NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

VA OIG Identifies Security Deficiencies in Audit of VA Spokane Healthcare System
Feb23

VA OIG Identifies Security Deficiencies in Audit of VA Spokane Healthcare System

An audit of the Department of Veterans’ Affairs Spokane Healthcare System in Washington state by the Department of Veterans Affairs Office of Inspector General (VA OIG) identified deficiencies in all three control areas inspected: configuration management, security management, and access controls. The audit was conducted on the Mann-Grandstaff VA Medical Center between January 29 and February 6, 2025, which has approximately 1,300 employees and provided care to 27,000 patients in fiscal year 2024. There were several instances where staff failed to remediate critical and high-severity vulnerabilities within the 60-day time frame stipulated by the VA, and in some cases had failed to develop the required action plans to remediate those vulnerabilities within that time frame. VA OIG also identified systems that were running unsupported software, and several devices were identified that had not been configured to VA-approved security baselines. These deficiencies increased the risk of unauthorized access and operational disruption, especially the failure to meet the security baselines...

Read More
Senators Demand Answers from Labor Secretary on Decline in OSHA Safety & Health Enforcement
Feb23

Senators Demand Answers from Labor Secretary on Decline in OSHA Safety & Health Enforcement

Six Democratic Senators have written to the United States Secretary of Labor, Lori Chavez-DeReme, demanding answers about an apparent rollback of safety rules and reduced oversight of workplace safety and health. Senators Elizabeth Warren (D-MA), Angela Alsobrooks (D-MD), Tammy Baldwin (D-IL), Richard Blumenthal (D-CT), Alex Padilla (D-CA), and Ron Wyden (OR) questioned whether the Trump administration is discouraging the enforcement of workplace safety laws, and whether the sharp reduction in inspections and penalties is a precursor to the elimination of key safety regulations that were established to keep American workers safe. Sen. Warren was confidentially provided with data that shows a 20% reduction in workplace inspections by the Department of Labor’s Occupational Safety and Health Administration (OSHA) between April 2025 and September 2025, compared to the corresponding period the previous year. The data also show a 42% reduction in inspections with citations for willful violations. While there may have been improvements to workplace safety, resulting in fewer citations for...

Read More
Interview: Hoala Greevy, Founder & CEO, Paubox
Feb23

Interview: Hoala Greevy, Founder & CEO, Paubox

The HIPAA Journal has spoken with Paubox founder and CEO, Hoala Greevy to find out more about their work and experiences with HIPAA. Tell the readers about your career in the healthcare industry My journey in healthcare began in 2014, following a lunch meeting with Siana Austin Hunt, who was CEO of the Make-A-Wish Foundation of Hawaii at the time. She explained a business problem to me and after some thought, I decided to do something about it. From there we built a seamless email encryption solution that became Paubox. What was your first position? My first job out of college was working for an email company in San Francisco in 1999. I’ve been doing email ever since. What is your current position? I’m the Founder and CEO of Paubox. What are the main challenges in your position? Communicating the mission, vision, and future direction of Paubox to staff, investors, and customers. I’ve found in my role, there is no such thing as over-communicating. Tell the readers about any significant event in your career. During my first semester taking computer science courses...

Read More
What are the HHS OIG Anti-Kickback Regulations?
Feb20

What are the HHS OIG Anti-Kickback Regulations?

The HHS OIG anti-kickback regulations prohibit the remuneration of individuals or organizations in Federal healthcare programs when the purpose of the remuneration is to induce referrals – or is in return for referrals – for items or services reimbursable by a Federal healthcare program. Individuals and organizations that violate the regulations can be fined, imprisoned, and/or excluded from all federal healthcare programs. The HHS OIG anti-kickback regulations were introduced in 1972 as a safeguard against fraud and abuse in federal healthcare programs such as Medicare and Medicaid. Originally only relating to financial transactions, the HHS OIG anti-kickback regulations have been subsequently extended to include any form of monetary or “in-kind” remuneration offered, solicited, paid, or received in exchange for items or services billable to a federal healthcare program. According to its November 2023 interpretation of remuneration, HHS OIG states “remuneration includes anything of value, whether in cash, in kind, or other form. […] Remuneration may take the form of cash,...

Read More
Audit of Utah Department of Health and Human Services Identifies Critical Privacy & Security Weaknesses
Feb20

Audit of Utah Department of Health and Human Services Identifies Critical Privacy & Security Weaknesses

An audit of the Utah Department of Health and Human Services (DHHS) by the Office of the Utah State Auditor has identified privacy and security weaknesses that are putting the health information privacy of state residents at risk, especially children. The audit was conducted in response to a complaint by a DHHS whistleblower employee who alleged that the DHHS had not implemented adequate incident response procedures and had insufficient monitoring mechanisms for detecting and managing privacy incidents. According to the complainant, the deficiencies have resulted in under-reporting of incidents and unmitigated exposure of sensitive data, especially the data of children. The audit was led by Tina M. Cannon, State Auditor; Nora Kurzova, State Privacy Auditor; and Mark Meyer, Assistant State Privacy Auditor, and involved a review of applicable laws related to incident response and data protection, a privacy risk assessment of the most significant data processing activities as they relate to children, an evaluation of incident response documentation and internal privacy and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist