25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Clinical Trials Database Containing 1.6 Million Records Exposed Online
Feb19

Clinical Trials Database Containing 1.6 Million Records Exposed Online

A database containing approximately 1.6 million clinical trial records has been exposed over the Internet and could be accessed without a password. The 2 TB database was found by cybersecurity researcher Jeremiah Fowler, who reports that the database contains 1,674,218 records, including PDF survey results that include sensitive personal and medical information. The exposed data included names, phone numbers, email addresses, dates of birth, vaccination information, current medications, health conditions, and patient notes. In some cases, the notes included doctors’ names, pregnancy status, adverse reactions to previous vaccines, and whether individuals were on birth control. The records related to individuals across the United States. An analysis of a limited sample of the records found no duplicates, although from that limited sample Fowler could not rule out the possibility that individuals had enrolled in separate individual surveys. Fowler, of the firm Security Discovery, identified DM Clinical Research as the potential owner from the name of the database and references within...

Read More

What Are HIPAA Laws?

The main objective of HIPAA law is to protect the privacy of an individuals’ health information while at the same time permitting needed information to be disclosed for patient care and other purposes such as billing. This balance helps protect the rights of patients while ensuring smooth operation of the healthcare system. HIPAA compliance laws set the standards for protecting sensitive patient data that healthcare providers, insurance companies, and other covered entities must adhere to. You can use our HIPAA Law Compliance Checklist to check your compliance requirements and avoid HIPAA violations. What follows is an overview of the main components of HIPAA Law: The HIPAA Law Privacy Rule A key component of HIPAA compliance law is the Privacy Rule, which sets out national standards for when protected health information (PHI) may be used and disclosed. PHI refers to any information about health status, provision of health care, or payment for health care that can be linked to a specific individual. This interpretation of PHI is broad and encompasses any part of a...

Read More
HIPAA Compliance for Counselors
Feb18

HIPAA Compliance for Counselors

The responsibility for HIPAA compliance for counselors in the healthcare industry can vary depending on a counselor’s HIPAA status and whether a practice is part of a managed care organization – in which case, the structure of the managed care organization can determine who is responsible for HIPAA compliance. Counselors who qualify as – or who work for – a HIPAA covered entity are required to comply with all applicable standards and implementation specifications of the HIPAA Administrative Simplification Regulations. These not only include the HIPAA Privacy, Security, and Breach Notification Rules, but also the General Provisions in Parts 160 and 164, and the Transactions and Code Sets Rules in Part 162. The responsibility for determining which standards and implementation specifications apply can vary depending on a counselor’s HIPAA status and what services are contracted out. For example, a sole practitioner counselor that subcontracts claims and billing transactions to a business associate is not required to comply with Part 162 – although it is advisable to monitor business...

Read More
Ransomware Gangs Attack Sault Ste. Marie Tribe of Chippewa Indians & SimonMed Imaging
Feb18

Ransomware Gangs Attack Sault Ste. Marie Tribe of Chippewa Indians & SimonMed Imaging

SimonMed Imaging and the Sault Ste. Marie Tribe of Chippewa Indians have suffered ransomware attacks, and the San Diego trade union, UFCW Local 135, has reported a breach of the personal data of more than 62,000 individuals. SimonMed Imaging SimonMed Imaging, a radiology practice in Scottsdale, Arizona, was targeted by a ransomware group. A spokesperson for the practice said the attack was identified and interrupted before any files were encrypted. Some systems were temporarily taken offline, which caused a delay to some services; however, the practice remained fully operational throughout. The spokesperson said there was no unauthorized access to any clinical systems. The Medusa ransomware group has claimed responsibility for the attack and added SimonMed Imaging to its data leak site, along with apparent proof of data theft. 45 files were added to the listing, and the group claimed it stole 212 GB of data in the attack and demanded a $1 million ransom payment. Medusa gave SimonMed Imaging until February 21, 2025, to pay the ransom. Medusa claims to have stolen data such as...

Read More
Email Account Breaches Reported by Kansas & West Virginia Medical Centers
Feb18

Email Account Breaches Reported by Kansas & West Virginia Medical Centers

Heartland Community Health Center in Kansas and Charleston Area Medical Center in West Virginia have identified unauthorized access to employee email accounts that contained patient data. Heartland Community Health Center Heartland Community Health Center in Lawrence, Kansas, identified unauthorized access to an employee’s email account on October 1, 2024. The forensic investigation confirmed that the breach was limited to a single email account and no other systems were affected. The file review confirmed that the email account contained electronic protected health information such as names, addresses, phone numbers, email addresses, Social Security numbers, driver’s license/state ID numbers, dates of birth, medical diagnosis/treatment information, prescription information, dates of service, patient ID numbers, provider names, medical record numbers, Medicare/Medicaid numbers, health insurance information, health insurance claim numbers, health insurance policy numbers, and/or treatment cost information. Heartland Community Health Center added a substitute breach notice to its...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist