25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Hamilton County (TN) & Bigfork Valley Hospital (MN) Announce Data Breaches
Apr07

Hamilton County (TN) & Bigfork Valley Hospital (MN) Announce Data Breaches

Hamilton County in Tennessee has confirmed that a data breach at a business associate involved the protected health information of 14,081 individuals. Bigfork Valley Hospital in Minnesota has confirmed that up to 8,496 individuals were affected by a November 2024 email account breach. Hamilton County, Tennessee Officials at Hamilton County in Tennessee have confirmed that the protected health information of 14,081 individuals has been compromised in a security incident at one of its business associates, the debt collection agency Nationwide Recovery Service. According to the notification letters, Nationwide Recovery Service notified the Hamilton County Government on July 14, 2024, about a cybersecurity incident that was ongoing at the time, and said further information would be provided as the investigation progressed. Seven months later, on February 24, 2025, the Hamilton County Attorney’s Office received a letter providing an update on the incident, confirming that there had been unauthorized access to the Nationwide Recovery Service network between July 5, 2024, and July 11,...

Read More

Protect Healthcare Data from Phishing

The Threat of Phishing Attacks on the Healthcare Industry One of the key areas of online security that every HIPAA-covered entity should make its priority is to protect healthcare data from phishing. Phishing attacks are becoming a greater threat to the healthcare industry than any other attack vector. Recently almost 25,000 patient records were accessed by hackers as the result of a phishing attack on Saint Agnes Heath Care Inc. in Maryland. Phishing attacks on the healthcare industry usually have one of two objectives – to obtain access to PHI or to deliver ransomware. PHI is now a valuable commodity on the black market as it can be used to create false identities, obtain free medical treatment, and commit insurance fraud. Once ransomware has been installed on a healthcare organization´s network, hackers can demand significant ransoms for the encrypted files to be unlocked. The number of phishing attacks on the healthcare industry is increasing, despite organizations providing online security training to employees. Many of the successful attacks are attributable to the...

Read More
HIPAA Compliance for SaaS
Apr04

HIPAA Compliance for SaaS

HIPAA compliance for SaaS consists of ensuring the software product or service complies with all applicable Security Rule standards, and that the product or service includes capabilities that can be configured to support end-user HIPAA compliance.   HIPAA compliance for SaaS is one of the many HIPAA-related topics full of if, buts, and maybes. In this case, the reason for there being so many possible answers to questions about cloud services is because the original Health Insurance Portability and Accountability of 1996 Act was enacted long before cloud services were commercially available. The subsequent HITECH Act of 2009 and the Final Omnibus Rule of 2013 make limited references to any technical specifications, leaving many developers, service providers and hosting companies in the dark about HIPAA compliance for SaaS. However, there are some guidelines and best practices businesses developing, providing or hosting cloud services should adopt. What is HIPAA Compliance for SaaS? In relation to software developers and service providers, HIPAA compliance for SaaS means adherence to...

Read More
Mercer County Joint Township Community Hospital Cyberattack Affects Up to 88,500 Individuals
Apr04

Mercer County Joint Township Community Hospital Cyberattack Affects Up to 88,500 Individuals

Mercer County Joint Township Community Hospital in Coldwater, Ohio, has suffered a significant data breach involving the electronic protected health information of up to 88,541 individuals. According to the substitute breach notice on its website, linked on the home page using the text “For information on data security click here,” the hospital said unauthorized activity was identified on a limited number of devices on its network on or about April 2, 2024. A third-party forensic investigation confirmed that an unauthorized third party had access to certain networked devices between April 2, 2024, and April 3, 2024. Mercer County Joint Township Community Hospital explained that the decision was taken to issue notification letters to all individuals whose protected health information was stored on the network at the time of the incident, “out of an abundance of caution and in an effort to provide notification in the most expedient manner.” The types of information exposed in the incident varied from individual to individual and may have included name in combination with one or...

Read More
Sentara Health Identifies Job Sharing Scam and Potential Unauthorized EMR Access
Apr04

Sentara Health Identifies Job Sharing Scam and Potential Unauthorized EMR Access

Sentara Health, a nonprofit healthcare provider serving Virginia, Northeastern North Carolina, and Florida, has notified 14,898 patients about a potential insider breach involving their electronic medical records. Sentara Health’s Lab Services department hired an individual in December 2024 to process lab requisitions – orders from providers that explain the lab tests that need to be run for patients. The employee was a remote worker, and following a January 2025 virtual meeting with his manager, the manager raised concerns with the privacy team that the individual with whom the manager had been interacting might not have been the person who was initially hired for the position. The employee’s access to Sentara’s systems was immediately terminated pending an investigation, and Sentara later determined that the employee’s activity was consistent with a job-sharing scam. These scams involve an individual obtaining employment at multiple locations and farming out the work to other individuals in exchange for a percentage of the pay. On or around January 28, 2025, Sentara...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist