25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

California Health Insurance Exchange Sent Sensitive User Data to LinkedIn
May19

California Health Insurance Exchange Sent Sensitive User Data to LinkedIn

The California health insurance exchange, Covered California, has been found to be sharing sensitive data with LinkedIn via website trackers, according to an investigation by The Markup. Tracking code is used across the Internet. Website owners add the code to their websites to gain insights into user behavior. The providers of that code are often sent the data the tracking code collects, which may be information about the pages the user visited, how long they spent on each page, and how they navigated the website. In the case of an e-commerce website, that data may include a product that was added to the cart but was not purchased. The user can then be served adverts related to that product as they browse the web. If tracking code is added to a web page that collects sensitive data, that information may also be transmitted to a third party. The Markup conducted a scan of the coveredca.com website, which is used by Californians to shop for health insurance, and identified 60 different trackers between February and March of this year. Out of all of those trackers, the LinkedIn...

Read More
Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients
May19

Unsecured Serviceaide Database Exposed Data of 483,000 Catholic Health Patients

Serviceaide, Inc., a Santa Clara, California-based business associate that offers agentic AI-powered agents for IT and workflow management, has announced a major data breach affecting almost half a million patients of the six-hospital healthcare system, Catholic Health in Buffalo, New York. Serviceaide provides information technology support management services to Catholic Health, which requires access to patients’ electronic protected health information. On November 15, 2024, Serviceaide discovered that certain information within its Catholic Health Elasticsearch database had been exposed online and could be accessed without authentication. Serviceaide launched an investigation, which revealed the database had been exposed online for around six weeks between September 19, 2024, and November 5, 2024. The investigation found no evidence to suggest any of the information in the database had been copied by unauthorized individuals while it was exposed, but it was not possible to rule out the possibility that sensitive data had been copied. The database has been reviewed and found to...

Read More
Tri-City Cardiology Consultants & Northeast Georgia Health System Announce 21K+ Record Data Breaches
May19

Tri-City Cardiology Consultants & Northeast Georgia Health System Announce 21K+ Record Data Breaches

Data breaches have been announced by Tri-City Cardiology Consultants in Arizona, Northeast Georgia Health System, Family Christian Health Center in Illinois, and Primary Health Care in Iowa. Tri-City Cardiology Consultants, Arizona Tri-City Cardiology Consultants, a cardiology medical group based in Phoenix, Arizona, has warned 22,753 patients about an attempted infiltration of its computer network. The security breach was identified on or around April 6, 2025, and immediate action was taken to secure its network and prevent further unauthorized access. While no evidence was found that suggested its network was accessed specifically to obtain patient data, it is possible that an unauthorized third party viewed or obtained names, health insurance information, and protected health information. The types of data involved varied from individual to individual. Tri-City Cardiology Consultants confirmed that Social Security numbers were not compromised in the incident; however, out of an abundance of caution, the affected individuals have been offered complimentary credit monitoring and...

Read More

Will a HIPAA Violation Show Up on a Background Check?

Whether or not a HIPAA violation will show up on a background check depends on the nature of the violation, the consequences of the violation, and the motive for the violation. While it is currently rare for a HIPAA violation to show up on a background check, this may change due to a proposed update to the Privacy Rule. There are many different types of HIPAA violations. Some have minimal impact and no long-lasting consequences – i.e., an accidental disclosure of PHI that is overheard, but nothing comes of it – whereas others can have a major impact on an organization and serious consequences for individuals affected by the violation – i.e., the deliberate misuse of login credential that exposes a PHI database. Most employee HIPAA violations are addressed according to a Covered Entity’s sanctions policy. Employees responsible for minor violations will likely be sanctioned with verbal or written warnings and additional HIPAA training. Those responsible for repeated or serious violations could be sanctioned with a suspension or termination of employment, or loss of license to...

Read More
CardioVascular Health Clinic & Hunter Health Clinic Announce Data Breaches
May16

CardioVascular Health Clinic & Hunter Health Clinic Announce Data Breaches

CardioVascular Health Clinic in Oklahoma is investigating a recent cyberattack and data breach, and Hunter Health Clinic in Kansas has confirmed an email breach involving the information of almost 32,000 patients. CardioVascular Health Clinic, Oklahoma CardioVascular Health Clinic, a healthcare network with more than a dozen facilities in Oklahoma, has recently announced a security incident and data breach at its cloud service provider. The incident was detected on March 4, 2025, when network disruption was experienced. The forensic investigation confirmed that an unauthorized third party had access to its network between February 18, 2025, and March 4, 2025. The investigation and file review are ongoing, and it is not yet possible to determine the specific types of information that have been exposed and potentially stolen; however, it is likely that the affected individuals had some or all of the following types of information exposed in the incident: name, address, phone number, email address, date of birth, Social Security Number, driver’s license/state ID number, financial...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist