25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

How Should You Respond To An Accidental HIPAA Violation?
Jan05

How Should You Respond To An Accidental HIPAA Violation?

How you should respond to an accidental HIPAA violation depends on the nature of the accidental violation and the potential consequences. Examples of accidental HIPAA violations that would require different responses because of their nature and/or potential consequences include: Sending a single email containing PHI to the wrong recipient. Sending 1,000 emails containing PHI to the wrong recipients. Unknowing use of shadow IT for storing PHI without a BAA. Unknowing use of shadow IT for storing PHI insecurely. Failing to obtain an authorization before disclosing SUD records. Disclosing more than the minimum necessary PHI for a permitted use. Allowing a colleague to use login credentials under supervision. Sharing login credentials with multiple colleagues with no supervision. In this article, we outline what exactly to do when there is an accidental HIPAA violation. You can also use the article in conjunction with our free HIPAA Violations Checklist to understand what is required to ensure full HIPAA compliance. Use any form on this page to arrange for your copy of the checklist....

Read More
What is the HIPAA Safe Harbor Law?
Jan05

What is the HIPAA Safe Harbor Law?

The HIPAA Safe Harbor Law (HR 7898) is an amendment to the HITECH Act passed by Congress in 2021 which instructs the Secretary of Health and Human Services to take into account existing security practices when determining penalties for HIPAA violations. Organizations that have adopted a recognized security framework will also benefit from less disruptive corrective action plans and audits. In 2009, the HITECH Act amended the HIPAA Enforcement Rule by introducing a four-tiered penalty structure and by increasing the maximum civil monetary penalties that could be imposed by HHS’ Office for Civil Rights for HIPAA violations. The structure has stayed in place ever since and the penalties have increased annually since 2015 to account for inflation. The 2021 amendment to the HITECH Act came as the result of a Request for Information issued by the Department of Health and Human Services (HHS). The Request for Information had the objectives of exploring ways the administrative burden on Covered Entities and Business Associates could be reduced and data sharing could be improved for better...

Read More
Illinois Department of Human Services Exposes Sensitive Data of 700,000 Individuals Online
Jan05

Illinois Department of Human Services Exposes Sensitive Data of 700,000 Individuals Online

The Illinois Department of Human Services (IDHS) has announced a major data breach affecting hundreds of thousands of state residents, whose sensitive data has been exposed online. IDHS created planning maps to assist with resource allocation and decision-making, which were added to a mapping website. On or around September 22, 2025, IDHS discovered that the website, which was intended for internal department use only, was accessible via the public Internet. Upon discovery, the website was immediately secured, and an investigation was launched to determine the cause of the error and the extent of any data exposure. The investigation revealed that sensitive data had been exposed online for up to four years between 2021 and 2025. The planning maps had been created by the IDHS Division of Family and Community Services’ Bureau of Planning and Evaluation, which inadvertently misconfigured the privacy settings. Following a comprehensive review, IDHS determined that the protected health information of approximately 672,616 Medicaid and Medicare Savings Program recipients had been exposed...

Read More

HIPAA Explained

Our HIPAA explained article provides information about the Health Insurance Portability and Accountability Act (HIPAA) and the Administrative Simplification Regulations – which include the HIPAA Privacy Rule, HIPAA Security Rule, and Breach Notification Rule.    What is HIPAA? The Health Insurance Portability and Accountability Act (HIPAA) is an Act passed in 1996 that primarily had the objectives of enabling workers to carry forward healthcare insurance between jobs, prohibiting discrimination against beneficiaries with pre-existing health conditions, and guaranteeing coverage renewability multi-employer health insurance plans. At the time, the cost of health insurance was rising rapidly. To prevent health insurance companies further increasing premiums and deductibles due to the costs associated with the portability and accountability provisions, cost-cutting measures were added as the Act passed through Congress to reduce health care fraud and to make the administration of health claims processing more efficient. Further measures relating to medical liability reform,...

Read More
What is HIPAA Authorization?
Jan05

What is HIPAA Authorization?

A HIPAA authorization is a form that must be completed by a patient or a health plan member when a covered entity wishes to use or disclose PHI for a purpose not permitted by the HIPAA Privacy Rule. The failure to obtain a valid HIPAA authorization is considered a serious violation of HIPAA compliance. What is HIPAA Authorization? The HIPAA Privacy Rule (effective since April 14, 2003) introduced standards covering allowable uses and disclosures of health information, including to whom information can be disclosed and under what circumstances protected health information can be shared. The HIPAA Privacy Rule permits the sharing of health information by healthcare providers, health plans, healthcare clearinghouses, business associates of HIPAA-covered entities, and other entities covered by HIPAA Rules under certain circumstances. In general terms, permitted uses and disclosures are for treatment, payment, or health care operations, and reporting issues such as domestic abuse to public health agencies. HIPAA authorization is written consent obtained from a patient or health plan...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist