25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Email Account Breaches Reported by Access TeleCare & Madison County, MS
Mar19

Email Account Breaches Reported by Access TeleCare & Madison County, MS

Access TeleCare in Texas and Madison County, Mississippi have reported breaches of employee email accounts, and the California Department of Child Support Services has discovered an employee emailed sensitive data to a personal email account. Access TeleCare, Texas The Dallas, TX-based acute and specialty telemedicine provider Access TeleCare identified unauthorized access to an employee’s email account on January 8, 2024. An investigation was launched which revealed an unauthorized third party had access to the email account for 2 months since November 6, 2023, and other email accounts may also have been accessed. During the two months, it is possible that emails and attachments were downloaded from the account. A data review vendor was engaged, and Access TeleCare was provided with the final results of the review on August 30, 2024; however, it took until March 4, 2025, for individual notifications to be mailed. Access TeleCare said the four-and-a-half-month delay from receiving the final results to issuing notification letters was due to the time-intensive process of reviewing...

Read More
The Biggest Healthcare Data Breaches of 2024
Mar19

The Biggest Healthcare Data Breaches of 2024

Last year was an annus horribilis for healthcare data breaches. While there appears to have been a slight year-over-year reduction in the number of reported data breaches of 500 or more records, the number of individuals affected by those breaches has risen considerably. As of March 19, 2025, 734 large data breaches have been reported to OCR, a percentage decrease of 1.74% from the 747 large healthcare data breaches reported in 2023. While a reduction in healthcare data breaches is a step in the right direction, 2024 was the worst-ever year in terms of breached healthcare records, which jumped by 64.1% from last year’s record-breaking total to 276,775,457 breached records, or 81.38% of the 2024 population of the United States. Those figures will surely grow over the coming weeks and months as more data breaches are expected to be added to OCR’s breach portal for December, and 64 data breaches in 2024 have been reported using potential placeholder estimates of 500 or 501 breached records. These figures are commonly used when the file review has not been completed by the breach...

Read More

What is Required for HIPAA Compliance?

What is required for HIPAA compliance is for covered entities and business associates to comply with all applicable standards and implementation specifications of the HIPAA Administrative Simplification Regulations in order to protect the privacy and security of individually identifiable health information. Due to the complexity of the HIPAA Administrative Simplification Regulations, misunderstandings can sometimes exist about what HIPAA is, who it applies to, what is protected by HIPAA, and who is responsible for HIPAA compliance. These misunderstandings can make it difficult to determine what is required for HIPAA compliance. What is HIPAA? HIPAA stands for the Health Insurance Portability and Accountability Act – an Act passed in 1996 with the purpose of reforming the health insurance industry. Due to the cost of the reforms, a second Title was added to the Act which aimed to counter the cost by reducing fraud in the healthcare industry and simplifying the administration of healthcare transactions. The Administrative Simplification Regulations are what most people refer to when...

Read More
$17.5 Million Settlement Resolves Infosys McCamish Systems Data Breach Lawsuit
Mar18

$17.5 Million Settlement Resolves Infosys McCamish Systems Data Breach Lawsuit

A settlement has been agreed to resolve multiple Infosys McCamish Systems class action lawsuits that were filed in response to a 2023 ransomware attack and data breach that involved unauthorized access to the personal data of more than 6 million individuals. Infosys is India’s second-largest IT services provider, and Infosys McCamish Systems is a U.S. subsidiary that provides life insurance and retirement software and services. In November 2023, Infosys McCamish Systems discovered its systems had been breached in a ransomware attack. The forensic investigation confirmed that an unauthorized cyber actor had access to its systems between October 29 and November 2, 2023, exfiltrated sensitive data, and used ransomware to encrypt files. The LockBit ransomware group claimed responsibility for the attack and demanded a ransom, payment of which was required to obtain the keys to decrypt data and prevent the stolen data from being made public. A LockBit representative claimed that Infosys McCamish offered to pay $50,000 to prevent the release of the stolen data but the lowball offer was...

Read More
New HIPAA Exemption Added to Kentucky Consumer Data Protection Act
Mar18

New HIPAA Exemption Added to Kentucky Consumer Data Protection Act

In April 2024, Kentucky joined the growing number of states that have adopted comprehensive consumer privacy and data protection laws. The Kentucky Consumer Data Protection Act was signed into law on April 4, 2024, and is due to take effect on January 1, 2026. The Kentucky Consumer Data Protection Act applies to individuals and legal entities that control or process the personal data of at least 100,000 Kentucky consumers or control or process the personal data of 25,000 Kentucky consumers and derive over 50% of gross revenue from the sale of personal data. An amendment to the law has been signed by state governor Andy Beshear that narrows the scope of the law, exempting information collected by healthcare providers covered under HIPAA that maintain protected health information in compliance with the HIPAA Rules and other related regulations. The amendment also expands the excluded information to include information collected in a limited data set, as defined in 45 C.F.R. 8 164.514(e) to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. 8...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist