25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Sandhills Medical Foundation Ransomware Attack Affects 169,000 Patients
Apr30

Sandhills Medical Foundation Ransomware Attack Affects 169,000 Patients

Sandhills Medical Foundation in South Carolina and Laurel Eye Clinic in Pennsylvania have experienced security incidents that exposed patient data. The ransomware attack on Sandhills Medical Foundation affected more than 169,000 individuals. Sandhills Medical Foundation, South Carolina Sandhills Medical Foundation, Inc., a federally qualified community health center (FQHC) that provides primary care, behavioral health, and immunization services to residents of Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina, has notified 169,017 individuals that some of their personal and health information was stolen by a ransomware group that compromised its network in May 2025. The ransomware attack was detected on May 8, 2025, when files were encrypted. Digital forensics experts were engaged to investigate the incident, who determined that the ransomware group had access to its network from May 2, 2025, to May 8, 2025. During that time, files were exfiltrated from its network. The exposed and stolen files have been reviewed and were found to contain names, dates of...

Read More
Vendor Data Breaches Announced by Six HIPAA-Regulated Entities
Apr30

Vendor Data Breaches Announced by Six HIPAA-Regulated Entities

There have been several announcements about data breaches at business associates of HIPAA-regulated entities recently, including Providence St. Joseph Orange and Skin & Beauty Center in California, Management-ILA Managed Health Care Trust Fund in New York, and Ideal Home Care, Duncan Regional Home Care, and Chisholm Trail Hospice in Oklahoma. Providence St. Joseph Orange, California Providence St. Joseph Orange, a catholic general hospital in Orange, California, has been affected by a data security incident at its vendor, Pinnacle Holdings, LTD, a health care consulting company. Pinnacle experienced a network disruption in November 2024, and the forensic investigation confirmed unauthorized access to its network between November 11, 2024, and November 25, 2024, during which time files containing protected health information may have been exfiltrated from Pinnacle’s network. Data potentially compromised in the incident included patients’ first and last name, address, email address, date of birth, encounter ID number, health insurance claim number, health insurance policy number,...

Read More
Southern Illinois Healthcare Enterprises Pixel Settlement Approved
Apr30

Southern Illinois Healthcare Enterprises Pixel Settlement Approved

A settlement has been agreed to resolve litigation against defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over their use of website tracking technologies without website users’ knowledge or consent. Southern Illinois Healthcare Enterprises Pixel Settlement A class action lawsuit over the use of website tracking technologies has been settled. The lawsuit was filed by John Doe, individually and on behalf of similarly situated individuals, against the defendants Southern Illinois Healthcare Enterprises, Southern Illinois Hospital Services, and Southern Illinois Medical Services over an alleged impermissible disclosure of the plaintiff’s and class members’ private information to third parties. The lawsuit – Doe v. Southern Illinois Healthcare Enterprises, Inc. – was filed in Williamson County Circuit Court, Illinois, and alleged that personally identifiable information was disclosed to Meta (Facebook) via third-party tools on the defendants’ websites without the knowledge or permission of...

Read More
Settlements Agreed to Resolve Two Class Action Healthcare Data Breach Lawsuits
Apr29

Settlements Agreed to Resolve Two Class Action Healthcare Data Breach Lawsuits

Settlements have received preliminary approval from the courts to resolve class action data breach lawsuits against Dove Healthcare Management Services and Blackstone Valley Community Health Care over the exposure of plaintiffs’ private information in 2023 and 2024 hacking incidents. Dove Healthcare Management Services Data Breach Settlement Dove Healthcare Management Services, a provider of nursing and rehabilitation care, assisted living, and palliative care services, has agreed to a settlement to resolve litigation over a July 2024 cyberattack that exposed the private information of patients and employees. Cybercriminals breached its information systems on or around July 6, 2024, exposing names, dates of birth, Social Security numbers, driver’s license numbers, full face photographs, health information, and health insurance information. The affected individuals began receiving notifications about the incident on March 18, 2025. The first class action lawsuit was filed on March 26, 2025, followed by several similar lawsuits. The complaints were consolidated into a single action...

Read More
AI Analysis Identifies 38 Flaws in OpenEMR Platform
Apr29

AI Analysis Identifies 38 Flaws in OpenEMR Platform

An automated, AI-driven analysis of the most widely used electronic medical records platform uncovered 38 previously unknown vulnerabilities, including two critical flaws with maximum CVSS severity scores of 10.0. The vulnerabilities were identified as part of a collaboration between AISLE, an autonomous, AI-native application security platform, and OpenEMR, an open source and U.S. government-certified platform, the purpose of which was to identify and remediate critical vulnerabilities in the platform before they could be exploited by malicious actors. OpenEMR is used by more than 100,000 healthcare providers worldwide, and the platform serves more than 200 million patients globally. OpenEMR is free open source software with no licensing fees and relatively low operating costs, making it a popular choice for under-resourced healthcare providers. The platform is widely used in the United States. The analysis by AISLE resulted in 39 GitHub Security Advisory (GHSA) vulnerabilities in Q1, 2026, including critical, high, and moderate severity vulnerabilities, with 38 of the 39...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist