25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Nurse Patient Communication

Nurse patient communication is not only important for the identification of symptoms and feedback on treatments, but it can also help improve the patient experience, increase the prospects of recovery, and reduce readmissions – saving healthcare facilities money through CMS’ Hospitals Readmission Reduction program. Effective communication between nurses and patients is a fundamental part of good nursing care. Good nurse patient communication makes patients feel valued, cared for, and safe. When patients are admitted into hospital it is common for them to feel like they have lost control of their lives. Everyday things they used to take care of themselves are placed in the hands of others. Being totally reliant on hospital staff can leave patients feeling helpless. When nurses spend time talking with patients and practice patient-centered communication, patients feel valued as a person and they will be more likely to speak openly about how they are feeling. This will put nurses in a better position to formulate a comprehensive, individualized care plan for the patient. Good nurse...

Read More
Law Enforcement Operation Takes Down 8Base Ransomware Group
Feb11

Law Enforcement Operation Takes Down 8Base Ransomware Group

An international law enforcement operation has taken down the negotiation and data leak sites of the 8Base ransomware group. The operation saw four individuals – two men and two women – arrested across different locations in Phuket, Thailand, with law enforcement officers seizing mobile phones, laptop computers, and digital wallets. The four individuals now face charges of conspiracy to commit an offense against the United States and conspiracy to commit wire fraud. The 8Base ransomware group emerged in March 2022, initially keeping a low profile until June 2023 when the group started leaking data stolen in its attacks. The group is believed to consist of experienced hackers, potentially from a different ransomware group. VMWare has linked the group to another ransomware operation, RansomHouse, due to similarities in their data leak sites and ransom notes, although it is unclear if the same individuals operate both ransomware groups. 8Base was responsible for more than 1,000 ransomware attacks worldwide, including attacks on healthcare organizations. The U.S. Department...

Read More

HIPAA Compliance for Behavioral Health Practices

HIPAA compliance for behavioral health practices not only consists of complying with the HIPAA Privacy, Security, and Breach Notification Rules, but also with any other federal or state regulations that preempt HIPAA’s “federal floor” of privacy protections. These regulations include (for example) the Part 2 “SUD” regulations and the Texas Medical Records Privacy Act. Most behavioral health professionals are subject to the HIPAA Privacy, Security, and Breach Notification Rules inasmuch as they are either solo practitioners who qualify as a HIPAA Covered Entity, or they work for a behavioral health practice that has implemented policies and procedures to comply with the HIPAA Rules. In terms of HIPAA compliance for behavioral health practices, if a solo practitioner qualifies as a Covered Entity, they are responsible for implementing measures to protect the privacy of individually identifiable health information and that ensure the confidentiality, integrity, and availability of electronic Protected Health Information (PHI). In multi-practitioner behavioral health practices, these...

Read More
Southeast Series of Lockton Companies to Pay $9.9 Million to Settle Data Breach Litigation
Feb11

Southeast Series of Lockton Companies to Pay $9.9 Million to Settle Data Breach Litigation

Southeast Series of Lockton Companies, LLC, a provider of insurance services, has agreed to pay up to $9,900,000 to settle a class action lawsuit stemming from a major data breach in November 2024. While many cyberattacks involve broad access being gained to computer networks, in this case a hacker accessed a single account and computer within its environment; however, despite the access being limited, the hacker was able to access files containing the protected health information of 1,124,727 individuals, including names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and financial information. The affected individuals were notified about the data breach in March 2025 and were offered complimentary credit monitoring services for 24 months. Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint – Penny Beasley, et al. v. Southeast Series of Lockton Companies, LLC, et al. – in the Circuit Court of Jackson County, Missouri. The defendants maintain there was no wrongdoing and...

Read More
Accendo Insurance Company Affected by Business Associate Data Breach
Feb11

Accendo Insurance Company Affected by Business Associate Data Breach

Data breaches have recently been announced by Accendo Insurance Company, Menorah Life, Humboldt Independent Practice Association, and Samaritan Counseling Center of the Fox Valley. Accendo Insurance Company Accendo Insurance Company, a CVS Health Medicare supplement insurance provider, has been affected by a data breach at one of its business associates. Landmark Admin is a third-party administrator for insurance carriers, and in its capacity as a business associate, was provided with the personal information of individuals who purchased insurance through Accendo. On or around May 13, 2024, Landmark identified suspicious activity within its computer network. A third-party cybersecurity firm was engaged to investigate the activity and the investigation concluded on July 24, 2024. Landmark confirmed that a ransomware group had access to its network between May 13, 2024, and June 17, 2024, and exfiltrated data from its systems and encrypted files. According to Accendo’s January 22, 2025, notice to the South Carolina Attorney General, Landmark has been issuing notifications to the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist