25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Compliance Challenges for Small Medical Practices
Aug09

HIPAA Compliance Challenges for Small Medical Practices

All healthcare providers are required to comply with the HIPAA Rules, but there are unique challenges for small medical practices. Large healthcare organizations have greater resources to devote to compliance, and can attract and pay for dedicated compliance professionals, in-house IT and cybersecurity staff, cutting-edge cybersecurity solutions, and staff training programs. Small medical practices typically have limited resources and are forced to make difficult decisions about where to allocate funds due to budget constraints. Investments in the business that boost revenue and profits often take priority over HIPAA compliance and cybersecurity improvements. Small practices often cannot afford to have a dedicated HIPAA Privacy and Security Officer, and compliance duties fall on staff members with many other responsibilities. There may also not be an in-house IT department to oversee security and ensure the information security program is fully compliant with the HIPAA Security Rule. Despite financial constraints, HIPAA compliance and cybersecurity are not optional. The HHS’ Office...

Read More
Senators Demand Answers from UnitedHealth After Second Massive Data Breach in a Year
Aug08

Senators Demand Answers from UnitedHealth After Second Massive Data Breach in a Year

Two U.S. senators have written to UnitedHealth Group (UHG) CEO Stephen J. Hemsley demanding answers about cybersecurity and the response to the massive data breach at its subsidiary, Episource, which exposed the personal and protected health information of 5.4 million individuals earlier this year. Episource, which was acquired by UHG-owned Optum in 2023, provides medical coding and risk adjustment services to physicians, health plans, and other healthcare companies. In June 2025, the company announced a hacking incident that involved unauthorized access to its network between January 27, 2025, and February 6, 2025. The hackers stole sensitive information such as names, dates of birth, Social Security numbers, health information, health insurance information, and Medicare/Medicaid numbers. The hacking incident at Episource occurred within a year of a ransomware attack on another UHG subsidiary, Change Healthcare, which resulted in the largest healthcare data breach in U.S. history. Change Healthcare has recently confirmed that 192.7 million individuals were affected and had their...

Read More
HIPAA Training for Medical Laboratory Technicians
Aug08

HIPAA Training for Medical Laboratory Technicians

HIPAA training for medical laboratory technicians supports HIPAA compliance by preparing laboratory personnel to protect protected health information (PHI) while collecting, labeling, testing, reporting, and transmitting laboratory data that can identify a patient and reveal health conditions. Why Laboratory Workflows Create Unique HIPAA Risks Laboratory environments move fast and rely on precision, which means privacy and security issues often arise from routine operational steps rather than intentional behavior. PHI can appear on specimen labels, requisitions, analyzer printouts, pending worklists, quality review reminders, courier logs, instrument interface messages, and laboratory information system screens. Results reporting can involve internal messaging, faxes, portals, and calls to clinical units, and each handoff creates an opportunity for misdirection, over-disclosure, or unauthorized viewing if safeguards are not followed. Laboratory staff also work with information that can be especially sensitive, such as infectious disease testing, toxicology, pregnancy testing,...

Read More
Alera Group Notifies 155K Individuals About July 2024 Hacking Incident
Aug08

Alera Group Notifies 155K Individuals About July 2024 Hacking Incident

Alera Group has notified more than 155,000 individuals about a July 2024 hacking incident. Data breaches have also been announced by The Good Samaritan Health Center of Cobb and Western Montana Clinic. Alera Group Notifies Individuals About July 2024 Hacking Incident Alera Group, Inc., a provider of risk management, insurance, and financial services, has notified 155,567 individuals about the potential theft of some of their protected health information. The incident was first announced on May 21, 2025, and has recently been reported to the HHS’ Office for Civil Rights. Suspicious network activity was detected in August 2024, and the forensic investigation confirmed unauthorized access to its network between July 19, 2024, and August 4, 2024. During that time, sensitive data may have been copied. A file review was initiated to determine the types of data involved and the individuals affected, and that process was completed on April 28, 2025. Alera Group has confirmed that the data related to employees and certain clients, business partners, and providers. That information included...

Read More
Hacking Incidents Announced by Two Texas Health Clinics
Aug08

Hacking Incidents Announced by Two Texas Health Clinics

A drug and alcohol addiction center and an OB/GYN Medical Center in Texas have notified patients about unauthorized access to some of their protected health information. Nova Recovery Center Reports Unauthorized Network Access Nova Recovery LLC (Nova Recovery Center), a drug and alcohol addiction center in Wimberley, Texas, has identified unauthorized access to certain systems hosted on the Nova Recovery network. The intrusion was identified by its IT and Security teams on May 25, 2025. The threat was neutralized, and the breach was investigated to determine if any patient data had been exposed. On June 17, 2025, Nova Recovery confirmed that business records on its network had been accessed, some of which contained patients’ personal information. Data compromised in the incident includes first, middle, and last names, addresses, dates of birth, Social Security numbers, and financial payment information. Individual notification letters have been mailed to the 7,713 affected individuals, and complimentary credit monitoring services have been offered. The third-party consulting firm...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist