25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breaches Reported by Southern Illinois Dermatology; Heart South Cardiovascular Group
Apr08

Data Breaches Reported by Southern Illinois Dermatology; Heart South Cardiovascular Group

Patient data has potentially been compromised in data incidents at Southern Illinois Dermatology and Heart South Cardiovascular Group in Alabama. Southern Illinois Dermatology, Illinois Southern Illinois Dermatology has notified an unspecified number of individuals about a data security incident it identified on November 28, 2025. An investigation was immediately launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts. The investigation confirmed unauthorized access to parts of its network where patient data was stored, and potentially, files were copied from its network. The affected data was reviewed and found to contain personal information and protected health information, including full names, addresses, dates of birth, Social Security numbers, telephone numbers, email addresses, person numbers, and medical record numbers. The types of data involved vary from individual to individual. Notification letters started to be mailed to the affected individuals on April 2, 2026. Southern Illinois Dermatology has taken...

Read More
Woodfords Family Services Data Breach Affected Almost 42,000 Individuals
Apr08

Woodfords Family Services Data Breach Affected Almost 42,000 Individuals

Legal counsel for Woodfords Family Services has provided an updated breach notice to the Maine Attorney General, confirming that more individuals were affected by its ransomware attack than previously reported. The initial breach report submitted to the Maine Attorney General on March 27, 2026, stated that 8,073 individuals had been affected; however, a substitute notice has been issued for 33,911 individuals, with 41,984 individuals in total confirmed as affected by the data breach. The data breach has been reported to the HHS’ Office for Civil Rights as involving unauthorized access to the electronic protected health information of 38,061 individuals. March 30, 2026: Woodfords Family Services Notifies Patients Affected by April 2024 Ransomware Attack Westbrook, Maine-based Woodfords Family Services, a provider of services to individuals with special needs and their families, has notified the Maine Attorney General about a breach of the personal and protected health information of 8,073 individuals in a ransomware attack, including 7,701 Maine residents. Suspicious network...

Read More
ProxyCare; Oscar Health; AccentCare Announce Data Breaches
Apr07

ProxyCare; Oscar Health; AccentCare Announce Data Breaches

Data incidents have recently been announced by ProxyCare in Florida, Oscar Health in New York, and AccentCare in Texas. ProxyCare, Florida ProxyCare LLC, a Sunrise, Florida-based provider of personalized pharmacy services, has started mailing notification letters to individuals impacted by an August 2025 cybersecurity incident. The company learned on August 22, 2025, that certain computer systems within its network environment had been affected by a cybersecurity incident. Third-party cybersecurity professionals were engaged to determine the nature and scope of the incident, and whether, and to what extent, patient information had been compromised. The investigation confirmed that patient data had been exposed, and following a comprehensive manual document review, ProxyCare determined on January 29, 2026, that files accessed or acquired by an unauthorized third party in the incident included names, dates of birth, Social Security numbers, and driver’s license numbers. Notification letters were mailed to the affected individuals on March 23, 2026, and individuals whose Social...

Read More
Maine House Unanimously Passes Bill to Strengthen Cybersecurity at Maine Hospitals
Apr07

Maine House Unanimously Passes Bill to Strengthen Cybersecurity at Maine Hospitals

The Maine House of Representatives has voted unanimously to advance a bill that seeks to strengthen cybersecurity at Maine hospitals to prevent cyberattacks and ensure continuity of care following cyber intrusions. The bill faces further votes in the House and Senate in the coming days. The bill was proposed by Rep. Julie McCabe (D-Lewiston), a member of the Health and Human Services Committee, following two cyberattacks last year that impacted five Maine hospitals –  Covenant Health’s St. Mary’s Hospital in Lewiston, St. Joseph’s Hospital in Bangor, and Central Maine Medical Center’s hospitals in Lewiston, Bridgton, and Rumford. The Covenant Health ransomware attack alone affected 478,188 individuals, and along with the cyberattack on Central Maine Medical Center, around one-third of state residents were affected. Those cyberattacks had a negative impact on patient care, crippling basic communication services, exposing serious breakdowns in hospitals’ protocols, and causing major disruption to patient care that lasted for weeks, including disruptions to preventative care and...

Read More
Trump Administration Proposes 12.5% Cut to HHS Budget for FY 2027
Apr07

Trump Administration Proposes 12.5% Cut to HHS Budget for FY 2027

The HHS’ Office for Civil Rights (OCR) has long been seeking an increase to its budget to support its HIPAA enforcement activities; however, that is looking unlikely as the Trump Administration is seeking to cut funding for the Department of Health and Human Services (HHS) in 2027. The Trump Administration has proposed $111.1 billion in discretionary funding for fiscal year 2027, a $15.8 billion (12.5%) cut in funding compared to FY 2026. One of the main casualties is the National Institutes of Health (NIH), which faces a $5 billion cut to its budget, plus $5 billion in cuts through consolidations and eliminations of programs across several sub agencies, including the Health Resources and Services Administration (HRSA), Substance Abuse and Mental Health Services Administration (SAMHSA), Centers for Disease Control and Prevention (CDC), and the Office of the Assistant Secretary for Health (OASH). The Trump Administration is seeking to establish the Administration for a Healthy America (AHA), which, in part, will involve the elimination of programs that the Trump Administration says...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist