25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is HIPAA Safe Harbor and how does Cybersecurity Training help?
Jan17

What is HIPAA Safe Harbor and how does Cybersecurity Training help?

The HIPAA Safe Harbor Law, as integrated into the proposed HIPAA Security Rule update, potentially benefits organizations that can prove they have implemented and maintained recognized security practices over time. Healthcare focused cybersecurity training plays an important part in showing that those practices are understood and used by the workforce rather than only written in policy documents. What is HIPAA Safe Harbor and Where Does Training Fit in? The HIPAA Safe Harbor Law, added to the HITECH Act in 2021 as HITECH Act section 13412, “Recognition of Security Practices”, instructs the Department of Health and Human Services (HHS) to consider whether a HIPAA Covered Entity or HIPAA Business Associate had recognized security practices in place for at least twelve months before a security related HIPAA incident. If those practices can be demonstrated, HHS may reduce penalties, shorten audits, or take a more favorable view of remedial actions. Recognized security practices often come from frameworks such as NIST cybersecurity standards or sector specific guidance, but those...

Read More

HIPAA Rules for Dentists

The HIPAA Rules for dentists are the same as for any other healthcare provider that qualifies as a HIPAA covered entity inasmuch as, if a dentist qualifies as a HIPAA covered entity, they must comply with the applicable standards of the HIPAA Privacy, Security, and Breach Notification Rules. However, not all dentists qualify as a covered entity, and certain HIPAA regulations for dental offices may not apply in every state if the state has passed a privacy law with more stringent data protection or increased patient rights. The issue of HIPAA in dentistry is a complex one. This can because some dentists do not fulfil the criteria to be covered entities and others may have hybrid roles, provide services to a covered entity as a business associate, or operate in a state with more stringent privacy laws than HIPAA. It is not only dentists that find the HIPAA Rules for dentists challenging. 65% of complaints from members of the public relating to HIPAA violations are dismissed after review due to not having an eligible case for action. While not all the complaints are attributable to...

Read More
Final Rule Implementing Proposed HIPAA Privacy Rule Changes Edges Closer
Jan16

Final Rule Implementing Proposed HIPAA Privacy Rule Changes Edges Closer

In January 2021, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published a proposed update to the HIPAA Privacy Rule – Modifications to the HIPAA Privacy Rule to Support, and Remove Barriers to, Coordinated Care and Individual Engagement. The purpose of the update is to revise the HIPAA Privacy Rule to strengthen individuals’ rights to access their own health information, improve care coordination, and reduce the compliance burden on healthcare providers and health plans, while continuing to protect the privacy of patients. Under the Biden administration, the proposed update did not appear to be a priority for the HHS, and there have been no signs during the first year of the new Trump administration that a final rule is any closer to being published; however, that changed on January 14, 2026, when OCR Director Paula M. Stannard published a notification of Tribal consultation on the 2021 Rule in the Federal Register. It has been five years since the proposed update to the HIPAA Privacy Rule was published in the Federal Register, and while...

Read More
How Employees Can Help Prevent HIPAA Violations
Jan16

How Employees Can Help Prevent HIPAA Violations

Employees can help prevent HIPAA violations by fully understanding what PHI is, knowing when PHI can permissibly be used and disclosed, and by following their employers’ policies on the compliant use of healthcare technologies and communication devices. Employees can also help prevent HIPAA violations by reporting poor practices they identify to a manager or compliance officer. One of the key goals of compliance officers is to prevent HIPAA compliance violations whenever possible. To achieve this goal, many compliance officers rely on technological solutions or sanctions policies to deter employees from noncompliant behaviors. However, by taking a more positive approach, employees can help prevent HIPAA violations. Use the article in conjunction with our free HIPAA Violations Checklist to understand what is required to ensure full compliance. Please use the form on this page to arrange for your copy. Most Frequent Complaints According to the Department of Health and Human Services’ Enforcement Highlights web page, the most frequent complaint received by HHS’ Office for...

Read More
Epic Sues Health Information Exchange Network Alleging Improper Record Access
Jan16

Epic Sues Health Information Exchange Network Alleging Improper Record Access

Epic Systems, the market-leading electronic medical record system provider, has filed a lawsuit against the health information network Health Gorilla and several of its clients, alleging improper access to the records of 300,000 patients. The lawsuit, which also names OCHIN Inc, Reid Hospital & Health Care Services Inc. (Reid Health), Trinity Health Corporation, and UMass Memorial Health Care Inc., as plaintiffs, alleges bad actors have fraudulently obtained access to patient data and are abusing access for financial gain. The lawsuit seeks to put an end to the exploitation of health information exchange frameworks for obtaining and monetizing patient data. The lawsuit alleges that certain Health Gorilla clients are turning nationwide interoperability frameworks into data marts, where sensitive patient data can be bought and sold without patients’ or physicians’ knowledge or consent, including patient data stored in Epic’s interoperability framework. Two national frameworks – Carequality and TEFCA – are responsible for almost one billion patient-record exchanges each...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist