25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Somerset County Children and Youth Services Department Data Breach
Sep09

Somerset County Children and Youth Services Department Data Breach

Officials in Somerset County, Pennsylvania, have confirmed an email hacking incident affecting Children and Youth Services patients. Beech Acres Parenting Center in Cincinnati has notified more than 19,000 clients that their personal information was compromised in a November 2024 hacking incident. Somerset County Children and Youth Services Officials in Somerset County, Pennsylvania, have identified unauthorized access to the email accounts of certain employees of the Department of Children and Youth Services. Suspicious activity was identified in an employee’s email account on June 26, 2025. Third-party cybersecurity experts were engaged to investigate the activity and confirmed that multiple email accounts had been accessed by an unauthorized third party between June 26 and June 30, 2025. Some of the emails and attachments in the compromised accounts contained patients’ protected health information. The data review confirmed that the affected individuals had some or all of the following exposed: name, date of birth, Social Security number, date(s) of service, information related...

Read More
Cybercriminals Hit Washington Laboratory and New York Pharmacies
Sep09

Cybercriminals Hit Washington Laboratory and New York Pharmacies

Hacking-related data breaches have been reported by Meridian Valley Laboratories in Washington, and College Parkside Pharmacy and College Hometown Pharmacy in New York state. College Parkside Pharmacy & College Hometown Pharmacy Certain patients who received services from College Parkside Pharmacy and/or College Hometown Pharmacy in New York state are being notified about a recent security incident that potentially involved unauthorized access to their protected health information. The pharmacies are operated by Albany College of Pharmacy and Health Sciences, which previously announced the security breach; however, the HHS’ Office for Civil Rights has only recently been notified. The OCR breach portal indicates the incident affected 9,742 individuals who received services from College Hometown Pharmacy and 5,736 individuals who received services from College Parkside Pharmacy. According to the breach notice, unusual activity was identified within its computer network on or around September 14, 2024. External cybersecurity specialists were engaged to assist with the...

Read More
Florida Pediatric ENT Specialists Confirm Data Breach Affecting 44,000 Individuals
Sep09

Florida Pediatric ENT Specialists Confirm Data Breach Affecting 44,000 Individuals

Pediatric Otolaryngology Head & Neck Surgery Associates has reported a data breach affecting almost 44,000 patients. Anchorage Neighborhood Health Clinic in Alaska is investigating a potential security breach that may have affected up to 10,000 patients, and Valley Mountain Regional Center has exposed data over the Internet. Pediatric Otolaryngology Head & Neck Surgery Associates, Florida Pediatric Otolaryngology Head & Neck Surgery Associates (POHNS) in Florida recently reported a data breach to the HHS Office for Civil Rights affecting 43,446 individuals. POHNS first announced the data breach on April 25, 2025. Unusual activity was identified within its computer network on February 24, 2025. The forensic investigation confirmed unauthorized access between February 19 and February 24, 2025, including access to patients’ protected health information. The file review confirmed that a range of patient data had been exposed, although the information involved varied from individual to individual. Data potentially compromised in the incident included names in combination...

Read More
New York Blood Center Enterprises Notifies Individuals Affected by January Ransomware Attack
Sep09

New York Blood Center Enterprises Notifies Individuals Affected by January Ransomware Attack

New York Blood Center Enterprises, the operator of 19 blood donor centers in New York and New Jersey, has notified the Maine Attorney General about its January 2025 ransomware attack and has provided further information on the findings of its investigation. As previously announced and reported below, the attack was detected on January 26, 2025. The forensic investigation confirmed that an unauthorized third party had access to its computer network between January 20 and January 26, 2025, and obtained a copy of a subset of files stored on the network. The files were reviewed, and New York Blood Center Enterprises obtained a preliminary list of individuals whose names and sensitive data were involved on June 30, 2025. The draft list was reviewed, and “an extensive analysis” was conducted to develop a final list of the individuals to notify. The final list was obtained on August 12, 2025. The types of information involved vary from individual to individual and may include names in combination with Social Security numbers, driver’s license numbers, other government...

Read More
HIPAA Compliance for Pain Management Clinics
Sep08

HIPAA Compliance for Pain Management Clinics

HIPAA compliance for pain management clinics requires implementing controls under the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule across scheduling, evaluation, treatment planning, procedures, prescribing support, referrals, billing, and records release. HIPAA Compliance in Pain Management Practices Pain management clinics create, receive, maintain, and transmit protected health information through registration, referrals, clinical histories, diagnostic documentation, treatment plans, procedure notes, medication lists, prior authorization records, and revenue cycle activities. Pain management practices frequently exchange protected health information with primary care providers, specialists, imaging providers, laboratories, pharmacies, and payers. Each exchange must be governed as a regulated use or disclosure and supported by documented controls. Pain management services also operate within multidisciplinary care models that involve physical therapy, behavioral health support, and care coordination functions. HIPAA compliance must cover how...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist