NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

ARC Community Services Announces November 2024 Ransomware Attack
Dec24

ARC Community Services Announces November 2024 Ransomware Attack

Madison, WI-based ARC Community Services, a provider of behavioral health, substance use disorder treatment, and support services to women and children, has experienced a ransomware attack involving the theft of sensitive data from its network. ARC Community Services identified unauthorized network activity on November 4, 2024, immediately took its systems offline, and launched an investigation to determine the nature and scope of the unauthorized activity. Assisted by third-party digital forensics experts, ARC Community Services confirmed unauthorized network access, including data exfiltration. In a November 12, 2025, updated substitute breach notice, ARC Community Services said it performed a detailed review of the exposed and exfiltrated data and confirmed that the following types of information were involved: names, contact information, dates of birth, medical record numbers, health information, driver’s license numbers, and financial account information. No evidence has been found to indicate any misuse of the stolen data; however, as a precaution, the affected individuals...

Read More
Oklahoma Spine Hospital Agrees to $1.1M Data Breach Settlement
Dec24

Oklahoma Spine Hospital Agrees to $1.1M Data Breach Settlement

Oklahoma Spine Hospital has agreed to pay $1,100,000 to settle a class action lawsuit stemming from a July 2024 data breach that affected almost 39,000 current and former patients. A potential email account breach was detected on or around July 1, 2024. The forensic investigation confirmed that sensitive patient data was exposed and potentially acquired by an unauthorized individual, including first and last names, dates of birth, financial account numbers and routing numbers, health insurance information, medical information, payment card information, and driver’s license information. The data breach affected 38,945 current and former patients. Two class action lawsuits were filed in response to the data breach, the first of which was filed in the Oklahoma District Court of Oklahoma County on November 15, 2024. The lawsuits were combined into a single complaint – In re: Oklahoma Spine Hospital Data Breach Litigation – as they had overlapping claims. The lawsuit asserted claims of negligence, negligence per se, breach of implied contract, unjust enrichment, and breach of...

Read More
Spartanburg Medical Center Settles Alleged EMTALA Violation for $100,000
Dec24

Spartanburg Medical Center Settles Alleged EMTALA Violation for $100,000

An investigation conducted by the Department of Health and Human Services Office of Inspector General (HHS-OIG) has resulted in a $100,000 settlement with South Carolina’s Spartanburg Medical Center. HHS-OIG determined that there had been a violation of the Emergency Medical Treatment and Active Labor Act (EMTALA) – otherwise known as the patient dumping statute. Under EMTALA, hospitals that receive Medicare funding and provide emergency services must ensure public access to emergency medical services, regardless of a patient’s ability to pay. When a patient presents at an emergency department, and a request is made for an examination or treatment of an emergency medical condition, the hospital must provide a medical screening examination (MSE) and, if an emergency medical condition is confirmed, provide stabilizing treatment. The patient cannot be transferred to another facility unless the hospital lacks the capability to stabilize the patient or a transfer is requested by the patient. HS-OIG investigated a complaint about a potential EMTALA violation involving the inappropriate...

Read More
HIPAA Disclosure Accounting
Dec23

HIPAA Disclosure Accounting

Section §164.528 of the Privacy Rule is better known as the HIPAA disclosure accounting standard and states that an individual has the right to know who disclosures of Protected Health Information have been made to in the past six years. However, there are so many exceptions to this standard, it is difficult to know what is left to account for. The HIPAA disclosure accounting standard is included in the HIPAA Privacy Rule to reassure plan members and patients that any disclosures of Protected Health Information (PHI) are accounted for. However, individuals who exercise the right to request an accounting of disclosures may be surprised to find there are very few disclosures a covered entity has to account for. When is a Disclosure Accounting Required under HIPAA? A disclosure accounting is required under HIPAA whenever it is requested by an individual who is the subject of the PHI that has been disclosed or their personal representative. There are no limits to how frequently an individual can request a HIPAA disclosure accounting, and covered entities have to provided the requested...

Read More
Wilbarger General Hospital & Ochsner LSU Health System Announce Data Breaches
Dec23

Wilbarger General Hospital & Ochsner LSU Health System Announce Data Breaches

Data breaches have been announced by Wilbarger General Hospital, a rural and community hospital in Vernon, Texas, and Ochsner LSU Health System – Regional Urology in northern Louisiana. Wilbarger General Hospital Wilbarger General Hospital, a rural and community hospital in Vernon, Texas, has recently announced a security incident involving unauthorized access to an employee’s email account.  Suspicious activity was identified within the account on October 20, 2025, and an investigation was launched to determine the cause of the activity. Assisted by third-party cybersecurity experts, Wilbarger General Hospital determined that an unauthorized third party had access to the email account for a short period, during which time information in the account may have been accessed or copied. The affected account was reviewed to determine the extent to which patient data had been exposed, and on November 25, 2025, Wilbarger General Hospital confirmed that patients’ protected health information was present in the account. The substitute breach notice states that the review of the account is...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist