25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

MedStar Health Agrees to $1.35 Million Settlement to Resolve Class Action Data Breach Litigation
Jul24

MedStar Health Agrees to $1.35 Million Settlement to Resolve Class Action Data Breach Litigation

MedStar Health has agreed to settle class action litigation stemming from a 2023 data breach that affected more than 183,000 individuals. MedStar Health will create a $1.35 million settlement fund to cover attorneys’ fees, legal costs and expenses, and claims from class members for reimbursement of out-of-pocket expenses fairly traceable to the data breach. MedStar Health, the largest healthcare provider in Maryland and Washington, D.C., provides medical services through 120 entities, including 10 hospitals. Between January 25, 2023, and October 18, 2023, an unauthorized third party gained access to the email accounts of three employees and accessed or obtained the protected health information of 183,079 patients. The individuals were notified about the data breach on May 4, 2024. Shortly after mailing notification letters, a class action lawsuit was filed by Gwendolyn Riddick individually and on behalf of similarly situated individuals. A further five class action lawsuits were filed by other MedStar Health patients. Since all six lawsuits were materially and substantively...

Read More
The Harris Poll Survey Reveals Growing Concern About Workplace Safety in Healthcare
Jul24

The Harris Poll Survey Reveals Growing Concern About Workplace Safety in Healthcare

A recent survey by The Harris Poll has revealed that three out of five (59%) healthcare workers are concerned about safety in the workplace, and almost two out of five healthcare workers have considered leaving their employment due to safety concerns as incidents of violence in the workplace increase. The survey was conducted between April 21 and May 7, 2025, on 1,027 U.S. healthcare workers who frequently interact with patients or their families.  The biggest concerns among healthcare workers were verbal harassment from patients (81%), aggressive behavior/threats from patients (77%), verbal harassment from non-patients (62%), and aggressive behavior/threats from non-patients (59%). More than one-fifth (21%) of healthcare workers said they worry about verbal harassment most of the time or every time they go to work. These concerns are far from unfounded. Data from the U.S Bureau of Labor Statistics shows healthcare workers are five times more likely to experience violence in the workplace than workers in other industries, and multiple surveys suggest workplace violence is on the...

Read More
HHS-OIG Imposes Penalties on Skilled Nursing Facilities for Employing Excluded Individuals
Jul24

HHS-OIG Imposes Penalties on Skilled Nursing Facilities for Employing Excluded Individuals

The U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) has recently announced enforcement actions against entities alleged to have employed excluded individuals who provided items or services that were billed to federal healthcare programs. On May 29, 2025, HHS-OIG announced a $1,565,374.11 settlement agreement with 19 skilled nursing facilities to resolve allegations that they knew or should have known that they employed individuals who were excluded from federal healthcare programs. Sundance Creek Post Acute, California Escondido Post Acute, California Jurupa Hills Post Acute, California Crystal Cove Care Center, California Redwood Cove Healthcare Center, California Huntington Valley Healthcare Center, California Houston Transitional Care, Texas Napa Post Acute, California Norwood Towers Post Acute, Ohio Sunnyvale Post Acute Center, California Stoney Point Healthcare, California Trellis Centennial, Nevada San Diego Post Acute, California Mirage Post Acute, California Crystal Ridge Care Center, California Aviara Healthcare, California Concord Post...

Read More
Cumberland County Hospital Data Breach Affects Almost 37,000 Individuals
Jul24

Cumberland County Hospital Data Breach Affects Almost 37,000 Individuals

While compiling data for last month’s data breach report, the HIPAA Journal identified a data breach that had previously been missed. On June 2, 2025, Cumberland County Hospital Association in Kentucky notified the HHS’ Office for Civil Rights about a hacking-related data breach that affected 36,659 individuals. Cumberland County Hospital detected the hacking incident on April 3, 2025. According to its substitute breach notice, an unauthorized third party had access to its network between February 21, 2025, and April 3, 2025. While its electronic medical record system was not accessed, files on the compromised parts of the network were discovered to include patient information, and some of those files were accessed during the attack. The review of the files confirmed they contained demographic information (name, date of birth, address, phone number(s), email address, race, and ethnicity), along with Social Security numbers, medications, diagnoses, treatment notes, dates of service, medical record numbers, health plan numbers, and claims and billing information. Some employee...

Read More
New York Surgery Center Pays $250K to Settle HIPAA Risk Analysis; Breach Notification Violations
Jul24

New York Surgery Center Pays $250K to Settle HIPAA Risk Analysis; Breach Notification Violations

Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Director, Paula M. Stannard, has announced OCR’s 18th HIPAA penalty of the year.  Syracuse ASC, which does business as Specialty Surgery Center of Central New York, a single-facility ambulatory surgery center in Liverpool, New York, has agreed to settle alleged violations of the HIPAA Security Rule and HIPAA Breach Notification Rule and will pay a $250,000 financial penalty. OCR launched an investigation of Syracuse ASC after receiving a data breach notification report on October 14, 2021, about a hacking incident involving unauthorized access to the protected health information of 24,891 current and former patients. A threat actor had access to its network from March 14, 2021, through March 31, 2021, and potentially obtained names, dates of birth, Social Security numbers, financial information, and clinical treatment information. OCR investigation confirmed that this was a ransomware attack involving PYSA ransomware. OCR’s investigation uncovered no evidence to suggest that Syracuse ASC had ever conducted...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist