25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Business Associate Data Breaches Affect Florida Healthcare Providers
Aug07

Business Associate Data Breaches Affect Florida Healthcare Providers

PhyNet Dermatology, a business associate of Premier Dermatology Partners, has identified unauthorized access to an email account containing patient information. Baptist Health South Florida has recently confirmed that it was affected by a breach at Oracle Health (Cerner). PhyNet Dermatology – Premier Dermatology Partners PhyNet Dermatology, a provider of managed administrative services to dermatology practices, has announced a breach that has affected one of its affiliates, Boca Raton, FL-based Total Vein & Skin, LLC, which does business as Premier Dermatology Partners. Suspicious activity was identified in an employee’s email account on November 7, 2024. Immediate action was taken to secure the account, and an investigation was launched to determine the nature and scope of the activity. The investigation determined that the breach was more extensive, and further employee email accounts had also been compromised. The review was completed on June 6, 2025, and confirmed that Premier Dermatiology Partners’ data was present in the compromised accounts. The types of...

Read More
Warning Issued About High-severity Flaw Affecting Microsoft Exchange Hybrid Deployments
Aug07

Warning Issued About High-severity Flaw Affecting Microsoft Exchange Hybrid Deployments

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft have issued warnings about a high-severity flaw affecting Exchange hybrid deployments that could allow an attacker to escalate privileges in Exchange Online cloud environments undetected, potentially impacting the identity integrity of an organization’s Exchange Online service. The vulnerability is tracked as CVE-2025-53786 and affects hybrid-joined configurations of Exchange Server 2016, Exchange Server 2019, and Microsoft Exchange Server Subscription Edition. The vulnerability has a CVSS v3.1 severity score of 8.0 and is due to improper authentication. The vulnerability can be exploited by an attacker with administrative access to an on-premise Microsoft Exchange server. In hybrid Exchange deployments, the on-premise Exchange Server and Exchange Online share the same service principal, which is used for authentication between the on-premise and cloud environments. If an attacker controls the on-premise Exchange server, they can potentially manipulate trusted tokens or API calls. Exchange Online will...

Read More
Family Health Center; NorthCare Settle Data Breach Lawsuits
Aug07

Family Health Center; NorthCare Settle Data Breach Lawsuits

Settlements have received preliminary approval from the courts to resolve class action data breach litigation against Family Health Center in Michigan and NorthCare in Oklahoma. Family Health Center Class Action Data Breach Settlement Family Health Center, a Michigan healthcare provider with three locations in Kalamazoo, has agreed to settle class action data breach litigation stemming from a January 25, 2024, cyberattack that exposed the personal and protected health information of up to 34,926 individuals. The ransomware attack prevented access to certain systems, and the forensic investigation confirmed unauthorized access to names, addresses, health insurance information, Social Security numbers, and medical information. The affected individuals were notified about the data breach on March 24, 2024. Two lawsuits were filed in response to the data breach – Donald Vickery, et al. v. Family Health Center, Inc., and Janet Walker v. Family Health Center, Inc. – in the Ninth Judicial Circuit in and for Kalamazoo County, Michigan. The two lawsuits had overlapping claims and were...

Read More
Small Nebraska Critical Access Hospital Announces Data Breach
Aug06

Small Nebraska Critical Access Hospital Announces Data Breach

Genoa Medical Facilities, which operates a 19-bed critical access hospital in Nebraska, has discovered unauthorized access to its email environment.  Email breaches have also been confirmed by Vail Summit Orthopaedics & Neurosurgery in Colorado and Southern Immediate Care in Alabama. Genoa Community Hospital (Genoa Medical Facilities), Nebraska Genoa Medical Facilities, which includes Genoa Community Hospital, a 19-bed critical access hospital, a 39-bed nursing home, and a medical clinic in Nebraska, has discovered unauthorized access to an employee’s email account. Suspicious email activity associated with a single email account was identified in March 2025. The forensic investigation confirmed that the breach was limited to a single account, and the account was reviewed to determine whether patient data had been exposed. The review was completed on July 8, 2025, when it was confirmed that names, dates of birth, Social Security numbers, other government ID numbers, financial account information, medical treatment/diagnosis information, and health insurance information...

Read More
Jury Finds Meta Violated California Privacy Law by Collecting Flo App Users’ Sensitive Data
Aug06

Jury Finds Meta Violated California Privacy Law by Collecting Flo App Users’ Sensitive Data

Users of the Flo Period & Ovulation Tracker app (Flo App) who sued Facebook (Meta) and others over the alleged collection and interception of their sensitive data without consent have won a landmark victory after a jury found Meta had violated the California Invasion of Privacy Act. The Flo App, developed and owned by Flo Health, is one of the most popular health and wellness apps. According to Flo Health, the app is the #1 mobile product for women’s health. At the time the lawsuit was filed, the app had been downloaded more than 180 million times and had over 38 million active monthly users. When individuals download the Flo App, they are asked to enter personal data and answer a series of personal questions about their sexual health, gynecological health, general health and well-being, and menstruation cycles. As they continue to use the app, they are asked to provide further sensitive information, including when they have their period, if they have had sex, whether they masturbated, any health symptoms, and their mood. Flo Health uses the information provided to predict...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist