25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

PeaceHealth Employee Accessed Medical Records Without Authorization for Almost 6 Years
Sep29

PeaceHealth Employee Accessed Medical Records Without Authorization for Almost 6 Years

PeaceHealth, a not-for-profit Catholic health system based in Vancouver, WA, has discovered one of its former employees had accessed the medical records of almost 2,000 of its patients without any legitimate work reason for doing so. The unauthorized access was discovered by PeaceHealth on August 9, 2017, triggering an investigation. PeaceHealth determined the improper access started in November 2011 and continued until July 2017. The investigation confirmed Social Security numbers and financial information were not accessed by the employee, although patient names, medical record numbers, admission and discharge dates, medical diagnoses, and progress notes were all viewed. Due to the nature of information that was accessed, and the results of the internal investigation, PeaceHealth does not believe any patients impacted by the breach are at risk of identity theft. However, all impacted individuals have been advised to remain vigilant and review their credit reports and account statements for any sign of fraudulent activity. Patients impacted by the breach had visited either the...

Read More

Ransomware Attack Potentially Impacts 128,000 Arkansas Patients

Arkansas Oral Facial Surgery Center in Fayetteville has experienced a ransomware attack that has potentially impacted up to 128,000 of its patients. Ransomware was believed to have been installed on its network between July 25 and 26, 2017. The attack was detected rapidly, although not before files, x-ray images, and documents had been encrypted. The incident did not result in the encryption of its patient database, except for a ‘relatively limited’ set of patients who data related to their recent visits encrypted. Those patients had visited the center for medical services in the three weeks prior to the ransomware attack. The ransomware attack is still under investigation, although to date, no evidence of data theft has been found. Arkansas Oral Facial Surgery Center believes the sole purpose of the attack was to extort money, and not to steal data; however, it has not been possible to rule out data access or data theft with a high degree of certainty. The files and images that were potentially accessed included information such as names, addresses, dates of birth, Social Security...

Read More
HITRUST/AMA Launch Initiative to Help Small Healthcare Providers with HIPAA Compliance
Sep27

HITRUST/AMA Launch Initiative to Help Small Healthcare Providers with HIPAA Compliance

HITRUST has announced it has partnered with the American Medical Association (AMA) for a new initiative that will help small healthcare providers with HIPAA compliance, cybersecurity, and cyber risk management. Small healthcare providers can be particularly vulnerable to cyberattacks, as they typically lack the resources to devote to cybersecurity and do not tend to have the budgets available to hire skilled cybersecurity staff. This week has underscored the need for small practices to improve their cybersecurity defenses, with the announcement of two cyberattacks on small healthcare providers by the hacking group TheDarkOverlord. Recent ransomware attacks have also shown that healthcare organizations of all sizes are likely to be attacked. Organizations of all sizes must practice good cyber hygiene and have the right defenses in place to improve resilience against ever changing cyber threats. HITRUST and AMA will be hosting 2-hour workshops where physicians and other healthcare staff will be educated on key areas of risk management, HIPAA compliance, and cybersecurity, with the...

Read More
SonicWall Responds to Increasing Cyber Threats with Major Expansion of Cybersecurity Solutions
Sep27

SonicWall Responds to Increasing Cyber Threats with Major Expansion of Cybersecurity Solutions

The massive rise in new ransomware and malware variants, and the increasing sophistication of cyberattacks on businesses have been accompanied by unprecedented innovation at SonicWall, which has rapidly expanded its range of cybersecurity solutions in response to the growing demand for more powerful solutions. SonicWall has now released its new SonicOS operating system, which includes more than 50 new features to enhance security and is the biggest customer-driven release in the history of the company. The SonicOS (v6.5) powers SonicWall’s Automated Real-Time Breach Detection and Prevention Platform. The new release has enhanced threat API capabilities that allow businesses to automate security systems and incorporate third-party intelligence feeds. New wireless features improve connectivity for an increasingly mobile workforce and help security teams enforce their policies across the entire organization. Advanced networking and connectivity capabilities have also been introduced to provide uninterrupted threat protection for connected networks of all types and sizes. The new...

Read More
The Benefits of Using Blockchain for Medical Records
Sep26

The Benefits of Using Blockchain for Medical Records

Blockchain is perhaps best known for keeping cryptocurrency transactions secure, but what about using blockchain for medical records? Could blockchain help to improve healthcare data security? The use of blockchain for medical records is still in its infancy, but there are clear security benefits that could help to reduce healthcare data breaches while making it far easier for health data to be shared between providers and accessed by patients. Currently, the way health records are stored and shared leaves much to be desired. The system is not efficient, there are many roadblocks that prevent the sharing of data, and patients’ health data is not always stored by a single healthcare provider – instead, a patient’s full health history is fragmented and spread across multiple providers’ systems. Not only does this make it difficult for health data to be amalgamated, but it also leaves data vulnerable to theft. When data is split between multiple providers and their business associates, there is considerable potential for a breach. The Health Insurance Portability and Accountability...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist