25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Verizon Releases Inaugural Breach Impact Study
Jul01

Verizon Releases Inaugural Breach Impact Study

Verizon Business has released the findings from its inaugural Breach Impact Study, which focuses on the financial impact of data breaches. The BIS report is from the same authoring team as the Verizon Data Breach Investigations Report and was produced in partnership with CyberAcuView. The report is based on an analysis of around 70,000 U.S. cyber insurance claims, including 38,000 claims where the policies paid out. The data spans from January 2019 to October 2025. In contrast to many data breach cost reports, the report is based on median claim amounts rather than averages, which are susceptible to skewing. In 2019, the median financial impact was around $60,000, rising by 80% to $110,000 in 2025, with data breach costs outpacing inflation, which was around 23% over the period of the study. More than half of paid-out claims exceeded $83,000, with 10% having an impact of $920,000 or more. The most extreme 2.5% of cases exceeded $5 million in losses. The report shows that data breach costs almost doubled between 2019 and 2025, with business interruption the single largest loss...

Read More
HHS Provides Update on its Artificial Intelligence RFI
Jul01

HHS Provides Update on its Artificial Intelligence RFI

The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has tremendous potential for improving efficiency in healthcare, achieving better patient outcomes, and lowering healthcare costs for Americans; however, there are risks associated with AI implementation in healthcare. The HHS issued a Request for Information (RFI) in December 2025 on how AI tools can be used to deflate healthcare costs, as part of the Make America Healthy Again initiative. HHS Secretary Robert F. Kennedy Jr. sought broad public input on how the HHS could use its regulatory, reimbursement, and research & development levers to enable AI adoption to propel the U.S. healthcare system forward. The HHS sought information on how digital health and software regulatory frameworks should evolve to account for AI-driven tools while maintaining patient safety; whether reimbursement structures could be simplified and better aligned to support the use of efficient, deflationary technologies; and...

Read More
Take the Guesswork out of HIPAA Compliance for Small Practices
Jul01

Take the Guesswork out of HIPAA Compliance for Small Practices

Removing guesswork from HIPAA compliance means replacing assumptions about what a practice has covered with a documented process that maps directly to the requirements of the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. Small practices frequently operate on inherited assumptions: a predecessor set up a policy years ago, a staff member attended a training session at some point, or a binder was purchased and filled out once. None of those assumptions can be verified on demand, and an inability to verify is treated the same as noncompliance during a regulatory review. A defined process removes that ambiguity by producing evidence rather than relying on memory or informal practice. The Uncertainty Small Practices Face Under HIPAA Owners and office managers at small practices commonly cannot answer basic questions about their own compliance status without checking multiple sources or guessing. Common uncertainty includes whether the Security Risk Analysis on file reflects the practice’s current systems, whether every staff member has...

Read More
Security Researcher Identifies Quintet of Bugs in Toolkit Used in DICOM Medical Imaging Software
Jul01

Security Researcher Identifies Quintet of Bugs in Toolkit Used in DICOM Medical Imaging Software

A quintet of vulnerabilities has been identified in a DICOM toolkit – OFFIS DCMTK – that is extensively used in medical imaging software. DICOM (Digital Imaging and Communications in Medicine) is the universal technical standard used to store, transmit, print, and display medical imaging data and is used by virtually all medical imaging devices. Since the toolkit is used in many medical imaging software solutions, the vulnerabilities are significant. Successful exploitation of the vulnerabilities could expose patient information, disrupt DICOM storage or worklist services, exhaust service memory, crash imaging services, or cause DCMTK-based clients to write files outside the intended output directory. The vulnerabilities were identified by independent security researcher Abhinav Agarwal, who reported them to the U.S. Cybersecurity and Infrastructure Agency (CISA) and the vendor in May 2026. Agarwal identified the vulnerabilities using standard subscriptions to Claude and ChatGPT, then manually reviewed and confirmed the findings. One of the vulnerabilities is rated critical with a...

Read More
Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack
Jul01

Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack

Medtronic has started issuing notifications to individuals affected by an April 2026 cyberattack. The ShinyHunters threat group claimed responsibility for the cyberattack and alleges that more than 9 million records containing personally identifiable information (PII) were stolen. Medtronic explained in the notification letters that it learned about the intrusion on April 15, 2026, when suspicious activity was identified within certain corporate IT systems. Assisted by leading third-party cybersecurity experts, Medtronic confirmed unauthorized access to certain IT systems from April 13 to April 19, 2026. The medical devices manufactured by Medtronic collect patient data. The review of that data confirmed that names, contact information, dates of birth, Social Security numbers, and health-related information may have been impacted. At the time of issuing the notification letters, Medtronic said it was unaware of any release of the stolen data on the public Internet. Medtronic confirmed that it takes privacy and security seriously and had implemented many safeguards to protect its...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist