25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breaches Announced By Decisely Insurance Services & Apex Global Solutions
Jun25

Data Breaches Announced By Decisely Insurance Services & Apex Global Solutions

Data breaches have been announced by Decisely Insurance Services, Apex Global Solutions, Upper Dublin Family Dentistry, and Arkansas Urology Associates. Ransomware groups have claimed attacks on West Texas Oral and Facial Surgery and Freedman HealthCare. Decisely Insurance Services, Georgia Decisely Insurance Services has notified 65,405 individuals about a December breach involving its cloud storage platform. The Roswell, GA-based benefits brokerage and HR services firm identified suspicious activity within its cloud storage platform on December 17, 2024. Steps were taken to secure the platform and prevent further unauthorized access, and cybersecurity experts were engaged to investigate and determine the nature and scope of the unauthorized activity. The investigation confirmed there was unauthorized access and data acquisition on December 16, 2024. Decisely spent the following months reviewing the platform to identify the owners of the data and the individuals affected, and has been working with those clients to obtain contact information to allow notification letters to be...

Read More
Arisa Health to Pay $1.9 Million to Settle Data Breach Litigation
Jun24

Arisa Health to Pay $1.9 Million to Settle Data Breach Litigation

Arisa Health, an Arkansas behavioral health system, has agreed to pay $1.9 million to settle a class action lawsuit that was filed in response to a March 2024 cyberattack. Hackers breached the Arisa Health network and gained access to the protected health information of more than 375,000 patients. Hackers had access to the Arisa Health network for almost three weeks between March 1, 2024, and March 18, 2024, and obtained files containing patient names, contact information, Social Security numbers, health insurance information, medical histories, diagnoses, driver’s license numbers, and certifications of substance abuse program completion. A class action lawsuit – Rebecca Miller et. al., v. Arisa Health, Inc. – was filed in the Circuit Court of Johnson County, Arkansas over the data breach. The plaintiffs alleged that the cyberattack and data breaches were the result of negligence by Arisa Health, which failed to implement reasonable and appropriate cybersecurity measures to prevent unauthorized access to highly sensitive patient data. Arisa Health denies all claims and...

Read More
Albany College of Pharmacy and Health Sciences Cyberattack Affects 28,600 Individuals
Jun24

Albany College of Pharmacy and Health Sciences Cyberattack Affects 28,600 Individuals

Data breaches have recently been announced by Albany College of Pharmacy and Health Sciences, Central Kentucky Radiology, TRG Medical Imaging, and Elmore County in Idaho. Albany College of Pharmacy and Health Sciences Albany College of Pharmacy and Health Sciences (ACPHS) in New York has notified 28,600 individuals about a September 2024 data security incident. Unusual network activity was identified on September 14, 2024, and an investigation was launched to determine the cause of the activity. Assisted by third-party cybersecurity experts, ACPHS determined that an unauthorized third party had access to its network between August 31, 2024, and September 14, 2024, during which time, files may have been copied. The types of information potentially compromised in the incident vary from individual to individual and include names in combination with one or more of the following: date of birth, birth certificate, account number, routing number, security code, marriage certificate, mother’s maiden name, digital signature, passport number, government identification number, Social Security...

Read More
MNGI Digestive Health Agrees to Pay $2.8 Million to Settle Data Breach Lawsuit
Jun23

MNGI Digestive Health Agrees to Pay $2.8 Million to Settle Data Breach Lawsuit

MNGI Digestive Health has agreed to settle a class action lawsuit that alleged negligence for failing to protect the sensitive data of its patients. The litigation stems from a 2023 ransomware attack by the ALPHV/Blackcat ransomware group on the Minnesota gastroenterology practice. MNGI Digestive Health detected the attack on August 25, 2024, and the forensic investigation confirmed that its network was first breached on August 20, 2024. MNGI Digestive Health said the data compromised in the incident included names, medical information, health insurance information, dates of birth, patient account numbers, financial account information, driver’s license or state ID numbers, passport numbers, payment card information, usernames and associated passwords, taxpayer ID numbers, biometric data, and Social Security numbers. The breach was reported to the HHS’ Office for Civil Rights as affecting 767,670 individuals. Several class action lawsuits were filed against MNGI Digestive Health over the data breach, which were consolidated into a single action in the Minnesota District Court for...

Read More
Texas Judge Vacates Abortion Privacy Protections
Jun23

Texas Judge Vacates Abortion Privacy Protections

A Texas Judge has ruled that the HIPAA Privacy Rule update issued by the U.S. Department of Health and Human Services (HHS) in 2024 to strengthen reproductive health care privacy was unlawful and has vacated the rule. Background and HHS Rulemaking on Reproductive Healthcare Privacy In response to the Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization in 2022 and the overturning of Roe v. Wade, the HHS issued a notice of proposed rulemaking (NMPR) to strengthen reproductive health information privacy. The Supreme Court’s decision eliminated the federal right to abortion and returned the authority to regulate abortion to individual states. Following the decision, many U.S. states introduced laws banning or severely restricting abortions for state residents. A consequence of those restrictions is that individuals wishing to terminate their pregnancies had to travel to states with more permissive reproductive healthcare laws to have those procedures performed legally. Due to concerns that states with strict abortion laws could try to prosecute state...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist