25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Illinois Department of Human Services Exposes Sensitive Data of 700,000 Individuals Online
Jan05

Illinois Department of Human Services Exposes Sensitive Data of 700,000 Individuals Online

The Illinois Department of Human Services (IDHS) has announced a major data breach affecting hundreds of thousands of state residents, whose sensitive data has been exposed online. IDHS created planning maps to assist with resource allocation and decision-making, which were added to a mapping website. On or around September 22, 2025, IDHS discovered that the website, which was intended for internal department use only, was accessible via the public Internet. Upon discovery, the website was immediately secured, and an investigation was launched to determine the cause of the error and the extent of any data exposure. The investigation revealed that sensitive data had been exposed online for up to four years between 2021 and 2025. The planning maps had been created by the IDHS Division of Family and Community Services’ Bureau of Planning and Evaluation, which inadvertently misconfigured the privacy settings. Following a comprehensive review, IDHS determined that the protected health information of approximately 672,616 Medicaid and Medicare Savings Program recipients had been exposed...

Read More

HIPAA Explained

Our HIPAA explained article provides information about the Health Insurance Portability and Accountability Act (HIPAA) and the Administrative Simplification Regulations – which include the HIPAA Privacy Rule, HIPAA Security Rule, and Breach Notification Rule.    What is HIPAA? The Health Insurance Portability and Accountability Act (HIPAA) is an Act passed in 1996 that primarily had the objectives of enabling workers to carry forward healthcare insurance between jobs, prohibiting discrimination against beneficiaries with pre-existing health conditions, and guaranteeing coverage renewability multi-employer health insurance plans. At the time, the cost of health insurance was rising rapidly. To prevent health insurance companies further increasing premiums and deductibles due to the costs associated with the portability and accountability provisions, cost-cutting measures were added as the Act passed through Congress to reduce health care fraud and to make the administration of health claims processing more efficient. Further measures relating to medical liability reform,...

Read More
What is HIPAA Authorization?
Jan05

What is HIPAA Authorization?

A HIPAA authorization is a form that must be completed by a patient or a health plan member when a covered entity wishes to use or disclose PHI for a purpose not permitted by the HIPAA Privacy Rule. The failure to obtain a valid HIPAA authorization is considered a serious violation of HIPAA compliance. What is HIPAA Authorization? The HIPAA Privacy Rule (effective since April 14, 2003) introduced standards covering allowable uses and disclosures of health information, including to whom information can be disclosed and under what circumstances protected health information can be shared. The HIPAA Privacy Rule permits the sharing of health information by healthcare providers, health plans, healthcare clearinghouses, business associates of HIPAA-covered entities, and other entities covered by HIPAA Rules under certain circumstances. In general terms, permitted uses and disclosures are for treatment, payment, or health care operations, and reporting issues such as domestic abuse to public health agencies. HIPAA authorization is written consent obtained from a patient or health plan...

Read More
What are the HIPAA Photography Rules?
Jan05

What are the HIPAA Photography Rules?

The HIPAA photography rules vary according to the nature of the photograph, its purpose, and whether it is part of a designated record set. The HIPAA rules for photos also may or may not apply depending on who is taking the photos, while the environment in which photos are taken can also influence hospital policies. Photos are only mentioned twice in HIPAA – once in the Safe Harbor method of de-identifying PHI, and once in the list of individually identifiable health information that has to be removed from a designated record set to make it a limited data set. Because these are the only mentions of photographs in HIPAA, many covered entities assume that every photograph should be classified as Protected Health Information (PHI) and subject to HIPAA Privacy and Security Rule standards. But this is not the case. Individually identifiable information such as photos and videos only become individually identifiable health information when they are created or received by a covered entity and relate to “the past, present, or future physical or mental health or condition of an individual;...

Read More
Covenant Health Ransomware Attack Victim Count Increases by 5,980%
Jan05

Covenant Health Ransomware Attack Victim Count Increases by 5,980%

Covenant Health has provided an update on the number of individuals affected by its May 2025 ransomware attack, confirming that at least 478,188 individuals were affected, a 5,980% increase from the previously reported total of 7,864 individuals. In a notification letter sent to the Maine Attorney General, issued on Covenant Health’s behalf by its legal counsel, Baker & Hostetler LLP, additional notification letters started to be mailed on December 31, 2025, including notifications to 284,529 Maine residents. Baker & Hostetler explained that after the initial data breach report was submitted on July 11, 2025, the investigation continued, and the bulk of its data analysis has now been completed, suggesting the total may increase further by the time the investigation is concluded. The ransomware attack was detected on May 26, 2025, when suspicious activity was observed within its IT environment, and the investigation confirmed that an unauthorized third party had access to its network from May 18, 2025, and was able to access files containing patient information. The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist