25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS Agrees to Settlement Requiring the Restoration of Deleted Health Data and Websites
Sep10

HHS Agrees to Settlement Requiring the Restoration of Deleted Health Data and Websites

The Trump administration has agreed to settle a lawsuit filed by the Washington State Medical Association (WSMA) and eight other plaintiffs that sought to stop and reverse the deletion of important public health and science data from federal websites. Under the terms of the settlement, the Department of Health and Human Services is required to restore more than 100 datasets and webpages that were deleted since January 2025. On January 20, 2025, President Trump signed several executive orders, two of which concerned gender identity and diversity, equity, and inclusion (DEI) – Executive Order 14168: Ending Radical and Wasteful Government DEI Programs and Preferencing & Executive Order 14151: Defending Women from Gender Ideology Extremism and Restoring Biological Truth to the Federal Government. Over the course of several months, the Trump administration directed federal agencies such as the Centers for Disease Control and Prevention (CDC), National Institutes of Health (NIH), and Food and Drug Administration (FDA) to delete public health information that had previously been...

Read More
Data Breaches Announced by US HealthConnect & Altos Inc.
Sep10

Data Breaches Announced by US HealthConnect & Altos Inc.

The medical education provider US HealthConnect and the California billing services vendor Altos Inc have recently announced cyberattacks and data breaches. US HealthConnect US HealthConnect, a provider of continuing medical education and promotional education to healthcare providers, has recently announced a cybersecurity incident that was identified on January 25, 2025. Suspicious activity was identified within its computer network, and third-party cybersecurity specialists were engaged to investigate to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to its network and may have obtained certain information from the affected systems, including names and Social Security numbers. After validating the results and obtaining up-to-date contact information, notification letters started to be issued on September 4, 2025. US HealthConnect has enhanced its existing policies and procedures and implemented additional administrative and technical safeguards to protect against similar incidents in the future, and the...

Read More
Data Breaches Announced by Washington, Florida, and Minnesota Healthcare Providers
Sep10

Data Breaches Announced by Washington, Florida, and Minnesota Healthcare Providers

Data breaches have recently been announced by Northwest Medical Specialties in Washington, Medical Associates of Brevard in Florida, and Twin Cities Pain Clinic in Minnesota. Northwest Medical Specialties Northwest Medical Specialties, PLLC (NWMS), a physician-owned practice with six locations in the South Puget Sound area of Washington state, has started notifying patients about a recent security incident that potentially involved unauthorized access to some of their protected health information. NWMS was contacted by an unidentified party on August 18, 2025, who claimed to have accessed its network and sensitive patient data. After securing the network and engaging third-party digital forensics specialists to investigate a potential breach, it was concluded that patient data was potentially copied without authorization. The review of the affected files was completed on August 22, 2025, and confirmed that the potentially compromised data included full names, dates of birth, Social Security numbers, and medical information. Notification letters are now being sent to the affected...

Read More
Wayne Memorial Hospital Notifies 163,000 Patients About May 2024 Ransomware Attack
Sep09

Wayne Memorial Hospital Notifies 163,000 Patients About May 2024 Ransomware Attack

Wayne Memorial Hospital patients have recently been notified that some of their protected health information was stolen by a ransomware group fifteen months ago. Wayne Memorial Hospital, a rural 84-bed hospital in Jessup, Georgia, has recently mailed individual notifications to the 163,400 patients affected by the incident. The ransomware attack was first identified on June 3, 2024, and the forensic investigation revealed that the ransomware group had access to its network from May 30, 2024, to June 3, 2024. The ransomware group exfiltrated files containing patient data, encrypted files on its network, and demanded a ransom payment to prevent the publication of the data and to obtain the keys to decrypt data. When the attack was identified, the network was disconnected, and systems were taken offline to contain the attack. The ransom was not paid, and files were successfully recovered from backups. The Monti ransomware group claimed responsibility for the attack and added Wayne Memorial Hospital to its data leak site. While the leak site is not currently accessible, the posting...

Read More
Somerset County Children and Youth Services Department Data Breach
Sep09

Somerset County Children and Youth Services Department Data Breach

Officials in Somerset County, Pennsylvania, have confirmed an email hacking incident affecting Children and Youth Services patients. Beech Acres Parenting Center in Cincinnati has notified more than 19,000 clients that their personal information was compromised in a November 2024 hacking incident. Somerset County Children and Youth Services Officials in Somerset County, Pennsylvania, have identified unauthorized access to the email accounts of certain employees of the Department of Children and Youth Services. Suspicious activity was identified in an employee’s email account on June 26, 2025. Third-party cybersecurity experts were engaged to investigate the activity and confirmed that multiple email accounts had been accessed by an unauthorized third party between June 26 and June 30, 2025. Some of the emails and attachments in the compromised accounts contained patients’ protected health information. The data review confirmed that the affected individuals had some or all of the following exposed: name, date of birth, Social Security number, date(s) of service, information related...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist