25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Gardner Orthopedics Ransomware Attack Affects 47,000 Patients
Jul10

Gardner Orthopedics Ransomware Attack Affects 47,000 Patients

Data breaches have been announced by Gardner Orthopedics in Florida, Blue Cross and Blue Shield of Massachusetts, Health Care and Rehabilitation Services of Southeastern Vermont, Retina Associates of Cleveland, and Clement Manor in Wisconsin. Gardner Orthopedics, Florida Gardner Orthopedics in Fort Myers, Florida, has recently determined that the protected health information of 47,000 patients was potentially compromised in a recent cyberattack. While not described as a ransomware attack, the Inc Ransom ransomware group claimed responsibility and added Gardner Orthopedics to its dark web data leak site on May 15, 2025, along with samples of the stolen data. Gardner Orthopedics detected the intrusion on April 29, 2025, and engaged third-party cybersecurity experts to contain the incident and determine the nature and scope of the unauthorized activity. The company also rebuilt the affected systems and strengthened security. Data had been backed up, and the backups were unaffected, so data could be recovered, and the network was rebuilt and restored within a week. Information...

Read More
MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit
Jul10

MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit

MarinHealth has agreed to a $3 million settlement to resolve claims related to its use of the Meta Pixel tracking tool on its website between 2019 and 2025. MarinHealth is the operator of Marin Health Medical Center and various outpatient clinics in Marin County and Sonoma County in California. Like many other healthcare providers, MarinHealth used Meta Pixel and other tracking tools on its website to collect visitor information. Meta Pixel, similar to other website tracking tools, gathers data from individuals who visit a website where the tool is installed. The tool collects information about website usage, including information that could be used to identify that individual. That information is then transmitted to Meta and can potentially be used to serve personalized ads elsewhere on the web. If Meta Pixel collects information from dropdown menus, button click data, and the pages an individual visits on a healthcare website, advertisements could be served related to a health condition the user has, believes they have, or has researched. The lawsuit against MarinHealth –...

Read More
Trend Micro Warns of New Ransomware Group Targeting Healthcare Orgs
Jul09

Trend Micro Warns of New Ransomware Group Targeting Healthcare Orgs

A new ransomware group has recently emerged that is targeting multiple sectors, especially healthcare, technology, and event services. According to a recent report from cybersecurity firm Trend Micro, the Bert ransomware group’s first attacks were observed in the United States and Asia, although internal telemetry has identified further victims across Europe. While only limited evidence has been found, the new group, tracked by Trend Micro as Water Pombero, is thought to be Russian, or at least have links to the region, as the group downloads and executes its ransomware from a remote IP address associated with ASN 39134, which is registered in Russia. The Bert Windows variant uses a straightforward code structure and a standard AES algorithm for encryption; however, the group is actively developing and refining the ransomware and improving and streamlining operations. For instance, the early iterations enumerated drives, dropped a ransom note in each directory, and collected valid file paths and saved them in an array, only proceeding with multi-threaded encryption after the...

Read More
OCR Announces Limited Waiver of HIPAA Sanctions & Penalties in Texas
Jul09

OCR Announces Limited Waiver of HIPAA Sanctions & Penalties in Texas

On July 8, 2025, HHS Secretary Robert F. Kennedy Jr. declared a Public Health Emergency exists in the State of Texas as a result of severe storms, straight-line winds, and flooding, and has done so since July 2, 2025. The HHS Secretary has also announced a limited waiver of HIPAA sanctions and penalties for covered hospitals in the areas of Texas covered by the PHE for a limited period. The PHE declaration and HIPAA waiver follow President Donald Trump’s July 6, 2025, Major Disaster Declaration for Kerr County, Texas. Severe natural disasters such as hurricanes and floods place additional challenges on healthcare providers, which can make compliance with certain provisions of the HIPAA Rules difficult, such as those related to the sharing of individuals’ protected health information with friends and family, public health officials, and emergency personnel. During a PHE, the HIPAA Rules are not suspended; however, to ease the burden on covered hospitals in the area covered by a PHE, the HHS Secretary often announces a limited waiver of HIPAA sanctions and penalties for specific...

Read More
Gramercy Surgery Center Agrees to Pay $400,000 to Cover Data Breach Claims
Jul09

Gramercy Surgery Center Agrees to Pay $400,000 to Cover Data Breach Claims

Gramercy Surgery Center in New York has agreed to settle a class action lawsuit that was filed in response to a June 2024 ransomware attack. The settlement provides a maximum of $400,000 to cover claims for out-of-pocket expenses and cash payments to class members. Gramercy Surgery Center identified the attack on June 18, 2024. While not described as a ransomware attack, the Everest ransomware group claimed responsibility and added Gramercy Surgery Center to its data leak site. The group had access to its network since June 14, 2025, and exfiltrated patient information such as names, addresses, Social Security numbers, dates of birth, driver’s license/state identification card numbers, medical record numbers, treatment information, and health insurance information. The data breach was reported to the HHS’ Office for Civil Rights (OCR) as affecting 52,544 individuals.* A lawsuit – Horvath v. Gramercy Surgery Center, Inc. – was filed against Gramercy Surgery Center in the United States District Court for the Southern District of New York over the data breach, alleging Gramercy...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist