIPAA updates and changes happen more frequently than many people are aware of because of the nature of the update or their minor impact on HIPAA compliance. A major update to HIPAA is long overdue, and steps were taken in December 2020 to address the need for HIPAA changes and HIPAA updates when the HHS’ Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) to make multiple changes to the HIPAA Privacy Rule and in December 2024, OCR proposed a long-awaited update to the HIPAA Security Rule. In addition to these proposed updates, there has been an update to align 42 CFR Part 2 – the Confidentiality of Substance Use Disorder Patient Records regulations – more closely with HIPAA, and an update to change the conditions under which PHI relating to reproductive healthcare can be used or disclosed. The Part 2 and reproductive health changes were finalized in 2024; however, the changes to reproductive healthcare privacy were vacated nationwide by a Texas court, which deemed them to be unlawful. A Final Rule implementing the proposed changes to the HIPAA Privacy...

Read More

What are the HIPAA Administrative Simplification Regulations?

The HIPAA Administrative Simplification Regulations are the regulations adopted “to improve the efficiency and effectiveness of the health care system by encouraging the development of a health information system through the establishment of standards and requirements for the electronic transmission of certain health information” (42 USC §1320d). The HIPAA Administrative Simplification Regulations are what most people consider to be HIPAA because they contain the General Provisions and the Enforcement Rule (Part 160), the Standards for Electronic Transactions and Data Elements (Part 162), and the Privacy, Security, and Breach Notification Rules (Part 164). However, the provisions, rules, and standards were not included in the text of HIPAA in 1996. They were published several years later. How the HIPAA Administrative Simplification Regulations Evolved The primary objectives of the Health Insurance Portability and Accountability Act (HIPAA) were to reform the health insurance industry, ensure the continuation of health insurance between jobs, and make health insurance more...

Read More
Effects of Poor Communication in Healthcare
Jan02

Effects of Poor Communication in Healthcare

The effects of poor communication in healthcare can have extremely serious consequences. As with other businesses, poor communication decreases profits; but, in healthcare, communication failures can negatively affect patient outcomes. Poor communications can result in misdiagnoses and other medical mistakes that can easily lead to avoidable health complications and adverse events for patients. In this article, we explore some of the main effects of poor communication in healthcare and suggest strategies to adopt to improve communication between staff and for communicating information to patients. Communication failures most commonly occur during shift changes, when care of a patient is handed over to a different caregiver. When incomplete, inaccurate, or ambiguous information is provided at the changeover, it increases the probability of medical mistakes occurring. Poor communication could lead to patients receiving the wrong treatment or procedure, being given incorrect medication, or could result in delays to essential tests and treatments – all of which may negatively...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist