NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

$13.75M Settlement Agreed to Resolve WebTPA Class Action Data Breach Litigation
Sep15

$13.75M Settlement Agreed to Resolve WebTPA Class Action Data Breach Litigation

WebTPA Employer Services (WebTPA) and the co-defendants in a consolidated class action lawsuit have agreed to a $13,750,000 settlement to resolve claims relating to an April 2024 cyberattack and data breach. WebTPA is a third-party administrator that provides custom health plans for self-funded employer groups, hospital health plans, and administrative outsourcing services. On April 23, 2023, WebTPA identified suspicious network activity, and the investigation confirmed unauthorized access to its network between April 18, 2023, and April 23, 2023, and potentially exfiltrated sensitive data.  The data breach was communicated to its customers on or around March 25, 2024, and individual notification letters were mailed to the affected individuals starting on May 8, 2024, and the HHS’ Office for Civil Rights was informed that the protected health information of 2,518,533 individuals had been exposed and potentially compromised in the incident. WebTPA was named in 13 putative class action lawsuits over the data breach, along with other defendants. Since the lawsuits had overlapping...

Read More
HIPAA Training for Organizations
Sep13

HIPAA Training for Organizations

HIPAA training for organisations is the structured process of educating the workforce on how to protect patient information, follow internal policies, meet HIPAA obligations, and reduce the risk of breaches, complaints, and enforcement actions. Online training is usually the best delivery method because it is consistent, scalable, easy to assign by role, and simple to document for audits. Why Organisations Need a Formal HIPAA Training Program A HIPAA training program turns rules into daily habits that staff can apply when handling patient data, speaking with patients and families, using systems, and responding to incidents. It also helps leadership set expectations and show that privacy and security are part of professional performance, not optional extras. When training is delivered consistently and tracked properly, it supports accountability across departments and locations. Training should be planned rather than improvised. Organisations need a defined curriculum, clear assignment rules, onboarding processes for new hires, refreshers for existing staff, and a reliable method...

Read More
HIPAA Medical Training
Sep12

HIPAA Medical Training

HIPAA medical training is the structured training healthcare organizations use to ensure every workforce member understands how to protect patient privacy, handle PHI and ePHI safely, and follow the policies and procedures that support HIPAA compliance in daily work. What HIPAA Medical Training Covers HIPAA medical training should explain the Privacy Rule, the Security Rule, and the Breach Notification Rule in clear, practical language that connects directly to real workflows. Staff should learn what PHI and ePHI are, how minimum necessary applies in common scenarios, and what to do when something goes wrong. Effective training also sets expectations for professionalism, including conversations in public areas, safe use of email and messaging, and avoiding disclosures through photos or social media. Training should also make reporting simple by explaining how to raise a concern, who to contact, and why early reporting protects patients and the organization. Who Must Receive HIPAA Medical Training All staff must receive HIPAA training because any workforce member can encounter PHI...

Read More
California Radiology Provider Announces 13,000-Record Data Breach
Sep12

California Radiology Provider Announces 13,000-Record Data Breach

Data breaches have been reported by Radiology Associates of San Luis Obispo, North Oaks Health System, The Children’s Center of Hamden, Huron Regional Medical Center, and Franklin Dermatology Group. Pacific Imaging Management (Radiology Associates of San Luis Obispo) Pacific Imaging Management, doing business as Radiology Associates of San Luis Obispo in California, has identified unauthorized access to certain employee email accounts. Suspicious activity was identified within its email environment on March 13, 2025. An investigation was launched, which revealed that certain email accounts were accessed by an unauthorized third party at various times between February 3, 2025, and March 17, 2025. The accounts were reviewed and found to contain the protected health information of 13,158 individuals. The types of data involved vary from individual to individual and are detailed in the individual notification letters that started to be mailed on September 10, 2025. Policies and procedures are being reviewed and enhanced, and the affected individuals have been offered...

Read More
Teamsters Union 25 Health Services & Insurance Plan Hacking Incident Affects 19,000 Members
Sep12

Teamsters Union 25 Health Services & Insurance Plan Hacking Incident Affects 19,000 Members

Teamsters Union 25 Health Services & Insurance Plan, a health and wellness benefits plan for members of Teamsters Union Local 25, a trade union representing truck drivers, warehouse workers, clerical workers, and service and technology employees, identified suspicious activity within its computer network on or around August 1, 2025, potentially indicating unauthorized access. Third-party cybersecurity experts were engaged to investigate the activity and confirmed unauthorized access to the network. Further investigation uncovered evidence that certain data, including Protected Health Information, on the network was accessed and potentially copied without authorization. The data related to members of the Teamsters Union 25 Health Services & Insurance Plan and the Teamsters Union 25 Investment Plan. The review of the affected files was completed on August 18, 2025, and notification letters were mailed to the affected individuals on September 3, 2025. The affected individuals have been offered 12-24 months of complimentary credit monitoring and identity theft protection...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist