25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

BakerHostetler: Ransomware in Decline with Fewer Attacks and Lower Payments
Apr16

BakerHostetler: Ransomware in Decline with Fewer Attacks and Lower Payments

Healthcare continues to be the sector most targeted by ransomware groups, according to the BakerHostetler 2025 Data Security Incident Response Report. Out of the ransomware incidents the law firm was involved with last year, 36% were on healthcare organizations, and those attacks typically disrupted patient care and resulted in revenue loss. There are signs, however, that ransomware is in decline, with fewer attacks and lower payments last year. BakerHostetler has identified an increase in fraudulent wire transfers, suggesting threat actors are responding to the falling profitability of ransomware attacks by making money in other ways. Fraudulent transfers increased by 302% year over year, with an average transfer of $1,256,797 and a median transfer of $130,000. While that may have been true for 2024, reports published earlier this month by cybersecurity firms suggest ransomware groups are conducting more attacks due to the increased reluctance of victims to pay ransoms. Several firms reported that Q1 2025 was a record-breaking quarter for ransomware attacks. In 2024, based on the...

Read More
Retina Group of Washington Agrees to $3.6 Million Settlement to Resolve Data Breach Lawsuit
Apr16

Retina Group of Washington Agrees to $3.6 Million Settlement to Resolve Data Breach Lawsuit

A settlement has been agreed to resolve a class action lawsuit against Retina Group of Washington over a March 2023 data breach that involved unauthorized access to the protected health information of 455,935 individuals. Under the terms of the settlement, a $3.6 million fund will be created to cover claims, attorneys’ fees, and legal costs and expenses. On December 22, 2023, Retina Group of Washington, a healthcare provider with eye care clinics in Maryland and Virginia, issued notifications about a ransomware attack on March 26, 2023. The hackers encrypted files and stole data such as names, addresses, telephone numbers, email addresses, dates of birth, demographic information, Social Security numbers, driver’s license numbers, medical record numbers, health information, payment information, and health insurance information. Seven lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit – In re: Retina Group of Washington Data Security Incident Litigation – in the United States District Court for the District of Maryland. The...

Read More
Medical Express Ambulance Service Data Breach Affects 118K Individuals
Apr16

Medical Express Ambulance Service Data Breach Affects 118K Individuals

Medical Express Ambulance Service has announced a March 2024 data breach that has affected more than 118,000 individuals. Data breaches have also been announced by Vitenas Cosmetic Surgery, Newport Harbor Pathology Medical Group, Rhea Medical Center, and Alabama Ophthalmology Associates. Medical Express Ambulance Service Medical Express Ambulance Service in Skokie, Illinois, has recently issued notification letters to individuals affected by a cybersecurity incident that was detected more than a year ago. While not specifically mentioned, the language used indicates this was a ransomware attack. The security breach was identified on March 18, 2024, when network disruption was experienced that affected the functionality of certain systems. Third party cybersecurity experts were engaged to investigate and confirmed that the threat actor had access to systems where patient data was stored and could therefore have acquired patient information. Legal counsel for Medical Express confirmed that the data mining process was completed on January 30, 2025, and a mailing vendor was engaged on...

Read More
Ransomware Attack Announced by True Dental Care for Kids and Adults
Apr15

Ransomware Attack Announced by True Dental Care for Kids and Adults

Data breaches have recently been announced by True Dental Care for Kids and Adults in Pennsylvania, North Hudson Community Action Corporation in New Jersey, and California Correctional Health Care Services. True Dental Care for Kids and Adults, Pennsylvania True Dental Care for Kids and Adults LLC in Pennsylvania has started notifying 17,640 individuals about a recent ransomware attack. A hacker gained access to its network on February 3, 2025, and downloaded ransomware, which was used to encrypt files on its network. The forensic investigation of the incident identified unauthorized access to patient data prior to file encryption. A ransom demand was issued; however, it was not paid, and files were successfully restored from backups. True Dental said it is unaware of any misuse of patient data at the time of issuing the notification. The types of information involved vary from individual to individual and include names, dates of birth, addresses, phone numbers, and patient dental/medical records. True Dental said additional safeguards are being implemented to prevent similar...

Read More
HIPAA Compliance Tools
Apr15

HIPAA Compliance Tools

HIPAA compliance tools are used as part of the HIPAA compliance process, for example, forms and notices, and to measure HIPAA compliance, for example, assessment tools or checklists that guide covered entities and business associates through the basics of HIPAA compliance. The HIPAA Journal has a number of free resources that help HIPAA-Covered Entities with their HIPAA compliance. HIPAA Business Associate Agreement Template This downloadable template provides a reference for what should be contained in a HIPAA Business Associate Agreement. Click to Download HIPAA Business Associate Agreement Template (Word document, 18K) HIPAA Release Form Releasing medical records without a HIPAA authorization form is a HIPAA violation. Click here for HIPAA release form (free PDF document – Opens directly in the browser) Two US states have their own forms Click here for California HIPAA release form Click here for Texas HIPAA release form HIPAA Notice of Privacy Practices HHS’ Office for Civil Rights has produced a Notice of Privacy Practices template that is free to download. Instructions...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist