25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Shields Health Care Agrees to $15.35 Million Settlement to Resolve Data Breach Litigation
May23

Shields Health Care Agrees to $15.35 Million Settlement to Resolve Data Breach Litigation

Shields Health Care Group has negotiated a $15.35 million settlement to resolve claims stemming from a 2022 data breach that affected more than 2 million patients. Shields Health Care is a Massachusetts-based provider of ambulatory surgical center management and medical imaging services throughout New England. A security breach was detected on March 28, 2022, and the forensic investigation determined that a threat actor had access to its network from March 7, 2022, to March 21, 2022. A security alert had been triggered on March 18, 2022, which was investigated and determined not to involve a HIPAA breach. Suspicious activity was then detected, with the investigation confirming unauthorized access and data theft. Over the course of two weeks, the hackers exfiltrated sensitive data such as full names, Social Security numbers, dates of birth, contact information, provider information, billing information, insurance information, medical record numbers, diagnoses, and treatment information. More than 50 facility partners were affected by the breach. Notification letters started to be...

Read More
OSHA Updates Targeted Inspection Program for Establishments with the Highest Injury and Illness Rates
May23

OSHA Updates Targeted Inspection Program for Establishments with the Highest Injury and Illness Rates

The Occupational Safety and Health Administration (OSHA) at the U.S. Department of Labor has updated its Site-Specific Targeting (SST) inspection program. The changes took effect on May 20, 2025. The SST program aims to ensure that employers provide safe and healthful workplaces through inspections to ensure that employers are remediating hazards in the workplace and maintaining OSHA compliance. The SST inspection program is the main OSHA site-specific programmed inspection initiative for non-construction workplaces with 20 or more employees and is targeted at industries and establishments that are most likely to be experiencing elevated rates and increasing numbers of workplace illnesses and injuries. Under the program, OSHA directs its resources to workplaces with the highest rates of injuries and illnesses based on employer-submitted 300A data for calendar years 2021, 2022, and 2023. OSHA generates its inspection lists based on elevated Days Away, Restricted, or Transferred (DART) rates; upward trending rates; establishments that failed to submit the required 2023 Form 300A data...

Read More
Coastal Orthopedics Agrees to Pay $1.4 Million to Settle Data Breach Litigation
May22

Coastal Orthopedics Agrees to Pay $1.4 Million to Settle Data Breach Litigation

Coastal Orthopedics & Sports Medicine of Southwest Florida (COSM) has agreed to settle class action litigation stemming from a June 2023 cyberattack and data breach that affected 203,427 individuals. Between June 6, 2023, and June 11, 2023, hackers had access to its network and exfiltrated files containing patient names, dates of birth, Social Security numbers, driver’s license numbers, diagnoses, treatment information, financial account information, health insurance information, and other types of sensitive data. Multiple lawsuits were filed against COSM over the data breach, two in the Circuit Court of the Twelfth Judicial Circuit in and for Manatee County, Florida, by plaintiffs Karl Ford and Barbara Balbo, and one in the Middle District of Florida, Tampa Division, by plaintiff Vikki Comarsh-White. A notice of voluntary dismissal was filed by plaintiff Comarsh-White, and the other two lawsuits were consolidated into a single lawsuit, In Re: Coastal Orthopedics & Sports Medicine of Southwest Florida Data Breach Litigation, in October 2024. The lawsuit alleged negligence...

Read More
Massachusetts Mental Health Service Provider Suffers 46K-record Data Breach
May22

Massachusetts Mental Health Service Provider Suffers 46K-record Data Breach

Data breaches have recently been announced by Community Counseling of Bristol County in Massachusetts, Community Hospital of Anaconda in Montana, and Radiology Chartered in Wisconsin. Community Counseling of Bristol County, Massachusetts Community Counseling of Bristol County (CCBC), a mental health service provider in Taunton, Massachusetts, has recently announced a data breach that occurred a year ago in May 2024. A security breach was detected on or around May 20, 2025, and the forensic investigation confirmed that an unauthorized third party had access to its network between May 18, 2024, and May 20, 2024. CCBC conducted an extensive review of documents on the compromised parts of its network and that process was completed on April 25, 2025, when it was confirmed that the compromised information included full names, addresses, dates of birth, Social Security numbers, driver’s license or state ID numbers, financial account information, medical information, and health insurance information. Notification letters were mailed to the affected individuals on May 19, 2025, and...

Read More
North Carolina Pathology Laboratory Suffers 235K-Record Data Breach
May22

North Carolina Pathology Laboratory Suffers 235K-Record Data Breach

An anatomic pathology laboratory and healthcare provider in North Carolina have experienced cyberattacks involving the theft of patient data. Marlboro-Chesterfield Pathology, North Carolina Marlboro-Chesterfield Pathology, P.C. (MCP) in Pinehurst, North Carolina, has recently reported a data breach to the HHS’ Office for Civil Rights that involved the theft of the protected health information of 235,911 individuals. The MCP breach notice explains that unauthorized activity was identified within some of its IT systems on or around January 16, 2025. The forensic investigation confirmed there was unauthorized access to files containing patient information, and certain records were copied from its network. A comprehensive review was conducted of the compromised files, and that process was completed on March 31, 2025. The compromised data included names, addresses, dates of birth, medical treatment information, and health insurance information. MCP said, “We took steps, to the best of our ability and knowledge, to ensure that the data taken by the unauthorized party was deleted,” and at...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist