25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Central Maine Healthcare Data Breach Affects 145,000 Individuals
Jan21

Central Maine Healthcare Data Breach Affects 145,000 Individuals

Data breaches have recently been announced by Central Maine Healthcare, Dermatology Associates in Kentucky, and Reproductive Medicine Associates of Michigan. The Central Maine Healthcare data breach has affected 145,000 individuals. Central Maine Healthcare Central Maine Healthcare, an integrated nonprofit healthcare system serving around 400,000 residents in central and western Maine, has announced a major data breach involving the electronic protected health information of up to 145,000 patients. Suspicious activity was identified within its IT systems on June 1, 2025, and immediate action was taken to secure its systems while an investigation sought to determine the nature and scope of the activity. The investigation determined that between March 19, 2025, and June 1, 2025, an unauthorized third party had access to its network and accessed or acquired files containing sensitive patient data. The file review confirmed that names and Social Security numbers were compromised, in combination with one or more of the following: address, date(s) of service, provider names, treatment...

Read More
HIPAA Training for Pharmacy Staff
Jan21

HIPAA Training for Pharmacy Staff

HIPAA training for pharmacy staff is required because pharmacies routinely create, access, and share protected health information through prescriptions, insurance claims, medication therapy management, patient counseling, and coordination with prescribers and other providers, and training is one of the most practical ways to reduce avoidable disclosures, improve incident reporting, and keep workflows compliant. In most healthcare settings, annual HIPAA training is a widely followed best practice, and all workforce members should receive training that matches their role and the way they interact with patient information. Why HIPAA Training Matters in a Pharmacy Setting Pharmacies handle PHI in high volume and at high speed. The risk is not only unauthorized access to prescription profiles, but also everyday situations such as conversations at the counter, voicemail messages, delivery logistics, prior authorization paperwork, and sharing information with caregivers. HIPAA training helps staff recognize what information is sensitive, when a disclosure is permitted, and what to do when...

Read More
Complying with HIPAA California Law
Jan20

Complying with HIPAA California Law

The difficulty in complying with HIPAA California law is that there are several significant Acts of state privacy legislation that healthcare organizations and their Business Associates have to comply with that overlay provisions of the Health Insurance Portability and Accountability Act (HIPAA). In the context of complying with HIPAA California law as a healthcare organization – or as a Business Associate of a healthcare organization – one of the primary areas of difficulty is understanding the differences between the Acts and where overlaying provisions apply. HIPAA HIPAA provides a federal floor of privacy protections that applies to healthcare organizations who conduct electronic transactions for which the Department of Health and Human Services (HHS) has published standards. Under HIPAA, “Covered Entities” are required to protect the privacy of individually identifiable health information (“Protected Health Information” or “PHI”) and safeguard the confidentiality, integrity, and availability of electronic PHI. HIPAA also applies to Business Associates who receive,...

Read More
Minnesota Department of Human Services Data Breach Affects Over 300K Individuals
Jan20

Minnesota Department of Human Services Data Breach Affects Over 300K Individuals

The Minnesota Department of Human Services (DHS) has notified almost 304,000 individuals about unauthorized access to their demographic records. The records were stored in the MnChoices system, which is used by counties, Tribal Nations, and managed care organizations to support their assessment and planning work for state residents requiring long-term services and support. The system is managed by the third-party vendor, FEI Systems, which notified the Minnesota DHS in November about unauthorized access to data in the system by a user associated with a licensed healthcare provider. While there was a legitimate reason to access limited information in the system, some data was accessed without authorization by the user. The unauthorized access ceased on September 21, 2025, and the user’s access to the system was fully removed on October 30, 2025. For the majority of affected individuals, the information accessed was limited to demographic information, although for 1,206 individuals, additional information was also accessed. Some medical information was accessed, and for certain...

Read More
HIPAA Compliance for Self-Insured Group Health Plans
Jan20

HIPAA Compliance for Self-Insured Group Health Plans

HIPAA compliance for self-insured group health plans – or self-administered health group plans – is a complicated area of HIPAA legislation due to the different ways in which self-insured group health plans can operate and due to potential exemptions from HIPAA compliance. The Administrative Simplification Rule of the Health Insurance Portability and Accountability Act (HIPAA) imposed requirements on health care clearinghouses, certain healthcare providers, and health plans (collectively known as “covered entities”) to comply with national standards for the privacy of individually identifiable health information and the security of electronic Protected Health Information. The standards were developed by the U.S. Department of Health & Human Services and published in 2000 (the HIPAA Privacy Rule) and 2003 (the HIPAA Security Rule). Subsequent amendments, guidelines, and companion Rules have shaped HIPAA compliance for self-insured group health plans to account for advances in technology and changes in working practices. A Breach Notification Rule was added in 2009....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist