25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Athens Orthopedic Clinic Breach: No Money to Pay for Identity Theft Protection Services

On June 14, a hacker operating under the name The Dark Overlord hacked an Athens Orthopedic Clinic database containing the records of 201,000 patients. The attack was performed via a third party vendor that was used by the clinic. Patient data were stolen and the hacker attempted to extort money from the clinic. A threat was issued saying the data would be sold if a payment was not made. When the clinic refused to pay, the data were listed for sale on darknet marketplace TheRealDeal. The data included patient names, dates of birth, addresses, telephone numbers, account numbers, Social Security numbers, and potentially diagnoses and medical histories. While healthcare cyberattacks usually result in patients being offered a minimum of 12 months credit monitoring and identity theft protection services to mitigate risk, Athens Orthopedic Clinic has confirmed that its patients will not be offered these services. A spokesperson for Athens Orthopedic Clinic issued a statement to the Athens Banner-Herald explaining that the clinic cannot afford to pay for extended credit monitoring...

Read More
655,000 Bon Secours Patients Notified of Potential PHI Breach
Aug16

655,000 Bon Secours Patients Notified of Potential PHI Breach

Bon Secours Health System is in the process of notifying 655,000 patients that some of their protected health information was exposed as a result of an error made by one of its business associates. The error was made by Arizona-based reimbursement optimization firm R-C Healthcare Management. Network settings were reconfigured between April 18 and April 21; however, an error was made that allowed files containing PHI to be accessed via the Internet. The configuration error was discovered by Bon Secours on June 21, almost two months later. Bon Secours notified R-C Healthcare Management of the error and prompt action was taken to ensure that files were secured. It is unclear whether PHI were accessed, although Bon Secours has said the vulnerability has now been addressed and PHI has been secured. No information has been received to suggest that any patient data were misused in any way. The files contained the names of patients, banking information, insurer names, insurance ID numbers, Social Security numbers, and some clinical data. No medical records were accessible at any point,...

Read More

CMS Cracks Down on Social Media Abuse of Nursing Home Residents

A significant number of cases of abuse of nursing home and assisted living center residents have come to light in recent months. The cases involved the taking of degrading and demeaning photographs and videos of residents by employees of nursing facilities, and sharing the images and videos on social media websites. Photographs of residents in various states of undress, covered in feces, or made to pose in degrading positions have been published on social media websites such as Snapchat, Instagram, and Facebook. The cases were recently highlighted in a ProPublica report, which uncovered 47 reports of such abuse since 2012. That report, along with other media coverage of abuse in nursing facilities, has spurred the Centers for Medicare and Medicaid Services (CMS) to take action. The CMS recently sent a memo to state health departments reminding them of facility and state agency responsibilities and the rights of residents to be free from all types of abuse, including mental abuse. The taking of demeaning videos and/or photographs and publishing the imagery on social media websites...

Read More

Walgreens Improper PHI Dumping Case Closed by OCR After 9 Years

Ten years ago, WTHR 13 conducted an investigation into the improper disposal of sensitive information by pharmacies. The investigation was conducted following a robbery that took place at the home of an Indiana resident. A drug addict targeted the individual knowing that she had pain medication. That information was obtained from a pharmacy dumpster. The investigation involved reporters checking the dumpsters behind a number of pharmacies in Indiana. The reporters discovered bags of trash, many of which contained sensitive information such as prescription details, names, addresses, and phone numbers. Reporters also discovered that in some cases, credit card details were also printed on documents discarded with regular trash. The investigation was first conducted on Walgreens, although it was later expanded to a number of other pharmacy chains including CVS and Rite Aid. The investigation was expanded to 12 states. Initially reporters were told by Walgreen’s representatives that the improper dumping of sensitive information was not company policy and occurred in isolated incidents....

Read More

13.6% Growth Expected in Hospital Cybersecurity Market to Combat New Threats

Over the next five to six years, growth in the healthcare cybersecurity solution market is expected to increase by 13.6%, according to a new Frost & Sullivan report. Healthcare organizations have to protect a much broader attack surface now that the vast majority of organizations have transitioned from paper to digital PHI formats. Keeping data protected from attacks by malicious actors is now a major concern for healthcare organizations. The threat landscape has changed considerably and traditional cybersecurity solutions are failing to prevent increasingly sophisticated attacks. The increase in cybersecurity threats will fuel considerable growth in the hospital cybersecurity market. As we have seen in the past few weeks, the Department of Health and Human Services’ Office for Civil Rights has stepped up enforcement of HIPAA regulations and has issued a number of multi-million dollar files to companies that have failed to protect adequately protect the ePHI of patients. The FTC and state attorneys general have also taken action against healthcare organizations that have failed...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist