NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

American Vision Partners Settles Data Breach Litigation for $1.75M
Aug28

American Vision Partners Settles Data Breach Litigation for $1.75M

Medical Management Resource Group LLC (MMRC), doing business as American Vision Partners, has agreed to settle class action litigation stemming from a 2024 data breach. MMRC identified suspicious activity within its computer systems on November 14, 2023. The forensic investigation confirmed on or around December 6, 2023, that certain systems had been accessed by an unauthorized third party, and files had been exfiltrated from its network, some of which contained patient information. Data compromised in the incident included names, contact information, dates of birth, medical information, clinical records, and medications. A subset of individuals also had their Social Security numbers compromised. The data breach was reported to the HHS Office for Civil Rights on February 6, 2026, as affecting more than 2.35 million individuals; however, the OCR breach portal was later updated with a slightly smaller figure of 2,264,157 individuals. The class action lawsuit states that approximately 1.6 million Americans were affected by the data breach. Multiple class action lawsuits were filed in...

Read More
Azul Vision Settles HIPAA Right of Access Case for $50,000
Aug28

Azul Vision Settles HIPAA Right of Access Case for $50,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve an alleged violation of the HIPAA Rules, and its 55th penalty under its HIPAA Right of Access enforcement initiative. Azul Vision Inc. is a California-based provider of optometry and ophthalmology services. OCR launched an investigation in response to a complaint from a patient who alleged that she had not been provided with timely access to her medical records. The complaint was filed with OCR in April 2023, three months after the patient submitted a request to Azul Vision for a copy of her health information. She did not receive the requested records until January 2025 – two years after her request was submitted. The HIPAA Privacy Rule gives patients the right to timely access to their medical records for a reasonable, cost-based fee. When a healthcare provider receives a request from a patient wishing to exercise that right, the healthcare provider has 30 days from receipt of the request to provide the requested records, although under...

Read More
Sources for HHS OIG Fraud, Waste, and Abuse Guidelines
Aug27

Sources for HHS OIG Fraud, Waste, and Abuse Guidelines

The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance with all applicable laws and program requirements. The guidelines can be found in many different sources, including guidance documents, advisory opinions, online training programs, and the HHS OIG YouTube channel. The healthcare industry is one of the most highly regulated industries in the U.S. Federal rules and regulations exist that govern patient safety (i.e., PSQIA), data security (i.e., HIPAA), and the physical environment (i.e., OSHA). In addition, each state has its own requirements for licensing healthcare organizations and healthcare practitioners. Failure to comply with these rules, regulations, and requirements can result in fines, facility closures, and/or loss of license. However, the most substantial penalties for non-compliance are often reserved for offenses against the federal government – particularly offenses that relate to fraud, waste, and abuse against a healthcare program operated by the Department of Health and Human...

Read More
HIPAA Without a Law Degree
Aug27

HIPAA Without a Law Degree

A practice does not need legal training to meet HIPAA requirements, because compliance depends on following a defined process correctly, not on interpreting statutory language. The regulation itself is written in legal terms, but the obligations it creates, a risk analysis, policies, training, signed vendor agreements, and documentation, can be met by staff with no legal or compliance background when the process is structured correctly. Why HIPAA Reads Like a Legal Document HIPAA regulations are written as federal law, with definitions, cross-references, and terminology that are not part of daily practice operations. A physician or office manager reading the regulation directly is reading text drafted for legal interpretation, not for implementation. This creates a barrier that has nothing to do with the practice’s actual ability to comply. The obligations underneath the legal language are concrete: identify where patient information is stored and accessed, document policies that address the risks found, train staff on those policies, confirm every vendor with access to that...

Read More
ShinyHunters Leaks 7.1 Million Baxter International Records
Aug26

ShinyHunters Leaks 7.1 Million Baxter International Records

The ShinyHunters data theft and extortion group recently claimed responsibility for an intrusion at the medical device manufacturer Baxter International (Baxter). Baxter was added to its dark web data leak site a day after Baxter issued a statement about a cybersecurity incident. ShinyHunters proceeded to leak around 7.1 million records allegedly stolen in the incident. The data leak suggests that Baxter refused to negotiate payment or that negotiations broke down. Baxter is a Deerfield, Illinois-based manufacturer of medical devices for renal care, IV solutions & infusion pumps, surgical products, inhaled anesthetics, and a range of patient monitoring devices and digital health tools. According to an August 13, 2026, statement from Baxter, unauthorized activity was detected within certain third-party applications. The company immediately activated its cybersecurity response procedures and launched an investigation, with assistance provided by third-party cybersecurity and digital forensics experts. The investigation is ongoing to determine the types and amount of information...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist