25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New York Labor Union Settles Data Breach Lawsuit for $6 Million
Feb28

New York Labor Union Settles Data Breach Lawsuit for $6 Million

The New York-based labor Union, UNITE HERE, has agreed to pay $6 million to resolve a consolidated class action lawsuit that alleged a failure to implement appropriate cybersecurity measures to protect the sensitive data it held. On October 20, 2023, UNITE HERE identified unauthorized access to its systems. Hackers were determined to have breached its network and gained access to files containing the personal and protected health information of members of certain local unions and health funds. It was not possible to determine exactly how many people were affected, so the decision was taken to send notification letters to all 791,273 potentially affected members. Data compromised in the incident included names, Social Security numbers, driver’s licenses, state identification numbers, alien registration numbers, tribal identification numbers, passport numbers, birth certificates, dates of birth, marriage licenses, signatures, financial account information, and medical information. Class action lawsuits were filed by union members, which were consolidated into a single lawsuit –...

Read More
Lawsuit Filed Against Amazon Alleging Unlawful Collection of Health & Location Data
Feb27

Lawsuit Filed Against Amazon Alleging Unlawful Collection of Health & Location Data

A lawsuit has been filed against Amazon alleging its software development kit (SDK) has unlawfully collected consumers’ health and location data in violation of federal laws and consumer privacy laws in Washington state. An SDK is a suite of software development tools such as compilers, code libraries, and debuggers, that allows software developers to build applications quickly and in a standardized way. The Amazon SDK is embedded in thousands of third-party applications and runs in the background, allowing Amazon to collect information such as location data directly from consumer devices. The information collected by Amazon is used for advertising purposes, and the data can be sold to others. The lawsuit alleges the Amazon SDK has been integrated into more than 10,000 different apps. The lawsuit was filed in the U.S. District Court for the Western District of Washington at Seattle on February 20, 2025, on behalf of plaintiff Cassaundra Maxwell and similarly affected individuals. The lawsuit alleges Amazon is unlawfully tracking, collecting and profiting from users’ location...

Read More
Fred Hutchinson Cancer Center Settles Class Action Data Breach Lawsuit for $11.5M
Feb27

Fred Hutchinson Cancer Center Settles Class Action Data Breach Lawsuit for $11.5M

Fred Hutchinson Cancer Center and the University of Washington have agreed to pay $11,500,000 to settle a proposed class action data breach lawsuit and have committed to investing $13,500,000 to improve cybersecurity. The lawsuit stems from a cyberattack and data breach discovered after the Thanksgiving weekend in 2023. Hackers breached its network and stole the protected health information of approximately 2.1 million individuals between November 10 and November 25, 2023, including names, contact information, medical information, and Social Security numbers. The attack was conducted by the Hunters International threat group, which demanded a ransom payment to prevent the publication of the stolen data. When the ransom was not paid, the affected patients were sent individual ransom demands and were told that they needed to pay $50 to have their stolen data deleted, otherwise, it would be published online. Several lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit – In re: Fred Hutchinson Cancer Center Data Breach Litigation – in...

Read More
Is Windows 11 HIPAA Compliant?
Feb26

Is Windows 11 HIPAA Compliant?

Windows 11 is HIPAA compliant inasmuch as the operating system has the underlying security and administrative capabilities to support HIPAA compliance. In addition, Microsoft has confirmed that its in-scope cloud platforms and services are covered by the Microsoft Business Associate Agreement when used on a device running Windows 11. With support for many editions of Windows 10 ending in October 2025, organizations using Microsoft services will be required to upgrade their operating systems to Windows 11. For most organizations currently using Windows 10, the upgrade process is straightforward. Provided devices meet minimum system requirements, programs, apps, and settings currently being used on the devices will be migrated automatically to the upgraded operating system. For organizations currently using older Windows operating systems (i.e., Windows 7), the upgrade will not be so straightforward. Depending on the existing configuration, upgrading to Windows 11 may require a clean install – in which case programs, apps, and settings will not be migrated. In some cases, it will be...

Read More
Is eFax HIPAA Compliant?
Feb26

Is eFax HIPAA Compliant?

eFax is HIPAA compliant for covered entities and business associates that subscribe to a qualifying eFax account, enter into a Business Associate Agreement, and configure the service to support HIPAA compliance. However, due to concerns about the vendor’s HIPAA knowledge and messaging, this may not be the most suitable electronic fax solution for all organizations. eFax is an electronic fax solution that enables customers to send, receive, and (in certain circumstances) store faxes via email and cloud services. In addition to supporting person-to-person faxes, eFax’s Enterprise Fax API enables customers to integrate fax processes between CRMs, ERPs, and EHRs – potentially eliminating many manual processes and saving healthcare organizations time and money. However, when using eFax to send, receive, and store faxes that contain Protected Health Information, it is necessary for eFax to be HIPAA compliant. This means the software must have technical capabilities to support HIPAA compliance, the location of the vendor’s servers must be protected according to the Security Rule’s...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist