25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Saying Someone Died a HIPAA Violation?
Jan19

Is Saying Someone Died a HIPAA Violation?

In answer to the question is saying someone died a HIPAA violation, it depends on who is making the statement, who the statement is made to, and what other information is disclosed with the statement. Saying someone died can be a HIPAA violation, but – as this blog discusses – in most cases it is not. Among other purposes, the HIPAA Privacy Rule protects the privacy of individually identifiable health information relating to the past, present, or future health condition of an individual. Organizations subject to the HIPAA Privacy Rule – and their workforces – must comply with this requirement with respect to a deceased individual “for a period of 50 years following the death of the individual”. However, not all organizations are subject to the HIPAA Privacy Rule. If, for example, an employee of a private nursing home which does not qualify as a HIPAA “covered entity” revealed somebody had died, it is not a HIPAA violation because the nursing home is not required to protect the privacy of individually identifiable health information (Note: although this might not be a violation of...

Read More
Monroe University: 320,000 Individuals Affected by December 2024 Cyberattack
Jan19

Monroe University: 320,000 Individuals Affected by December 2024 Cyberattack

Monroe University, a for-profit university with campuses in the Bronx and La Rochelle in New York, and Saint Lucia in the Caribbean, has recently confirmed that a cyberattack has resulted in unauthorized access to the personal and health information of approximately 320,973 individuals. The cyberattack was detected more than a year ago on December 23, 2024. When the intrusion was detected, immediate action was taken to secure its systems to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized third party had access to its network from December 9, 2024, to December 23, 2024, and exfiltrated files containing sensitive data. It has taken nine months to review the affected files to determine the individuals affected and the types of data involved. On September 30, 2025, Monroe University confirmed that the data compromised in the incident included names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, government...

Read More
HIPAA for Therapists
Jan19

HIPAA for Therapists

When discussing HIPAA for therapists, it is important to be aware that a therapist can be a solo covered entity, a hybrid covered entity, part of an affiliated covered entity, part of an Organized Health Care Arrangement, a business associate to a covered entity, or an employee of any of the above. Even when none of these options apply, therapists may still need to comply with HIPAA-style privacy, security, and breach notification requirements mandated by state legislation. When is a Therapist a Solo Covered Entity? A therapist is a solo covered entity under HIPAA when they work independently of other healthcare providers and conduct transactions electronically for which the Department of Health and Human Services (HHS) has adopted standards. The standards can be found in Part 162 of the HIPAA Administrative Simplification Regulations and relate to processes such as eligibility checks for treatment, authorizations for treatment, and billing for treatment when payment is made by a health plan. A therapist qualifies as a solo covered entity whether or not they conduct the...

Read More
Tens of Thousands of Patients Affected by Two Business Associate Data Breaches
Jan19

Tens of Thousands of Patients Affected by Two Business Associate Data Breaches

Mid Michigan Medical Billing Service, a Flint, MI-based revenue cycle management company that provides billing support services to HIPAA-covered entities, has fallen victim to a cyberattack that exposed the sensitive data of patients of its healthcare clients. Suspicious network activity was identified on March 27, 2025, and the forensic investigation confirmed that an unauthorized third party accessed and copied data from its network. The affected data was reviewed to determine the types of information involved and the affected individuals. Mid Michigan Medical Billing Service then notified the affected covered entity clients and worked with them to provide notice to the affected individuals. The Qilin ransomware group claimed responsibility for the attack. The file review confirmed that the protected health information of 28,185 individuals had been exposed in the cyberattack. The compromised data varied from individual to individual and may have included names in combination with one or more of the following: date of birth, driver’s license/ government issued identification...

Read More
Is Google Workspace HIPAA Compliant?
Jan19

Is Google Workspace HIPAA Compliant?

Google Workspace is HIPAA compliant for services that have “included functionality”, provided HIPAA-covered organizations subscribe to a Workspace Plan that supports HIPAA compliance and configure the services to comply with the HIPAA Security Rule. To make Google Workspace HIPAA compliant, it is also necessary to agree to Google’s Business Associate Addendum (BAA) to the Terms of Service Agreement. Google Workspace – formally known as G Suite –  is a collection of productivity and communication services. The services can be used independently or integrated with each other to streamline workflows and enhance collaboration. Workspace is a popular choice for organizations in the healthcare industry because most users already have experience of services such as Gmail and Drive. Most other Workspace services have familiar controls and are intuitive to use. However, most organizations in the healthcare industry are required to comply with HIPAA. HIPAA is a federal law which led to the development of privacy and security standards for “Protected Health Information” (PHI). The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist