25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Glidewell Laboratories Reports Breach of Employee Data
Sep23

Glidewell Laboratories Reports Breach of Employee Data

An unauthorized individual has been discovered to have stolen the personal information of a number of employees of James R. Glidewell, Dental Ceramics, Inc., according to a breach notice submitted to the California Department of Justice. The breach notice does not specifically mention whether the security breach was the work of a malicious insider or outsider, although the breach notice hints that the breach was caused by a former Glidewell employee. Glidewell has told employees “we are continuing to explore all available means of legal recourse and plan to pursue civil and/or injunctive relief, as may be appropriate.” Upon discovery of the data breach, law enforcement agencies were notified and Glidewell enlisted the help of external data security experts to conduct an internal forensic investigation. The investigations into the data theft are continuing. Patient data were not exposed in the incident, although confidential data of employees have been stolen. The information that has been compromised includes employee names, addresses, financial account information related to...

Read More

PHI of 54K Molina Healthcare Members Stolen by Former CVS Employee

A former employee of CVS, an Over-the-Counter benefits vendor contracted by Molina Healthcare, has been discovered to have stolen the Protected Health Information (PHI) of 54,203 current and former members of Molina Medicare Options Plus HMO SNP. The unnamed employee emailed data from a work computer to a personal email account on March 26, 2015, and while no evidence has yet been uncovered to suggest that data have already been used to make fraudulent claims, affected members do face an increased risk of suffering identity, insurance and medical fraud. According to the breach notification letter issued by Molina Healthcare, the information contained in the emailed file included patients’ full names, CVS ID numbers, CVS ExtraCare Health Card numbers, Rx Plan numbers, Rx Plan State, Plan start and end dates, and Member ID numbers. No financial information or Social Security numbers were exposed in the security breach. Members have been offered credit monitoring services for a year without charge, and have been informed to place alerts on their credit files to protect against...

Read More
Senator Calls for Answers over Excellus Data Breach; Lawyers Seek Damages for Victims
Sep21

Senator Calls for Answers over Excellus Data Breach; Lawyers Seek Damages for Victims

The Excellus data breach, first reported earlier this month, potentially exposed the Protected Health Information (PHI) of approximately 10.5 million health insurance subscribers. The Rochester-based insurer is investigating the malware infection that caused the breach, but many victims have been left puzzled over what went wrong, and how their data came to be exposed. On Friday, nine days after the Excellus data breach was announced, New York State Sen. Michael Nozzolio wrote a 4-page letter to the health insurer demanding answers. The data breach is understood to have affected 7 million health insurance subscribers, in addition to 3.5 million customers of its affiliates, Lifetime Healthcare Companies. Excellus BlueCross BlueShield is in the process of notifying all affected individuals about the exposure of their PHI, yet the information provided so far has been insufficient, according to the senator, who claims the company “has not been sufficiently transparent, nor comprehensive.” The letter, posted on the New York Senate website, says “Victims of this cyberattack simply have...

Read More

Systema Software Data Breach: 1.5M+ Medical Records Accessible via AWS

Insurance claim data and other highly sensitive information were inadvertently posted on Amazon Web Services after an error was made by a contractor of Systema Software; a Business Associate of a number of HIPAA-covered health insurance providers. Systema Software was responsible for processing claims for a number of U.S insurance companies. The data exposed in the Systema Software data breach included Social Security numbers, insurance claim information, drug test results, details of medical services provided – and dates of treatment – billing amounts, and unique payment and claimant ID numbers. Personal information was also exposed which ties the records to specific individuals. The data also included details of claims that had been approved and rejected by insurance companies, as well as details of how those insurance carriers were expecting to defend certain claims. The data breach was discovered by tech enthusiast Chris Vickery, who became aware that system dump data was occasionally posted to the cloud via Amazon Web Services. Upon investigation Vickery discovered a huge...

Read More

Flowers Hospital Urges Federal Judge to Dismiss Class Action Data Breach Lawsuit

Lawyers representing Flowers Hospital in Dothan, AL, have urged a federal judge to dismiss a proposed class action data breach lawsuit filed against the hospital, against the recommendation of a magistrate judge. The lawsuit was first filed in May 2014, after a former employee of the hospital – Kamarian Millender, 29, of Headland, AL – was discovered to have stolen the Protected Health Information (PHI) of patients, with the intent of using the data to file false tax returns. Patient names, dates of birth, Social Security numbers and health plan information were stolen from the hospital between June 2013 and February 2014. The hospital discovered the theft on February 26, and Millender’s employment contract was terminated. Millender was subsequently charged with trafficking in stolen identities, and admitted to filing at least 73 fraudulent tax returns in the names of the victims. Flowers hospital issued breach notification letters to the victims shortly after the discovery of the privacy violation, and offered the affected patients a year of credit monitoring services...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist