25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OSHA Proposes Removal of COVID-19 Emergency Temporary Standard
Jul02

OSHA Proposes Removal of COVID-19 Emergency Temporary Standard

On June 30, 2025, the Occupational Safety and Health Administration (OSHA) published a proposed rule in the Federal Register (90 FR 28336) to remove the remaining parts of its COVID-19 Emergency Temporary Standard that are still in effect. The COVID-19 Emergency Temporary Standard was issued on June 21, 2021, to protect workers in healthcare settings from exposure to the SARS-CoV-2 virus, which causes COVID-19. When the Emergency Temporary Standard was issued, COVID-19 presented a grave danger to healthcare and healthcare support workers, and the Emergency Temporary Standard was necessary to protect those workers. That same month, OSHA also promulgated COVID-19 recordkeeping and reporting provisions under the OSH Act. Employers were required to establish, maintain, and provide copies of a COVID-19 log of all COVID-19 infections and fatalities, regardless of how much time passed between the work-related exposure and an employer learning about COVID-19-related hospitalizations or fatalities. Covered healthcare employers were also required to report any staff hospitalizations and...

Read More
HHS; DHS Sued by 20 States for Alleged Illegal Medicaid Data Disclosure
Jul02

HHS; DHS Sued by 20 States for Alleged Illegal Medicaid Data Disclosure

A coalition of 20 state Attorneys General are suing the Department of Health and Human Services (HHS), Department of Homeland Security (DHS), HHS Secretary Robert F. Kennedy Jr., and DHS Secretary Kristi Noem over the alleged illegal disclosure of the Medicaid data of millions of individuals to deportation officials at the DHS. The Medicaid program was established in 1965 by the Medicaid Act to provide health insurance to lower-income individuals and underserved population groups, including children, seniors, pregnant women, and individuals with disabilities. States are permitted to develop and administer their own unique health plans and set their own eligibility standards and coverage, provided that they meet federal statutory criteria. Currently, more than 78 million Americans are enrolled in Medicaid and the Children’s Health Insurance Program (CHIP) across the United States. Last month, the Associated Press (AP) reported that the Trump administration had disclosed the personal data of millions of Medicaid recipients to the DHS, which houses the federal law enforcement agency,...

Read More
Kelly Benefits Data Breach Update: More Than 553,000 Individuals Affected
Jul02

Kelly Benefits Data Breach Update: More Than 553,000 Individuals Affected

Kelly Benefits has confirmed that a further 140,628 individuals have been affected by its December 2024 cyberattack than previously reported. Hackers gained access to the Kelly Benefits network between December 12, 2024, and December 17, 2024, and exfiltrated files containing sensitive data, including names, dates of birth, Social Security numbers, health insurance information, financial account information, and medical information. Notification letters have been issued on a rolling basis to the affected individuals, and the breach had previously been reported to the Maine Attorney General as affecting 413,032 individuals. The incident response and investigation were complex as so many of its clients were affected. Kelly Benefits said it reviewed its internal records to match the affected individuals to the appropriate client or carrier, and completed that process on March 3, 2025.  According to the Kelly Benefits website, 45 of its clients were affected by the data breach. The Maine Attorney General has been informed that 553,660 individuals had their protected health information...

Read More
CMS Notifies 103,000 Medicare Beneficiaries About Unauthorized Account Creation
Jul01

CMS Notifies 103,000 Medicare Beneficiaries About Unauthorized Account Creation

Approximately 103,000 Medicare beneficiaries are being notified that some of their personal information may have been exposed in a data incident. The HHS Centers for Medicare and Medicaid Services (CMS) was recently alerted that Medicare.gov accounts had been created in individuals’ names without their knowledge. An investigation was launched, which confirmed that a currently unknown threat actor had been using personal information obtained from unknown external sources to fraudulently create Medicare.gov accounts. The CMS said its Medicare call center started receiving calls on May 2, 2025, from beneficiaries who had been sent a letter confirming that an account had been created in their name, when they had not personally created the account. An investigation was launched, which revealed malicious actors had fraudulently created Medicare.gov accounts for approximately 103,000 beneficiaries using valid beneficiary information such as their Medicare beneficiary identifier (MBI), coverage start date, birth date, and zip code. The accounts were fraudulently created between 2023 and...

Read More
Esse Health Confirms Almost 264,000 Individuals Affected by April 2025 Cyberattack
Jul01

Esse Health Confirms Almost 264,000 Individuals Affected by April 2025 Cyberattack

Esse Health has confirmed that 263,601 individuals have been affected by its April 2025 cyberattack. Data breaches have also been announced by Health Care and Rehabilitation Services of Southeastern Vermont, Harbor in Ohio, and Mosaic Life Care in Missouri. Esse Health, Missouri Esse Health, an independent physician group healthcare provider with 50 locations in the Greater St. Louis area in Missouri, has recently notified the Maine Attorney General about an April 2025 cyberattack and data breach involving unauthorized access to the personal information of 263,601* individuals, although the breach report submitted to the HHS’ Office for Civil Rights suggests that the total only includes the protected health information of 23,671 patients. Esse Health had previously publicly announced the cyberattack, which prevented access to its electronic medical record system, resulting in appointments being cancelled. At the time of the announcement, the investigation and file review were ongoing, so it was unclear how many individuals had been affected. Esse Health has confirmed that the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist