25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cyberattack Forces North Carolina Radiology Practice to Close for More Than a Month
Mar19

Cyberattack Forces North Carolina Radiology Practice to Close for More Than a Month

Pinehurst Radiology Consultants has been closed for more than a month following a January cyberattack. Security incidents and data breaches have been reported by Baylor Scott & White Texas Spine & Joint Hospital and Atlas Healthcare CT. Pinehurst Radiology Consultants, North Carolina Pinehurst Radiology Consultants, a small radiology provider serving residents in the Sandhills region of North Carolina, fell victim to a cyberattack in January that disrupted its computer systems, forcing the practice to temporarily close. The practice remains closed more than a month after the attack. The recorded message on its voicemail system states that the practice will remain closed for the foreseeable future. Work is ongoing to restore its computer systems and while progress has been made, its scheduling system has yet to be restored and patients are unable to schedule mammography or ultrasound services. Patients requiring PET or MRI scans have been advised to visit the affiliated First Imaging, part of FirstHealth of Carolinas for those imaging services. Pinehurst Radiology said...

Read More
Cyberattack on Michigan Plastic Surgery Practice Affects Almost 20,000 Patients
Mar19

Cyberattack on Michigan Plastic Surgery Practice Affects Almost 20,000 Patients

Data breaches have been announced by the Hand & Plastic Surgery Centre in Michigan, Dove Healthcare in Wisconsin, and Southeast Series of Lockton Companies in Georgia. Hand & Plastic Surgery Centre, Michigan The Hand & Plastic Surgery Centre, PLC, which does business as Elite Plastic Surgery, has reported a data breach to the HHS’ Office for Civil Rights that affects 19,846 individuals. The Michigan-based aesthetic surgery provider detected unauthorized third-party access to its computer network on January 29, 2025. Independent IT security and digital forensics specialists were engaged to investigate and determine the nature and scope of the unauthorized activity. While no evidence was found to indicate any individual’s information was specifically accessed for misuse, it is possible that personal and protected health information was viewed or stolen. The exposed data included names, birth dates, Social Security numbers, and health insurance information. At the time of issuing notification letters on March 7, 2025, the Hand & Plastic Surgery Centre was unaware of...

Read More
Email Account Breaches Reported by Access TeleCare & Madison County, MS
Mar19

Email Account Breaches Reported by Access TeleCare & Madison County, MS

Access TeleCare in Texas and Madison County, Mississippi have reported breaches of employee email accounts, and the California Department of Child Support Services has discovered an employee emailed sensitive data to a personal email account. Access TeleCare, Texas The Dallas, TX-based acute and specialty telemedicine provider Access TeleCare identified unauthorized access to an employee’s email account on January 8, 2024. An investigation was launched which revealed an unauthorized third party had access to the email account for 2 months since November 6, 2023, and other email accounts may also have been accessed. During the two months, it is possible that emails and attachments were downloaded from the account. A data review vendor was engaged, and Access TeleCare was provided with the final results of the review on August 30, 2024; however, it took until March 4, 2025, for individual notifications to be mailed. Access TeleCare said the four-and-a-half-month delay from receiving the final results to issuing notification letters was due to the time-intensive process of reviewing...

Read More
The Biggest Healthcare Data Breaches of 2024
Mar19

The Biggest Healthcare Data Breaches of 2024

Last year was an annus horribilis for healthcare data breaches. While there appears to have been a slight year-over-year reduction in the number of reported data breaches of 500 or more records, the number of individuals affected by those breaches has risen considerably. As of March 19, 2025, 734 large data breaches have been reported to OCR, a percentage decrease of 1.74% from the 747 large healthcare data breaches reported in 2023. While a reduction in healthcare data breaches is a step in the right direction, 2024 was the worst-ever year in terms of breached healthcare records, which jumped by 64.1% from last year’s record-breaking total to 276,775,457 breached records, or 81.38% of the 2024 population of the United States. Those figures will surely grow over the coming weeks and months as more data breaches are expected to be added to OCR’s breach portal for December, and 64 data breaches in 2024 have been reported using potential placeholder estimates of 500 or 501 breached records. These figures are commonly used when the file review has not been completed by the breach...

Read More

What is Required for HIPAA Compliance?

What is required for HIPAA compliance is for covered entities and business associates to comply with all applicable standards and implementation specifications of the HIPAA Administrative Simplification Regulations in order to protect the privacy and security of individually identifiable health information. Due to the complexity of the HIPAA Administrative Simplification Regulations, misunderstandings can sometimes exist about what HIPAA is, who it applies to, what is protected by HIPAA, and who is responsible for HIPAA compliance. These misunderstandings can make it difficult to determine what is required for HIPAA compliance. What is HIPAA? HIPAA stands for the Health Insurance Portability and Accountability Act – an Act passed in 1996 with the purpose of reforming the health insurance industry. Due to the cost of the reforms, a second Title was added to the Act which aimed to counter the cost by reducing fraud in the healthcare industry and simplifying the administration of healthcare transactions. The Administrative Simplification Regulations are what most people refer to when...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist