NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Modernizing Medicine Agrees to $3M Data Breach Settlement
Sep17

Modernizing Medicine Agrees to $3M Data Breach Settlement

Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers, has agreed to pay almost $3 million to settle class action data breach litigation. The litigation stems from a July 2025 cybersecurity incident in which a criminal hacker gained access to two of its computer servers between July 9, 2025, and July 10, 2025. The servers were used for the conversion of data from retiring EHR platforms to the current Modernizing Medicine EHR platform. Data compromised in the incident included names, addresses, dates of birth, phone numbers, email addresses, limited Social Security numbers, health insurance information, and medical information. The affected individuals were notified on or around October 17, 2025. The HHS Office for Civil Rights was informed that 198,795 individuals had been affected. A class action lawsuit – Cavallaro-Kearins v. Modernizing Medicine, Inc. – was filed on November 19, 2025, in the U.S. District Court for the Southern District of Florida by...

Read More
Brevard Skin and Cancer Center Settles Class Action Complaint
Sep17

Brevard Skin and Cancer Center Settles Class Action Complaint

The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming from a 2025 cyberattack and data breach. Unauthorized activity was identified within its network on October 14, 2025. The forensic investigation confirmed unauthorized network access starting on September 28, 2025, and the exposure of patient data including names, phone numbers, e-mail addresses, dates of birth, Social Security numbers, diagnoses, clinical information, and billing and claims information. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 54,570 individuals. A threat group called PEAR claimed responsibility for the attack and threatened to publish the data unless a ransom was paid. The first class action lawsuit was filed on October 20, 2025, and similar class action lawsuits were filed by other individuals affected by the data breach. The lawsuits were consolidated into a single action as they had overlapping claims and classes. The consolidated lawsuit – In Re:...

Read More
Hacking Group Claims Attack on Cedar County Memorial Hospital
Sep17

Hacking Group Claims Attack on Cedar County Memorial Hospital

A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia. Cedar County Memorial Hospital Cedar County Memorial Hospital in El Dorado Springs, Missouri, disclosed on August 23, 2026, that it was the victim of a cyberattack that disrupted its IT systems. The affected computer systems were taken offline, and network access was paused to ensure the integrity of hospital systems. The measures taken to contain the attack and protect its systems resulted in an outage of its patient portal and electronic health record system, and the latter affected all hospital and Medical Mall Clinic services. To ensure patient safety, the emergency department was placed on partial diversion since medical imaging systems were unable to transmit medical images to radiologists. An update was issued by Cedar County Memorial Hospital on August 28, 2026, confirming that the hospital had returned to routine operations after...

Read More
House Subcommittee on Health Examines Healthcare Cybersecurity Proposals
Sep16

House Subcommittee on Health Examines Healthcare Cybersecurity Proposals

On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare cybersecurity, reform Medicare provider payments, and other healthcare matters. At the hearing, titled Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity, the subcommittee discussed two bills that seek to improve healthcare cybersecurity – the Rural Hospital Cybersecurity Enhancement Act and the Healthcare Cybersecurity and Resiliency Act of 2026. Healthcare data breaches have increased significantly in recent years. For the past five years, more than 700 data breaches affecting 500 or more individuals have been reported to the HHS’ Office for Civil Rights (OCR), and a new record was set in 2025, with 804 large data breaches currently listed on the OCR data breach portal. As of August 30, 2026, 496 large data breaches have been reported to OCR, indicating that 2026 will be another 700+ data breach year. So far this year, more than 74.6 million individuals have had...

Read More
xHealth Data Breach Affects 118,000 Individuals
Sep16

xHealth Data Breach Affects 118,000 Individuals

A data breach at zHealth, a practice management and EHR software provider, has affected 118,000 individuals. Data breaches have also been announced by Bridgeway Benefit Technologies, Longview ER Operations, and HealthStream. zHealth zHealth, Inc., a San Francisco, California-based cloud-based practice management and electronic health records (EHR) software provider, has disclosed a cybersecurity incident that may have involved data being acquired by an unauthorized third party. According to the breach notice provided to the California Attorney General, zHealth became aware that certain information may have been copied on or around June 15, 2026. An investigation was launched, which confirmed that its network had been accessed by an unauthorized third party between January 20 and January 21, 2026. The review of the impacted data was completed on September 3, 2026. The substitute breach notice on the zHealth website states that the impacted information varies from individual to individual and may include names, medical information, and health insurance information. The affected...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist