NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS-OIG Audit Uncovers Fraud Control Failures Within HHS Grant Payment System
Jun18

HHS-OIG Audit Uncovers Fraud Control Failures Within HHS Grant Payment System

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has recently published the findings of an audit of the HHS’s Program Support Center (PSC) grant payment system. The audit sought to establish whether effective internal controls, policies, and procedures had been implemented for preventing fraudulent transactions, and was conducted in response to $7.8 million in grant funds being fraudulently transferred to criminals’ bank accounts between March 2023 and January 2024. The fraudulent activity related to ten grants awarded to seven HHS recipients. According to HHS-OIG, malicious actors used fake email addresses for grant recipients to compromise the PSC grant payment system. The bad actors deleted legitimate users, changed contact information, and requested that payments be sent to their own bank accounts. The bad actors were able to divert more than $10 million in grant funds to their own accounts, although the banks rejected some of those transfers, resulting in a net loss to the HHS of $7.8 million. The HHS-OIG audit looked specifically at the PSC’s...

Read More
Erie Insurance Experiencing Business Disruption Due to Cyberattack
Jun18

Erie Insurance Experiencing Business Disruption Due to Cyberattack

Pennsylvania-based Erie Indemnity Corp., which does business as Erie Insurance, is investigating a network intrusion. Erie Insurance is a Fortune 500 company that provides a range of insurance policies, including life insurance, auto insurance, cyber insurance, and Medicare supplements. According to a recent Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), unusual network activity was identified on June 7, 2025. Its incident response protocols were immediately implemented to safeguard its systems and sensitive data, and law enforcement was notified. Erie Insurance is assisting with the police investigation and has engaged a leading third-party cybersecurity firm to determine the full scope, nature, and impact of the incident, and has confirmed it is continuing to take protective measures. Since the investigation has only recently been launched, it is too early to tell to what extent, if any, policyholders’ information has been exposed or stolen. Erie Insurance has approximately 7 million policyholders in the United States. The company has confirmed that the...

Read More
FTC Imposes $1.9 Million Penalty on Evoke Wellness for Deceptive Marketing Campaign
Jun17

FTC Imposes $1.9 Million Penalty on Evoke Wellness for Deceptive Marketing Campaign

The Federal Trade Commission (FTC) has proposed a $1.9 million settlement to resolve claims that Evoke Wellness, a Florida-based substance use disorder treatment clinic, engaged in deceptive business practices and deliberately misled consumers who were seeking substance use disorder treatment by pretending to be other clinics. According to the January 2025 complaint, Evoke Wellness, LLC, Evoke Health Care Management, and their officers, Jonathan Mosley and James Hull, conducted a deceptive Google Ads campaign targeting consumers conducting online searches for substance use disorder treatment clinics. According to the FTC, the campaign used the specific names of other clinics as keywords to ensure Evoke’s ads appeared when searches were made for those clinics. The ads prominently displayed the names of the impersonated clinics, misleading consumers into calling the telephone number for Evoke’s telemarketing call center. When the number was called, the Evoke telemarketers would explain that they had reached a centralized admissions office or an addiction treatment hotline,...

Read More
PHI Stolen in Sensata Technologies Ransomware Attack
Jun17

PHI Stolen in Sensata Technologies Ransomware Attack

A ransomware attack on Sensata Technologies involved the theft of health and wellness plan data. A former Evoke Wellness employee has been accused of stealing patient data for identity theft, and limited PHI has been impermissibly disclosed due to mailing errors at Blue Shield of California and AffirmedRx PBC. Sensata Technologies Hit with Ransomware Attack Sensata Technologies, Inc., a leading industrial technology firm that makes sensor and control solutions, has been hit with a ransomware attack. The attack was identified on April 6, 2025, when files were encrypted on its network. Sensata implemented its response protocols to contain the incident, and an investigation was launched with assistance provided by a third-party cybersecurity firm. Law enforcement was also notified about the attack. The forensic investigation confirmed that the ransomware group had access to its network between March 28, 2025, and April 6, 2025, during which time files were accessed and copied from its network. Over the past two months, Sensata reviewed the affected files and has confirmed that they...

Read More
Legislation Introduced to Make Violence Against Healthcare Workers a Federal Crime
Jun17

Legislation Introduced to Make Violence Against Healthcare Workers a Federal Crime

Companion bills have recently been introduced in the House of Representatives and the Senate that seek to make violent attacks on employees of hospitals and healthcare organizations a federal crime. Data released by the U.S. Bureau of Labor Statistics in 2018 revealed that healthcare workers are five times more likely to experience violence in the workplace than workers in other industries. In 2018, healthcare workers accounted for 73% of all nonfatal workplace injuries and illnesses due to violence, and there was an increase in violent incidents during the COVID-19 pandemic. In January 2024, a poll conducted by the American College of Emergency Physicians revealed that 91% of respondents had either personally experienced violence in the workplace or were aware of a colleague who was a victim of violence in the past year. 40% of respondents said they knew of an attack on a healthcare worker in a trauma center that resulted in moderate to severe disability or death. Last year, the American College of Surgeons reported an increase in violence against surgeons. Jay J. Doucet, MD, MSc,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist