25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Compliance Logo

Covered Entities Can Show Patients They Respect HIPAA Privacy Rights The HIPAA logo is closely associated with respecting patient privacy and patient HIPAA rights. A HIPAA entity can use a HIPAA compliance logo to indicate to patients that their patient rights under HIPAA are respected. There is no official HIPAA logo, so The HIPAA Journal has developed a number of logos that can be used by HIPAA Covered Entities to show patients that they care about patient rights and comply with HIPAA. The objective is to promote HIPAA awareness among patients. Usage rights for the logos are granted without royalty under 2 conditions: Condition 1) the covered entity using the logo has a HIPAA compliance program that includes a full set of compliance policies and HIPAA training for employees Condition 2) there is a link to this article beside or on the logo to ensure that patients are aware of their HIPAA privacy rights: https://www.hipaajournal.com/hipaa-rights/   Click here to download the above logo Click here to download the above logo Click here to download the above logo Click here to...

Read More
15K Patients Potentially Affected by Insider Incident at New York Healthcare Provider
Mar12

15K Patients Potentially Affected by Insider Incident at New York Healthcare Provider

More than 15,000 patients of Stram Center for Integrative Medicine have potentially been affected by an insider incident, SSK Plastic Surgery has disclosed a 2024 cyberattack, and The Grove at Valhalla Rehabilitation and Nursing Center has been affected by a security incident at one of its vendors. Stram Center for Integrative Medicine Stram Center for Integrative Medicine in New York has notified 15,263 individuals about a security incident involving the misuse of a patient’s payment card information by a former employee. The employee was arrested in connection with the card misuse and Stram Center for Integrative Medicine is cooperating with the law enforcement investigation. Since there is a possibility that the employee’s misuse of the payment card was not an isolated incident, a review was conducted to identify all patients whose data could potentially have been accessed by the former employee during their employment. Stram Center for Integrative Medicine said it is unaware of misuse of any other patient’s information and no Social Security numbers were accessed by the...

Read More
Hillcrest Convalescent Center Announces 106K-Record Data Breach
Mar11

Hillcrest Convalescent Center Announces 106K-Record Data Breach

Cyberattacks and data breaches have been announced by Hillcrest Convalescent Center in North Carolina, Bay Cove Human Services in Massachusetts, and SMC Corporation of America in Indiana. The Hillcrest incident involved the data of 106,194 individuals. Hillcrest Convalescent Center Hillcrest Convalescent Center in Durham, North Carolina has notified 106,194 individuals about a data security incident identified on June 27, 2024. Suspicious network activity was detected, and third-party cybersecurity experts were engaged to investigate and determine the nature and scope of the incident. They confirmed that an unauthorized third party had access to the network and acquired data from its systems. The data review was completed on February 13, 2025, and confirmed that names, dates of birth, Social Security numbers, medical information, treatment information, healthcare provider information, and health insurance information had been exposed. At the time of issuing notifications, Hillcrest Convalescent Center was unaware of any misuse of the affected data. The affected individuals have...

Read More
HHS-OIG Fines Two Healthcare Providers for EMTALA Violations
Mar11

HHS-OIG Fines Two Healthcare Providers for EMTALA Violations

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has entered into settlement agreements with two healthcare providers to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA), commonly known as the patient dumping statute. EMTALA requires hospitals to provide emergency care to anyone seeking treatment, regardless of their ability to pay. When a patient presents at a hospital emergency department, they must undergo an appropriate medical screening examination by a qualified medical professional to determine if they have an emergency medical condition, and stabilizing care must be provided. Organizations found to have violated EMTALA can face stiff financial penalties and, potentially, exclusion from federally funded healthcare programs. Baptist Medical Center South (Baptist), in Montgomery, Alabama, was alleged to have failed to provide an appropriate medical screening examination and/or stabilizing treatment on three occasions. The first instance was in October 2020 when a patient was brought in by ambulance after...

Read More
Settlement Agreed to Resolve RIPTA Ransomware Attack Lawsuit
Mar11

Settlement Agreed to Resolve RIPTA Ransomware Attack Lawsuit

A settlement has been agreed to resolve a lawsuit against the Rhode Island Public Transit Authority (RIPTA) and UnitedHealthcare New England (UHC) over a 2021 ransomware attack. The ransomware attack was detected and blocked on August 5, 2021; however, the forensic investigation confirmed that hackers gained access to its network on August 3, 2021, and stole sensitive data including names, dates of birth, Social Security numbers, and health plan ID numbers. RIPTA announced the data breach on December 23, 2021. The personal information of 17,378 current and former state employees was compromised in the attack, plus the protected health information of 5,015 members of its group health plan. The Rhode Island Attorney General received complaints from individuals about the data breach, questioning why their data had been compromised when they had not worked with or had any dealings with RIPTA. An investigation was launched, and it was confirmed that RIPTA’s previous health insurance provider, UnitedHealthcare of New England, had provided RIPTA with files containing the data of non-RIPTA...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist