25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Henry Ford Health Settles Tracking Technology Lawsuit
Jul11

Henry Ford Health Settles Tracking Technology Lawsuit

Another settlement has been reached to resolve a class action lawsuit over the use of third-party tracking tools on healthcare websites. Henry Ford Health, a not-for-profit health system in Detroit and the second-largest health system in Michigan, used tracking technologies on its website that collected information from web visitors. According to the complaint, tracking tools such as Meta Pixel, Google Analytics, Google Tag Manager, and Google DoubleClickAds, were installed on its website. Those tools collected visitor information, including protected health information (PHI), which was transferred to third parties such as Meta and Google Inc. without website users’ knowledge or consent. The tools were even used on web pages that required authorization to access, such as the MyChart Patient Portal. Henry Ford Health encouraged patients to use the website and patient portal to submit information, review their health records, book appointments, schedule visits, pay bills, and communicate with providers. From the information collected, third parties could infer that a patient was...

Read More
Ransomware Attacks Fall in Q2 as Ecosystem Reshuffles
Jul11

Ransomware Attacks Fall in Q2 as Ecosystem Reshuffles

Ransomware attacks declined by 23% from the previous quarter, although they are up 43% on this time last year, with the dip only partially explained by normal seasonal variations. In Q2 of 2025, 1,591 new victims of ransomware attacks were posted publicly on data leak sites, at an average of 17.5 per day, compared to 22.9 per day in Q1 of 2025 and 12.2 per day in Q2 of 2024. Compared to last year, Alphv/BlackCat – a major player in the ransomware ecosystem – has shut down, LockBit has been subject to law enforcement action, and there has been significant disruption to the RansomHub operation, all of which have contributed to the fragmentation of the ransomware ecosystem. Compared to last year, there are more small groups and lone wolves operating, who find it much easier to stay under the radar of law enforcement. In Q2, 2024, there were 41 active ransomware groups, and 71 in Q2, 2025, according to the quarterly Ransomware & Cyber Threat Report from the GuidePoint Research and Intelligence Team (GRIT), a 45% year-over-year increase. The United States is still the primary target...

Read More
HHS Publishes New General Policy on Criminal Referrals for Regulatory Violations
Jul10

HHS Publishes New General Policy on Criminal Referrals for Regulatory Violations

When individuals and entities violate Health and Human Services (HHS) regulations, HHS may choose to make a criminal referral to the Department of Justice (DoJ). For instance, when a healthcare employee accesses patient data without authorization for financial gain or in order to inflict harm on an individual, there may be criminal charges for the violation. The HHS has recently published its plans to address regulations that impose criminal liability, following on from President Trump’s Executive Order on Fighting Overcriminalization in Federal Regulations (Executive Order 14294). The Executive Order is intended to reduce the regulatory burden on everyday Americans and ensure that no American faces criminal charges for violating a regulation that they have no reason to know exists. The Executive Order states that the policy of the United States is criminal enforcement of criminal regulatory offenses is disfavored, and the prosecution of criminal regulatory offenses is most appropriate “for persons who know or can be presumed to know what is prohibited or required by the regulation...

Read More
Gardner Orthopedics Ransomware Attack Affects 47,000 Patients
Jul10

Gardner Orthopedics Ransomware Attack Affects 47,000 Patients

Data breaches have been announced by Gardner Orthopedics in Florida, Blue Cross and Blue Shield of Massachusetts, Health Care and Rehabilitation Services of Southeastern Vermont, Retina Associates of Cleveland, and Clement Manor in Wisconsin. Gardner Orthopedics, Florida Gardner Orthopedics in Fort Myers, Florida, has recently determined that the protected health information of 47,000 patients was potentially compromised in a recent cyberattack. While not described as a ransomware attack, the Inc Ransom ransomware group claimed responsibility and added Gardner Orthopedics to its dark web data leak site on May 15, 2025, along with samples of the stolen data. Gardner Orthopedics detected the intrusion on April 29, 2025, and engaged third-party cybersecurity experts to contain the incident and determine the nature and scope of the unauthorized activity. The company also rebuilt the affected systems and strengthened security. Data had been backed up, and the backups were unaffected, so data could be recovered, and the network was rebuilt and restored within a week. Information...

Read More
MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit
Jul10

MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit

MarinHealth has agreed to a $3 million settlement to resolve claims related to its use of the Meta Pixel tracking tool on its website between 2019 and 2025. MarinHealth is the operator of Marin Health Medical Center and various outpatient clinics in Marin County and Sonoma County in California. Like many other healthcare providers, MarinHealth used Meta Pixel and other tracking tools on its website to collect visitor information. Meta Pixel, similar to other website tracking tools, gathers data from individuals who visit a website where the tool is installed. The tool collects information about website usage, including information that could be used to identify that individual. That information is then transmitted to Meta and can potentially be used to serve personalized ads elsewhere on the web. If Meta Pixel collects information from dropdown menus, button click data, and the pages an individual visits on a healthcare website, advertisements could be served related to a health condition the user has, believes they have, or has researched. The lawsuit against MarinHealth –...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist