25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Key Systems Restored After Masimo Cyberattack
May28

Key Systems Restored After Masimo Cyberattack

Masimo has confirmed that it has made good progress recovering from the cyberattack it disclosed earlier this month. In its May 6, 2025, filing with the SEC, Masimo explained that the cyberattack had affected some of its manufacturing facilities, and was affecting its ability to process and fulfil orders; however, Masimo has now confirmed that its manufacturing facilities are working at near full capacity and its order taking and distribution and shipping systems are fully operational. The cyberattack did result in some delays to customers’ orders; however, by optimizing its systems, Masimo has ensured that all delayed orders are processed in a timely manner, and the company does not anticipate the incident harming its ability to meet existing orders and seasonal demand. Masimo holds a cyber insurance policy and expects it to cover the majority of the out-of-pocket costs incurred remediating the cyberattack, and does not believe the cyberattack will have any material impact on its fiscal 2025 revenue, which is expected to remain in the range of $1.5 billion to $1.53 billion....

Read More
Typical Roles within a Hospital Emergency Management Team
May27

Typical Roles within a Hospital Emergency Management Team

The roles within a hospital emergency management team can be much more extensive than emergency management roles in a non-medical organization. This is due to hospitals often having to respond to the needs of the community after an emergency in addition to managing its own environment. According to the Federal Emergency Management Agency (FEMA), most non-governmental organizations base their emergency management team structure on ICS-100 – an Incident Command System in which an Incident Commander is supported by Section Leaders from Operations, Planning, Logistics, and Finance/Admin, who each have support teams beneath them. Larger organizations and government agencies are more likely to adopt the military-style ICS-300 model for expanding incidents. In this model the Incident Commander has a small team reporting directly to him or her in addition to the Section Leaders. The roles beneath the Section Leader level are clearly defined and each role can be the responsibility of an individual or a department. HIPAA Training for Emergency Staff Staff need to understand how HIPAA...

Read More
Nationwide Recovery Service Data Breach Victim List Grows: 560,000+ Individuals Affected
May27

Nationwide Recovery Service Data Breach Victim List Grows: 560,000+ Individuals Affected

The list of victims from the data breach at the debt collection agency Nationwide Recovery Service (NRS) is steadily growing, with a further six NRS clients confirming that sensitive information was stolen in the attack: The City of Chattanooga, MAK Anesthesia, Duncan Regional Hospital, Swedish Edmonds Hospital, Smile Solutions of Goodlettsville, and UCM Medical Group. Currently, at least 560,067 individuals are known to have been affected, and several affected companies have yet to confirm breach numbers, including NRS. HIPAA-regulated entities that have previously confirmed that they were affected include Harbin Clinic, Northeast Georgia Health System, Rhea Medical Center, Chartered Radiology, Erlanger Western Carolina Hospital, and Vitruvian Health, with the latter affecting Hamilton Health Care System and its affiliates Hamilton Emergency Medical Services, Hamilton Physician Group, Hamilton Medical Center, and Anna Shaw Children’s Institute. NRS is used by many HIPAA-regulated entities to recover funds from delinquent accounts, as well as for issues related to...

Read More
Planned Parenthood Patients File Lawsuits Over Laboratory Services Cooperative Data Breach
May27

Planned Parenthood Patients File Lawsuits Over Laboratory Services Cooperative Data Breach

Planned Parenthood patients are taking legal action over the theft of their sensitive data from Laboratory Services Cooperative (LSC), a Seattle, WA-based diagnostic testing service provider used by Planned Parenthood centers in 30 states and the District of Columbia. On October 27, 2024, LSC identified unauthorized activity within its computer network. The forensic investigation confirmed in February 2025 that an unauthorized third party had accessed its network and obtained files that contained sensitive patient data, including names, contact information, dates of birth, medical and clinical information, health insurance information, billing and claims information, payment card information and banking information, Social Security numbers, driver’s license numbers, passport numbers, and other highly sensitive information. Workers were also affected by the breach and may have had dependent or beneficiary information stolen in the attack. In total, approximately 1.6 million individuals were affected by the data breach and were notified in April 2025. Complimentary credit monitoring...

Read More
$4.4 Million Settlement Agreed to Resolve WellNow Urgent Care Data Breach Litigation
May26

$4.4 Million Settlement Agreed to Resolve WellNow Urgent Care Data Breach Litigation

WellNow Urgent Care (formerly Five Star Urgent Care), a network of walk-in urgent care clinics in New York, Illinois, Michigan, and Ohio, has agreed to settle a class action data breach lawsuit for $4.4 million. The lawsuit was filed in response to a cyberattack and data breach detected on or around April 25, 2023, when ransomware was used to encrypt files. The ransomware group obtained names, dates of birth, Social Security numbers, state ID/driver’s license information, health and insurance information, banking information, and biometric data. The data breach also affected WellNow Urgent Care’s parent company, ADMI Corp., which does business as TAG – The Aspen Group, and Aspen Dental, Aspen Dental Management, Physicians Immediate Care, and Physicians Immediate Care Chicago. In total, the protected health information of approximately 597,000 individuals was compromised in the attack. The affected individuals started to be notified about the data breach in February 2024. In March 2024, lawsuits were filed in response to the data breach in the United States District Court for...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist