25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cal/OSHA Seeks Comment Workplace Violence Prevention Regulation Discussion Draft
Jun02

Cal/OSHA Seeks Comment Workplace Violence Prevention Regulation Discussion Draft

Cal/OSHA is working on an update to the 2023 legislation that introduced a new requirement for employers in California to develop and implement a workplace violence prevention plan. Senate Bill 553, Workplace Violence Prevention in General Industry, was signed into law on September 30, 2023, and took effect on July 1, 2024. The legislation requires employers to develop, implement, and maintain a Workplace Violence Prevention Plan, the main components of which are: Prohibiting employee retaliation Accepting and responding to reports of workplace violence Providing employee workplace violence training and communication Emergency response procedures Conducting workplace violence hazard assessments Maintaining a Violent Incident Log The legislation was introduced in response to an increase in workplace violence, which across the United States, affects almost 2 million workers each year. In 2021, in California alone, there were 57 employee deaths from workplace violence.  A summary of the current requirements has been published in a Cal/OSHA fact sheet. The legislation required Cal/OSHA...

Read More
House/Senate Bills Seek to Expand OSH Act to Cover Public Sector Workers
Jun02

House/Senate Bills Seek to Expand OSH Act to Cover Public Sector Workers

Senator Ed Markey (D-MA), for himself and on behalf of Sens. Chuck Schumer (D-NY), Bernie Sanders (I-VT), Ben Ray Luján (D-NM), Ron Wyden (D-OR), Chris Van Hollen (D-MD), Alex Padilla (D-CA), Richard Blumenthal (D-CT), Tammy Baldwin (D-WI), and Adam Schiff (D-CA) has recently introduced the Public Service Worker Protection Act, which seeks to expand the Occupational Safety and Health (OSH) Act to extend protections to public employees at the federal, state, and local levels. The OSH Act was introduced in 1970 and requires employers to maintain safe and healthful working conditions by requiring employees to be provided with a working environment free from recognized hazards that are likely to cause serious injury or death. Under the OSH Act, employers must comply with occupational safety and health standards promulgated under the OSH Act. The OSH Act also established the Occupational Safety and Health Administration (OSHA) within the U.S. Department of Labor to enforce OSH Act compliance. The OSH Act applies to most private sector employers and employees in the United States, but...

Read More
What is the Maximum Penalty for Violating HIPAA?
Jun02

What is the Maximum Penalty for Violating HIPAA?

The maximum penalty for violating HIPAA is currently $71,162 (June 2025) for a violation that is attributable to willful neglect and that, despite being alerted to the violation by HHS’ Office for Civil Rights, is not corrected within 30 days. However, this figure represents the maximum penalty per violation type. It is often the case that data breaches are attributable to more than one HIPAA violation  When Congress passed HIPAA in 1996, it set the maximum penalty for violating HIPAA at $100 per violation with an annual cap of $25,000. These limits were applied when the Department of Health & Human Services (HHS) published the Enforcement Rule in 2006 and they stayed in force until the publication of the Final Omnibus Rule in 2013. Among other changes to HIPAA, the Final Omnibus Rule introduced amendments to the Enforcement Rule attributable to passage of the HITECH Act in 2009. The HITECH Act mandated a four tier penalty structure for HIPAA violations and new minimum and maximum penalties for violating HIPAA. The four tiers were based on the level of culpability...

Read More
U.S. Dermatology Partners Announce June 2024 Cyberattack & Data Breach
Jun02

U.S. Dermatology Partners Announce June 2024 Cyberattack & Data Breach

Data breaches have recently been announced by U.S. Dermatology Partners in Texas, the Smith Institute for Urology in New York, Shore Medical Center in New Jersey, Connections for Kids in Maine, and the Missouri Department of Conservation. U.S. Dermatology Partners, Texas U.S. Dermatology Partners (USDP), a network of more than 100 dermatology practices in Arizona, Colorado, Kansas, Maryland, Missouri, Oklahoma, Texas, and Virginia, has recently announced a June 2024 cyberattack and data breach. USDP experienced network disruption on June 19, 2024, indicative of a cyberattack. Assisted by third-party digital forensics experts, USDP confirmed that there had been unauthorized access to its network on June 19, 2024, and files were exfiltrated to “an external destination”. A comprehensive review of those files was completed on April 2, 2025, when it was confirmed that the stolen data included names, dates of birth, medical record numbers, health insurance information, and other information related to the dermatology services received at one of its managed practices. A...

Read More
Serviceaide Facing Multiple Class Action Lawsuits Over 483K-Record Data Breach
May31

Serviceaide Facing Multiple Class Action Lawsuits Over 483K-Record Data Breach

A California company that provides an agentic AI-powered software solution for streamlining healthcare operations and improving operational efficiency has recently disclosed a major data breach involving the personal and protected health information of almost half a million patients of Catholic Health in Buffalo, New York. The HIPAA Journal reported on the breach on May 19, 2025, the same day six class action lawsuits were filed in federal court in California over the data breach. More lawsuits are expected to be filed in the coming days. The data breach was discovered on November 15, 2024, when an unsecured Elasticsearch database was identified that had been exposed online for more than 6 weeks between September 19, 2024, and November 5, 2024. The database contained the data of approximately 483,000 Catholic Health patients, including names, dates of birth, Social Security numbers, medical/health information, treatment information, health insurance information, and email/usernames and accompanying passwords. The affected individuals started to be notified about the data breach on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist