25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is the Maximum Penalty for Violating HIPAA?
Jun02

What is the Maximum Penalty for Violating HIPAA?

The maximum penalty for violating HIPAA is currently $71,162 (June 2025) for a violation that is attributable to willful neglect and that, despite being alerted to the violation by HHS’ Office for Civil Rights, is not corrected within 30 days. However, this figure represents the maximum penalty per violation type. It is often the case that data breaches are attributable to more than one HIPAA violation  When Congress passed HIPAA in 1996, it set the maximum penalty for violating HIPAA at $100 per violation with an annual cap of $25,000. These limits were applied when the Department of Health & Human Services (HHS) published the Enforcement Rule in 2006 and they stayed in force until the publication of the Final Omnibus Rule in 2013. Among other changes to HIPAA, the Final Omnibus Rule introduced amendments to the Enforcement Rule attributable to passage of the HITECH Act in 2009. The HITECH Act mandated a four tier penalty structure for HIPAA violations and new minimum and maximum penalties for violating HIPAA. The four tiers were based on the level of culpability...

Read More
U.S. Dermatology Partners Announce June 2024 Cyberattack & Data Breach
Jun02

U.S. Dermatology Partners Announce June 2024 Cyberattack & Data Breach

Data breaches have recently been announced by U.S. Dermatology Partners in Texas, the Smith Institute for Urology in New York, Shore Medical Center in New Jersey, Connections for Kids in Maine, and the Missouri Department of Conservation. U.S. Dermatology Partners, Texas U.S. Dermatology Partners (USDP), a network of more than 100 dermatology practices in Arizona, Colorado, Kansas, Maryland, Missouri, Oklahoma, Texas, and Virginia, has recently announced a June 2024 cyberattack and data breach. USDP experienced network disruption on June 19, 2024, indicative of a cyberattack. Assisted by third-party digital forensics experts, USDP confirmed that there had been unauthorized access to its network on June 19, 2024, and files were exfiltrated to “an external destination”. A comprehensive review of those files was completed on April 2, 2025, when it was confirmed that the stolen data included names, dates of birth, medical record numbers, health insurance information, and other information related to the dermatology services received at one of its managed practices. A...

Read More
Serviceaide Facing Multiple Class Action Lawsuits Over 483K-Record Data Breach
May31

Serviceaide Facing Multiple Class Action Lawsuits Over 483K-Record Data Breach

A California company that provides an agentic AI-powered software solution for streamlining healthcare operations and improving operational efficiency has recently disclosed a major data breach involving the personal and protected health information of almost half a million patients of Catholic Health in Buffalo, New York. The HIPAA Journal reported on the breach on May 19, 2025, the same day six class action lawsuits were filed in federal court in California over the data breach. More lawsuits are expected to be filed in the coming days. The data breach was discovered on November 15, 2024, when an unsecured Elasticsearch database was identified that had been exposed online for more than 6 weeks between September 19, 2024, and November 5, 2024. The database contained the data of approximately 483,000 Catholic Health patients, including names, dates of birth, Social Security numbers, medical/health information, treatment information, health insurance information, and email/usernames and accompanying passwords. The affected individuals started to be notified about the data breach on...

Read More
OCR Settles HIPAA Investigation with Comstar for $75,000
May30

OCR Settles HIPAA Investigation with Comstar for $75,000

The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an alleged violation of the risk analysis requirement of the HIPAA Security Rule. This is the 9th enforcement action under its risk analysis enforcement initiative, the 13th ransomware-related enforcement action to result in a financial penalty, and the 16th financial penalty of the year to resolve alleged HIPAA violations. Comstar, LLC, a Rowley, Massachusetts-based provider of billing, collection, and related services to non-profit and municipal emergency ambulance services, has agreed to pay a financial penalty of $75,000 to settle the alleged HIPAA violation. OCR initiated an investigation following a May 26, 2022, report of a ransomware attack and data breach. The ransomware group gained access to files containing names, dates of birth, medical assessment and medication information, health insurance information, and Social Security numbers. The breach was reported to OCR by Comstar on behalf of some of its covered entity clients as involving the protected health information of 68,957...

Read More
Bradford Health Services Notifies Patients About 2023 Cyberattack
May30

Bradford Health Services Notifies Patients About 2023 Cyberattack

Data breaches have recently been announced by Bradford Health Services in Alabama, Doctors Hospital at Renaissance in Texas, and Molecular Testing Labs in Washington. Ransomware groups have claimed responsibility for attacks on Desert Behavioral Health in Nevada and Curewell Specialty Pharmacy & Surgicals in New York. Bradford Health Services, Alabama Bradford Health Services in Birmingham, Alabama, has issued a May 30, 2025, notice about a data security incident that was detected more than 18 months ago on December 8, 2023. According to the breach notice, an investigation was immediately initiated when unusual activity was identified within its network. The investigation confirmed that an unauthorized third party had accessed its network and may have viewed or acquired files containing patient data. A thorough review was initiated of the affected files, and that process was completed on May 15, 2025. The data potentially compromised in the security incident included names, driver’s license numbers, dates of birth, diagnoses, treatment information, physician names, medical...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist