25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthplex Settles Alleged Cybersecurity Failures with NYDFS for $2 Million
Aug18

Healthplex Settles Alleged Cybersecurity Failures with NYDFS for $2 Million

Healthplex, one of the largest providers of dental health insurance programs in New York State, has agreed to a settlement with the New York Department of Financial Services (NYDFS) to resolve alleged violations of the NYDFS Cybersecurity Regulation (23 NYCRR Part 500). Healthplex has agreed to pay a $2 million financial penalty to New York State and take steps to improve its cybersecurity posture. The Cybersecurity Regulation took effect in 2017 and requires all financial institutions operating in New York State to implement and maintain a robust cybersecurity program. Some of the key requirements include conducting risk assessments, managing risks, and implementing security policies and procedures, an incident response plan, and multifactor authentication. Healthplex is a licensed provider of dental insurance management services and must therefore comply with the Cybersecurity Regulation. NYDFS launched a compliance investigation after Healthplex reported a cybersecurity event to NYDFS on April 8, 2022. Healthplex discovered the incident on November 24, 2021, when employees...

Read More
Arizona Orthopedics Practice Announces Data Breach
Aug15

Arizona Orthopedics Practice Announces Data Breach

Data breaches have recently been reported by Integrated Orthopedics of Arizona, Glen Falls Hospital in New York, and South Coast Pediatrics in California. Integrated Orthopedics of Arizona Integrated Orthopedics of Arizona (IOA) in Phoenix, Arizona, has recently notified 2,916 patients about a breach of its email tenant. Unauthorized activity was identified on or around April 7, 2025. Assisted by third-party cybersecurity experts, IOA confirmed unauthorized access to the email system, and some emails had been copied. The email system was reviewed to determine the individuals affected and the types of data involved, and that process was completed on June 19, 2025. The affected individuals had either visited IOA for healthcare services or their information was provided by other healthcare providers. The breached information included some or all of the following: name, address, date of birth, medical record number, patient ID/ account number, Medicare number, Medicaid number, health insurance information, diagnosis information, treatment information including date(s) and location,...

Read More
Langdon & Company; Michigan Medicine Announce Data Breaches
Aug15

Langdon & Company; Michigan Medicine Announce Data Breaches

A cyberattack has been announced by the North Carolina accountancy firm Langdon & Company, and Michigan Medicine has experienced a mailing incident that exposed patient information. Langdon & Company, North Carolina Langdon & Company, LLP, a certified public accountancy firm based in Garner, North Carolina, has recently notified 46,061 individuals about a breach of some of their protected health information. Langdon & Company is a business associate of Easterseals North Carolina & Virginia, which provides services to individuals with disabilities. Unusual network activity was identified by the accountancy firm on April 28, 2024. Cybersecurity experts were engaged to investigate the activity and determine the nature and scope of the activity. The forensic investigation revealed unauthorized network access between April 21, 2024, through April 28, 2024, during which time files were exfiltrated from its network. It has taken more than a year to review the affected files and issue notification letters. Langdon & Company said the delay was due to the extensive...

Read More
Nuance Communications Settles MOVEit Lawsuit for $8.5 Million
Aug15

Nuance Communications Settles MOVEit Lawsuit for $8.5 Million

A District Court judge has recently given preliminary approval of an $8.5 million settlement to resolve a consolidated class action complaint against the HIPAA business associate Nuance Communications over a May 2023 data breach. Nuance Communications is a Microsoft-owned computer software company based in Burlington, Massachusetts. The company provides speech recognition solutions and is a vendor to the healthcare industry.  Its AI-powered healthcare software solutions are used by physicians and radiologists to deliver personalized and connected experiences to improve care management. Nuance used Progress Software’s MOVEit Transfer software solution for file transfers. In May 2023, a hacking group known to target file transfer solutions found and exploited a zero-day vulnerability that allowed access to data stored within the MOVEit environment.  Nuance has previously confirmed that 13 of its healthcare provider clients were affected. The breached data included names, addresses, email addresses, birth dates, and information related to health records and health insurance. Nuance...

Read More
Warnings Issued About RCE Vulnerabilities in FortiSIEM & N-able N-central
Aug14

Warnings Issued About RCE Vulnerabilities in FortiSIEM & N-able N-central

Warnings have been issued about a critical vulnerability in Fortinet FortiSIEM with publicly available exploit code and two actively exploited vulnerabilities in N-able N-central. FortiSIEM FortiSIEM is a central security information and event management (SIEM) solution that is used by network defenders for logging, network telemetry, and security incident alerts. FortiSIEM is commonly used by large enterprises, healthcare providers, and government entities. Fortinet has issued a warning about a command injection flaw that can be exploited remotely by an unauthenticated attacker, for which exploit code exists in the wild. As such, it is essential to patch promptly to fix the vulnerability before it can be exploited. The vulnerability, CVE-2025-25256, is a critical flaw affecting FortiSIEM versions 5.4 to 7.3 and has a CVSS base score of 9.8 out of 10. Successful exploitation of the flaw would allow an unauthenticated attacker to remotely execute code or commands via crafted CLI requests. Fortinet did not state whether the vulnerability has already been exploited, only that...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist