25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Nacogdoches Memorial Hospital Data Breach More Than 257,000 Individuals
Apr01

Nacogdoches Memorial Hospital Data Breach More Than 257,000 Individuals

Nacogdoches Memorial Hospital (NMH), a 226-bed hospital in Nacogdoches, Texas, has recently announced a data security incident that was first identified on January 31, 2026. A hacker gained access to its computer network and information systems and potentially obtained files containing the personal and protected health information of up to 257,073 individuals, according to the notification sent to the Maine Attorney General. While the data security incident was detected on January 31, 2026, the forensic investigation determined that the hacker first gained access to its network two weeks previously, on January 15, 2026. NMH explained in its notification letters that it has not detected any misuse of the impacted data and that there are no indications that there will be any data misuse. While NMH said the hacker may have accessed or acquired patient information, with two weeks inside its network, patients should assume that their data has been compromised and should consider taking steps to prevent data misuse, such as implementing a fraud alert or security freeze with one of the...

Read More
Identify Your Highest-Risk HIPAA Compliance Gaps
Apr01

Identify Your Highest-Risk HIPAA Compliance Gaps

HIPAA compliance is mandatory for organizations that qualify as HIPAA covered entities.  With our 2-minute free HIPAA Compliance Risk Calculator, you can quickly Identify Your Highest-Risk HIPAA Compliance Gaps and receive a report with actionable insights to immediately improve compliance with HIPAA. Please note that in order for the report to accurately reflect your organization’s compliance status, you need to be aware of your organization’s current compliance activities when you take our free HIPAA risk check. Please also note that this check is designed to be used by organizations that are HIPAA covered entities. It is not suitable for solo practitioners or HIPAA Business Associates. Why use the HIPAA Compliance Risk Calculator? Being aware of your compliance obligations and those of your business partners can be vital because, in the event of a HIPAA violation, ignorance of the HIPAA requirements is not an acceptable defense against enforcement action. This free calculator is: Quick and Convenient: In just two or three minutes, answer a series of targeted questions designed...

Read More
DoL OIG to Audit OSHA to Assess Agency’s Efforts to Prevent Workplace Violence
Mar31

DoL OIG to Audit OSHA to Assess Agency’s Efforts to Prevent Workplace Violence

The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem of workplace violence. Workplace violence is a significant occupational safety concern, especially in the healthcare industry, where healthcare employees are regularly subjected to physical assaults, verbal threats, and other attacks. According to the U.S. Bureau of Labor Statistics, healthcare workers are five times as likely to suffer nonfatal workplace injuries as professionals in other sectors, and across all sectors, acts of violence and related injuries are the third leading cause of fatal occupational injuries in the United States. Data from 2022 shows that out of the 5,486 fatal injuries that occurred in the workplace, 849 involved intentional injury caused by another person. A Medscape survey published earlier this year found that almost 70% of physicians believe that physical security at work is a more pressing issue than it was three years ago, and a 2024 poll of members of...

Read More
Data Breach Reported by Orthopedic Implant Manufacturer TriMed
Mar31

Data Breach Reported by Orthopedic Implant Manufacturer TriMed

TriMed, a Santa Clarita, California-based manufacturer of upper and lower orthopedic implants, has announced a data security incident involving unauthorized access to parts of its network where order forms and invoices were stored. While in the most part the exposed data only contained information related to the company’s hardware and the individuals who received it, in some cases, the documentation included personal information. TriMed identified suspicious activity without certain systems in September 2025, prompting an investigation to determine the nature and scope of the activity. The forensic investigation determined that an unauthorized third party had access to parts of its environment between September 13, 2025, and September 21, 2025, during which time, files were potentially accessed and acquired by the unauthorized third party. TriMed manufactures hardware that is surgically implanted to repair or replace damaged joints. A programmatic and manual review of the exposed files confirmed that they contained information related to that hardware, which would have been ordered...

Read More
Urgent Action Required to Fix Actively Exploited Critical Citrix NetScaler Vulnerability
Mar31

Urgent Action Required to Fix Actively Exploited Critical Citrix NetScaler Vulnerability

Cybersecurity researchers warn that there could potentially be mass exploitation of a critical flaw in Citrix NetScaler products on a scale similar to the CitrixBleed vulnerability in 2023, which was exploited by ransomware groups. Earlier this week, Citrix disclosed a critical vulnerability affecting its NetScaler ADC and NetScaler Gateway application-delivery products. The vulnerability is an input validation flaw that could allow an attacker to leak sensitive information. The vulnerability occurs in NetScaler ADC and NetScaler Gateway when configured as a SAML IdP, leading to memory overread. The vulnerability is tracked as CVE-2026-3055 and has a CVSS v4 severity score of 9.3. The vulnerability affects the following NetScaler products, but only when the appliance is configured as a SAML identity provider (IdP): NetScaler ADC and NetScaler Gateway 1 BEFORE 14.1-66.59 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23 NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262 Citrix has released updated software versions to fix the vulnerability, and all customers are advised to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist