25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

McKenzie Memorial Hospital Announces Data Breach Affecting Almost 59,000 Patients
Jul25

McKenzie Memorial Hospital Announces Data Breach Affecting Almost 59,000 Patients

McKenzie Memorial Hospital in Michigan has reported a hacking incident affecting almost 59,000 patients. Arbor Associates in Massachusetts has reported a 17K-record data breach, and data breaches have been confirmed by Blue Shield of California and Human Development Services of Westchester. McKenzie Memorial Hospital, Michigan McKenzie Memorial Hospital in Sandusky, Michigan, has recently disclosed a cybersecurity incident that was detected on or around April 15, 2025, when suspicious activity was identified within its network. McKenzie Memorial did not state whether ransomware was used, only that the forensic investigation confirmed that its network was accessed by an unauthorized third party between April 14, 2025, and April 15, 2025. During that time, files containing patients’ protected health information may have been accessed. The investigation and file review were completed on June 19, 2025, and confirmed that the potentially compromised information included names, Social Security numbers, and financial account information. The data breach was recently reported to the Maine...

Read More
BJC HealthCare Settles Website Tracking Lawsuit for up to $9.25 Million
Jul25

BJC HealthCare Settles Website Tracking Lawsuit for up to $9.25 Million

BJC Health System, doing business as BJC HealthCare, is one of the latest healthcare organizations to settle litigation stemming from the use of website tracking tools. BJC HealthCare has agreed to pay up to $9.25 million to resolve the litigation and provide cash payments to the class members. BJC HealthCare is a non-profit healthcare organization based in St. Louis, Missouri, which runs the Washington University-affiliated hospitals Barnes–Jewish Hospital and St. Louis Children’s Hospital. According to the lawsuit – John Doe et al v. BJC Health System – BJC HealthCare maintained various web properties, including the websites www.bjc.org and www.barnesjewish.org, through which patients could communicate with BJC HealthCare. The plaintiffs alleged that tracking tools were added to the websites that collected web user data, including personally identifiable information, and that sensitive information was transmitted to companies such as Facebook (Meta), Google, SiteScout, Invoca, and TradeDesk, without the knowledge or authorization of web users. BJC HealthCare...

Read More
MedStar Health Agrees to $1.35 Million Settlement to Resolve Class Action Data Breach Litigation
Jul24

MedStar Health Agrees to $1.35 Million Settlement to Resolve Class Action Data Breach Litigation

MedStar Health has agreed to settle class action litigation stemming from a 2023 data breach that affected more than 183,000 individuals. MedStar Health will create a $1.35 million settlement fund to cover attorneys’ fees, legal costs and expenses, and claims from class members for reimbursement of out-of-pocket expenses fairly traceable to the data breach. MedStar Health, the largest healthcare provider in Maryland and Washington, D.C., provides medical services through 120 entities, including 10 hospitals. Between January 25, 2023, and October 18, 2023, an unauthorized third party gained access to the email accounts of three employees and accessed or obtained the protected health information of 183,079 patients. The individuals were notified about the data breach on May 4, 2024. Shortly after mailing notification letters, a class action lawsuit was filed by Gwendolyn Riddick individually and on behalf of similarly situated individuals. A further five class action lawsuits were filed by other MedStar Health patients. Since all six lawsuits were materially and substantively...

Read More
The Harris Poll Survey Reveals Growing Concern About Workplace Safety in Healthcare
Jul24

The Harris Poll Survey Reveals Growing Concern About Workplace Safety in Healthcare

A recent survey by The Harris Poll has revealed that three out of five (59%) healthcare workers are concerned about safety in the workplace, and almost two out of five healthcare workers have considered leaving their employment due to safety concerns as incidents of violence in the workplace increase. The survey was conducted between April 21 and May 7, 2025, on 1,027 U.S. healthcare workers who frequently interact with patients or their families.  The biggest concerns among healthcare workers were verbal harassment from patients (81%), aggressive behavior/threats from patients (77%), verbal harassment from non-patients (62%), and aggressive behavior/threats from non-patients (59%). More than one-fifth (21%) of healthcare workers said they worry about verbal harassment most of the time or every time they go to work. These concerns are far from unfounded. Data from the U.S Bureau of Labor Statistics shows healthcare workers are five times more likely to experience violence in the workplace than workers in other industries, and multiple surveys suggest workplace violence is on the...

Read More
HHS-OIG Imposes Penalties on Skilled Nursing Facilities for Employing Excluded Individuals
Jul24

HHS-OIG Imposes Penalties on Skilled Nursing Facilities for Employing Excluded Individuals

The U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) has recently announced enforcement actions against entities alleged to have employed excluded individuals who provided items or services that were billed to federal healthcare programs. On May 29, 2025, HHS-OIG announced a $1,565,374.11 settlement agreement with 19 skilled nursing facilities to resolve allegations that they knew or should have known that they employed individuals who were excluded from federal healthcare programs. Sundance Creek Post Acute, California Escondido Post Acute, California Jurupa Hills Post Acute, California Crystal Cove Care Center, California Redwood Cove Healthcare Center, California Huntington Valley Healthcare Center, California Houston Transitional Care, Texas Napa Post Acute, California Norwood Towers Post Acute, Ohio Sunnyvale Post Acute Center, California Stoney Point Healthcare, California Trellis Centennial, Nevada San Diego Post Acute, California Mirage Post Acute, California Crystal Ridge Care Center, California Aviara Healthcare, California Concord Post...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist