25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

$30 Million Settlement Agreed to Resolve Integris Health Class Action Data Breach Lawsuit
Oct14

$30 Million Settlement Agreed to Resolve Integris Health Class Action Data Breach Lawsuit

Integris Health has agreed to pay $30 million to settle class action data breach litigation. The settlement resolves claims stemming from a major data breach in 2023 that saw hackers gain access to systems containing the electronic protected health information of more than 2.38 million individuals. Integris Health, one of the largest health systems in Oklahoma, first announced the cyberattack and data breach in December 2023. Hackers gained access to its computer network on November 28, 2023, and exfiltrated files containing patient data. The threat actor did not encrypt files but demanded payment to prevent the release of the stolen data. On December 24, 2025, Integris Health started to be contacted by patients who had been contacted directly by the threat actor, who was demanding $50 per patient to delete their stolen data. The HHS’ Office for Civil Rights was notified about the data breach in February 2024 and was told that the protected health information of 2,385,646 individuals was compromised in the attack. The stolen data included names, contact information, birth dates,...

Read More
ALN Medical Management to Pay $4 Million to Settle Class Action Data Breach Lawsuit
Oct13

ALN Medical Management to Pay $4 Million to Settle Class Action Data Breach Lawsuit

ALN Medical Management, a Nebraska-based revenue cycle management company, has agreed to pay $4 million to settle class action litigation over a March 2024 cybersecurity incident. As reported below, this was a hacking incident that occurred in March 2024, which was initially reported to the HHS’ Office for Civil Rights (OCR) using a placeholder figure of at least 501 affected individuals. The breach total was then revised to more than 1.8 million individuals, and subsequently revised downwards to 1,323,720 individuals. The incident is now archived on the OCR breach portal, indicating that OCR has closed the investigation. ALN Medical Management and its healthcare clients, Allied Physicians Group, PLLC, Bethany Medical Clinic of New York, PLLC, Hoag Clinic, and National Spine and Pain Centers, LLC, were named in class action lawsuits over the data breach, which were consolidated in a single suit, In Re: ALN Medical Management Data Incident Litigation, in the U.S. District Court for the District of Nebraska. The lawsuit alleged that ALN Medical Management used the information...

Read More
Senate Confirms David Keeling as New OSHA Leader
Oct13

Senate Confirms David Keeling as New OSHA Leader

Earlier this month, the Senate confirmed David Keeling as the new Assistant Secretary of Labor for Occupational Safety and Health, after his nomination was approved with a 51-47 vote, along with more than 100 other nominees. Keeling, President Trump’s nominee for the new leader of the Occupational Safety and Health Administration (OSHA), was confirmed as OSHA’s new leader on October 3, 2025, and takes over from Amanda Wood Laihow, who has served as acting Assistant Secretary of Labor for Occupational Safety and Health since February 2025. OSHA has been without a permanent head since Douglas L. Parker left the role, having served from 2021 to 2025 under the Biden administration. Keeling has previously served as safety executive at UPS, a position he held for more than 30 years, before moving to Amazon, where he served as Director of Global Road and Transportation Safety for two years. Keeling’s nomination was approved by the Health, Education, Labor, and Pensions (HELP) Committee on June 26, in a 12-11 vote along party lines. Keeling shared three main goals with the HELP...

Read More
SimonMed Imaging: 1.27M Individuals Affected by January 2025 Cyberattack
Oct13

SimonMed Imaging: 1.27M Individuals Affected by January 2025 Cyberattack

On October 10, 2025, SimonMed Imaging started mailing notification letters to the individuals affected by its January 2025 cyberattack. SimonMed Imaging is one of the largest medical imaging providers in the country, operating more than 170 medical imaging facilities in 10 U.S. states. In a breach notice to the Maine Attorney General, the Scottsdale, AZ-based company confirmed that the protected health information of 1,275,669 individuals was compromised in the incident, including 22 Maine residents. The HHS’ Office for Civil Rights breach portal still lists the incident with a 500-individual placeholder figure. The notification letters provide little extra information beyond that provided in its previous announcement, other than the fact that data theft has now been confirmed. While patient data was stolen in the attack, SimonMed Imaging said it is unaware of any misuse of the stolen data; however, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services. As previously reported, the Medusa ransomware...

Read More
HIPAA Remediation Training
Oct12

HIPAA Remediation Training

HIPAA Remediation Training is comprehensive HIPAA training given after a HIPAA violation or breach has occurred, with particular emphasis on how the HIPAA rules were violated, why the violation happened, and what staff must do differently to prevent it from happening again. It also reinforces the importance of HIPAA compliance so that employees understand that the goal is not just to fix one incident but to improve everyday behavior with protected health information. When HIPAA Remediation Training is Used HIPAA Remediation Training is typically provided to individual staff members after they have been involved in a HIPAA violation. In these cases, the training is tailored to the specific incident, helping the employee see exactly where their actions diverged from policy and what the correct approach should have been. This individual focus makes the training highly relevant and reduces the chances of repeating the same mistake. HIPAA Training for Employees Our training provides employees with a clear and practical understanding of what to do and why in real-world HIPAA scenarios....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist