25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Texas Enacts Law Governing Security and Storage of Electronic Health Records
Jul18

Texas Enacts Law Governing Security and Storage of Electronic Health Records

The Governor of Texas has added his signature to a bill regulating the storage and security of electronic health records and the use of artificial intelligence in healthcare for diagnostic purposes. The bill also introduces a new definition of “biological sex” and sets rules concerning the amendment of biological sex in electronic health records. S.B. 1188 applies to HIPAA-covered entities and healthcare practitioners. The new law requires the electronic medical records of all Texas patients to be physically maintained in the United States, including if the medical records are stored by a third-party or subcontracted computing facility that provides cloud computing services. In such cases, the data center where the records are stored must be in the United States. The law also applies to electronic health records stored using technology that allows patient information to be electronically retrieved, accessed, or transmitted. Covered entities must implement reasonable and appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and...

Read More
High Severity Vulnerability Identified in Panoramic Dental Imaging Software
Jul18

High Severity Vulnerability Identified in Panoramic Dental Imaging Software

A high-severity vulnerability has been identified in Panoramic Dental Imaging Software that could allow a standard user to elevate privileges to NT Authority/SYSTEM. The vulnerability, identified by Damian Semon Jr. of Blue Team Alpha LLC, affects Panoramic Corporation Dental Imaging Software v.9.1.2.7600, and is due to an uncontrolled search path element (CWE-427), which makes the product vulnerable to DLL hijacking. The vulnerability is tracked as CVE-2024-22774 and has been assigned a CVSS v4 base score of 8.5 (CVSS v3.1: 7.8). The vulnerability affects an SDK component owned by Oy Ajat Ltd, which is no longer supported. A patch has not been released by Panoramic to correct the vulnerability, as it does not affect a component owned by Panoramic Corporation. No recommended mitigations have been released. Any users should contact Panoramic Corporation for further information via email at [email protected] The vulnerability has been reported to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) which recommends users take defensive measures, including minimizing...

Read More
Data Breaches Up 10% Although Victim Count Falls Sharply
Jul18

Data Breaches Up 10% Although Victim Count Falls Sharply

This year is set to become another record-breaking year for data breaches, according to the Identity Theft Resource Center (ITRC). The ITRC H1 2025 Data Breach Report shows an 11% year-over-year increase in reported data breaches, with 1,732 data compromises tracked by ITRC between January 1, 2025, and June 30, 2025. That’s 54.9% of the full year total for 2024. The increase in data breaches has largely been driven by cyberattacks, which account for 77.83% of all confirmed data compromises in H1 – 1,348 incidents. Across those incidents, the personal data of 114,582,621 individuals was compromised – 69.13% of the total number of victims across all data compromise incidents. The second main cause of data breaches was phishing/smishing/BEC attacks, with 251 confirmed incidents, followed by 73 confirmed ransomware attacks. The number of ransomware attacks is likely to be substantially higher, as ransomware is often not mentioned in breach notifications. There were 129 data compromises attributed to system or human error, impacting more than 6 million individuals. In total,...

Read More
OSH Act Penalty Reductions Expanded to Support Small Businesses
Jul17

OSH Act Penalty Reductions Expanded to Support Small Businesses

The Occupational Health and Safety Administration has issued updated guidance on the penalty structure in Section 7 of the Occupational Safety and Health (OSH) Act. The OSH Act was signed into law in 1970 to ensure safe and healthful working conditions for employees in the United States. In addition to setting workplace safety and health standards, it established the Occupational Health and Safety Administration (OSHA). OSHA is authorized to enforce compliance with the OSH Act and can issue penalties for violations. The penalties imposed by OSHA are intended to deter future violations and ensure that employers maintain a safe and healthful working environment. To ease the burden on small businesses and to promote the swift resolution of workplace hazards, OSHA has previously applied a 70% reduction in penalties for very small businesses with 10 or fewer employees. The new policy, detailed in the Penalties and Debt Collection section of OSHA’s Field Operations Manual, expands the penalty reductions for small employers to include businesses that employ up to 25 employees. The aim is...

Read More
Fake Claim from Ransomware Group About Theft of Patient Data
Jul17

Fake Claim from Ransomware Group About Theft of Patient Data

A ransomware group called Stormous claims to have stolen the personal and health information of 600,000 patients from North Country HealthCare. North Country HealthCare is a federally qualified community health center that provides comprehensive healthcare services to 11 communities in northern Arizona at 14 locations. Stormous is a pro-Russia ransomware group that has been in operation since early 2022. The group engages in double extortion, stealing data and encrypting files, and demanding payment to obtain the decryption keys and prevent the publication of the stolen data on its dark web data leak site. The group is known to have attacked at least 150 companies, generally conducting fewer than 10 attacks per month, although in May 2025, the group conducted more than 15 attacks. The sectors most targeted by the group are hospitality and tourism, technology, business services, healthcare, and government. The top five countries attacked are Spain, the United States, the United Arab Emirates, France, and Brazil. North Country HealthCare was listed on the group’s data leak site on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist