25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Phishing Attack Affects Multiple Cancer Treatment Centers
Jul08

Phishing Attack Affects Multiple Cancer Treatment Centers

A phishing attack has affected multiple cancer care providers that are part of the Integrated Oncology Network (ION). All affected entities have issued similar breach notices about the incident, which involved unauthorized access to a small number of employee email and SharePoint accounts in what was described as “a sophisticated phishing attack.” Immediate action was taken to secure the affected accounts, and an investigation was launched to determine the nature of the attack and the extent of any data breach. The forensic investigation confirmed that the accounts were compromised over three days between December 13, 2024, and December 16, 2024. Some of the compromised accounts contained patient information. The review of the accounts confirmed that they contained names, addresses, dates of birth, financial account information, diagnoses, lab results, medications, treatment information, health insurance and claims information, provider names, dates of treatment, and Social Security numbers. The affected cancer care providers have not found any evidence of misuse of...

Read More
Horizon Healthcare RCM Announces December 2024 Ransomware Attack
Jul08

Horizon Healthcare RCM Announces December 2024 Ransomware Attack

Horizon Healthcare RCM, a Crown Point, IN-based revenue cycle management firm, has recently disclosed a ransomware attack and data breach. The attack was identified on December 27, 2024, and the forensic investigation confirmed that the ransomware group had access to its network between December 25 and December 27, 2024, and exfiltrated sensitive data. The review of the affected files was completed on May 20, 2025. The types of information involved vary from individual to individual and generally include an internal Horizon number, customer number, or other patient identifier in combination with general claims processing information. A limited number of individuals (under 500) had other information compromised, such as non-address contact information, date of birth, Social Security number, driver’s license number, passport number, payment card information, and/or checking/financial account information. Horizon has started notifying the affected individuals by mail and has offered complimentary identity monitoring services to certain individuals. The substitute breach notice...

Read More
Compumedics Cyberattack Affects Almost a Dozen Healthcare Providers
Jul08

Compumedics Cyberattack Affects Almost a Dozen Healthcare Providers

Compumedics USA Inc., a vendor that provides diagnostic and research technologies for sleep disorders for use in sleep study clinics, has recently disclosed a data security incident that has affected patients of several of its healthcare provider clients. On March 22, 2025, Compumedics identified unauthorized access to its network which disrupted the operations of its information technology systems. Immediate action was taken to secure its systems and third-party forensics experts were engaged to investigate the incident. They confirmed that an unauthorized third party had access to its systems between February 15, 2025, and March 23, 2025, during which time files were copied from its systems. The file review was completed on May 13, 2025, and confirmed that some of the files contained patient information such as names, dates of birth, demographic information, medical record numbers, diagnosis information, treatment information, dates of treatment, provider names, and sleep study details and results. A subset of the affected individuals also had their Social Security numbers...

Read More
Behavioral Healthcare Provider Settles HIPAA Risk Analysis Investigation for $225,000
Jul08

Behavioral Healthcare Provider Settles HIPAA Risk Analysis Investigation for $225,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) with Deer Oaks – The Behavioral Health Solution for $225,000. Deer Oaks is a long-term care-focused behavioral healthcare provider that offers psychological and psychiatric services to residents of long-term care and assisted living facilities across the United States. Deer Oaks is an affiliated covered entity and directly owns and operates fourteen affiliated covered entity components, including Deer Oaks Consultation Services (DOCS). On December 6, 2021, OCR received a complaint that DOCS had impermissibly disclosed electronic protected health information (ePHI) online. Patient discharge forms could be accessed via the Internet without authorization. The forms contained patient names, dates of birth, patient identification numbers, facilities, and diagnoses. The discharge summaries were exposed online due to a coding error in a discontinued pilot program for an online patient portal. The...

Read More
Surmodics & Kentfield Hospital Fall Victim to Cyberattacks
Jul07

Surmodics & Kentfield Hospital Fall Victim to Cyberattacks

Data breaches have been disclosed by a Minnesota medical device manufacturer and the threat actor behind an apparent attack on a California hospital. Surmodics, Minnesota Surmodics, an Eden Prairie, MN-based provider of catheters, medical device coatings, and chemical components for in vitro diagnostic tests and microarrays, has disclosed a security incident to the United States Securities and Exchange Commission (SEC). According to the filing, a breach of its IT systems was detected on June 5, 2025, which rendered certain IT systems and data unavailable. While not explicitly stated, the language used to describe the incident suggests this was a ransomware attack. Third-party cybersecurity experts have been engaged to help contain, investigate, and remediate the incident. Critical IT systems have been restored and IT data is being validated. The remaining systems and data are in the process of being restored and validated. While the cyberattack has taken systems offline, Surmodics said it has continued to take and ship customer orders using alternative systems. Surmotics holds a...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist