25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breaches Announced by DermCare Management; Option Care Health; Aetna
Apr13

Data Breaches Announced by DermCare Management; Option Care Health; Aetna

Data breaches have recently been announced by DermCare Management in Florida, Option Care Health in New York, and Aetna in Connecticut. DermCare Management Discloses 2025 Hacking Incident DermCare Management, a Florida-based provider of practice management services to dermatology practices in Florida, Texas, California, and Virginia, has identified unauthorized access to its computer systems. Suspicious activity was identified within its computer network on February 26, 2025, and, assisted by third-party digital forensics specialists, DermCare Management determined on March 3, 2025, that there had been unauthorized network access between February 14, 2025, and February 26, 2025. During that time, patient information was either accessed or acquired. DermCare Management engaged data review specialists to determine the individuals affected and the types of data involved. Due to the complexity of the data, it took until March 2, 2026, to identify the individuals affected, the types of data involved, and obtain sufficient information to issue individual notification letters. DermCare...

Read More
HIPAA for Solo Practitioners
Apr13

HIPAA for Solo Practitioners

Most solo practitioners do not begin their careers in solo practice. They typically spend years working in hospitals, group practices, or supervised clinical settings where confidentiality, accurate recordkeeping, and respect for patient rights are treated as core professional obligations. By the time they open their own practice, solo practitioners have already acquired and demonstrated competence in the ethical and legal standards of their profession through formal education, licensing exams, and real‑world clinical experience. What changes in solo practice is not the practitioner’s understanding of these obligations, but the responsibility for operationalizing them. HIPAA provides a federal compliance framework that translates long‑standing professional duties into operational requirements that must be implemented, documented, and maintained. In larger organizations, this work is supported by administrative staff, IT teams, compliance officers, and established workflows. In a solo practice, the practitioner becomes the Privacy Officer, Security Officer, and compliance lead by...

Read More
February 2026 Healthcare Data Breach Report
Apr10

February 2026 Healthcare Data Breach Report

In February 2026, 63 data breaches were reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) that affected 500 or more individuals, a 14.5% increase from January 2026, and 12.5% more than the average number of February data breaches over the past 5 years. Between January 1 and February 28, 2026, 118 data breaches affecting 500 or more individuals have been reported to OCR, involving the protected health information of 9,651,076 individuals. While healthcare data breaches have declined 10.6% year-over-year, the number of individuals affected has increased 44.7%. Across the 63 data breaches reported in February, the protected health information of at least 8,134,378 individuals was exposed or impermissibly disclosed, a 436% month-over-month increase and 38.9% more than the average number of affected individuals over the past 12 months. Biggest Healthcare Data Breaches in February 2026 The high total in February is due to massive data breaches at two HIPAA-regulated entities in February – TriZetto Provider Solutions, a provider of administrative...

Read More
Data Breaches Announced by Neinstein Plastic Surgery; Atlantic Brain and Spine
Apr09

Data Breaches Announced by Neinstein Plastic Surgery; Atlantic Brain and Spine

Neinstein Plastic Surgery in New York and Atlantic Brain and Spine in North Carolina have announced security incidents that exposed patient information. Neinstein Plastic Surgery, New York Neinstein Plastic Surgery in New York City has identified unauthorized access to an email account that contained sensitive patient information. Unauthorized activity was identified in the email account on December 2, 2025. The account was secured, and an investigation was initiated to determine the nature and scope of the activity. The investigation confirmed that the account had been accessed by an unauthorized individual between November 12, 2025, and November 20, 2025, and that this was a financially motivated attack rather than an attempt to obtain patient information; however, patient information may have been obtained in the incident. The account was reviewed and on February 20, 2026, Neinstein Plastic Surgery confirmed that emails and documents in the account contained information such as names, contact information, dates of birth, driver’s license or passport numbers, Social Security...

Read More
Settlement Agreed to Resolve Class Action Data Breach Litigation Against Concord Orthopaedics
Apr09

Settlement Agreed to Resolve Class Action Data Breach Litigation Against Concord Orthopaedics

Concord Orthopaedics Professional Association, a New Hampshire-based provider of comprehensive orthopedic and rheumatology care, has settled a consolidated class action lawsuit stemming from a November 2024 cybersecurity incident involving unauthorized access to the personal and protected health information of 72,815 individuals. Concord Orthopaedics detected an intrusion on November 21, 2024. Hackers had gained access to its computer network, where names, dates of birth, Social Security numbers, appointment information, health insurance information, and driver’s license/state identification numbers were stored. The affected individuals started to be notified about the incident on March 25, 2025. The first class action lawsuit was filed by plaintiff Kattie Montambeault on April 1, 2025, in the Merrimack County Superior Court for the State of New Hampshire. A further four class action complaints were filed in response to the data breach, which were consolidated into a single action – Montambeault, et al. v. Concord Orthopaedics Professional Association – in the Superior Court...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist