25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

California Dental Care Provider; Childcare Referral Agency Announce Data Breaches
Mar16

California Dental Care Provider; Childcare Referral Agency Announce Data Breaches

Data breaches have been reported by two entities in California – Tieu Dental Corporation has announced a July 2025 hacking-related data breach affecting an as of yet undisclosed number of individuals. The Children’s Council of San Francisco has determined that more than 12,650 individuals have been affected by an August 2025 ransomware attack. Tieu Dental Corporation Announces July 2025 Data Breach Tieu Dental Corporation, a California-based provider of oral and maxillofacial surgery services, has started notifying patients about unauthorized access to its computer network last summer. The intrusion was identified on or around July 29, 2025, and the forensic investigation confirmed that an unauthorized third party accessed its network between July 28 and July 29, 2025. The compromised parts of its network were reviewed, and on January 11, 2026, Tieu Dental confirmed that the compromised files included patient data such as names, dates of birth, Social Security numbers, medical records, treatment plans, prescription information, and health insurance information. Tieu Dental...

Read More
EMR Practice Management Software Buyer’s Guide
Mar13

EMR Practice Management Software Buyer’s Guide

Selecting EMR practice management software requires evaluating scheduling, specialty support, charting flexibility, billing, patient engagement tools, support, integrations, future product development, and HIPAA compliance so the platform can support clinical operations, administrative workflows, and long-term practice growth without creating avoidable operational or regulatory risk. An EMR practice management platform affects how a practice books appointments, documents care, collects payment, communicates with patients, coordinates prescriptions and lab work, and protects electronic protected health information. A poor fit creates friction across the entire organization. A strong fit supports daily workflows, reduces administrative burden, and gives the practice room to expand services without replacing core systems. This buyer’s guide is built around the questions that matter during product evaluation. It focuses on workflow fit, support access, integration depth, product maturity, and compliance controls so practices can assess whether a platform meets current operational needs...

Read More
Long Island Plastic Surgical Group Settles Class Action Lawsuit Over BlackCat Ransomware Attack
Mar13

Long Island Plastic Surgical Group Settles Class Action Lawsuit Over BlackCat Ransomware Attack

A consolidated class action lawsuit against Long Island Plastic Surgical Group, P.C has been resolved with a $2,600,000 settlement. Legal action was taken by patients of the Garden City, New York-based private, academic plastic surgery practice in response to a January 4, 2024, ransomware attack by the ALPHV/BlackCat ransomware group. The forensic investigation confirmed that the BlackCat group accessed its network between January 4, 2024, and January 8, 2024, and used ransomware to encrypt files. Prior to encrypting files, sensitive data was exfiltrated from the network, including personal identifiable information (PII) and protected health information (PHI). Data stolen in the incident included full names, Social Security numbers, driver’s license numbers or state identification numbers, dates of birth, biometric information, account numbers, credit or debit card information, medical information, patient photographs, health insurance policy information, and patient account numbers. In total, more than 161,000 current and former patients were affected. The BlackCat ransomware...

Read More
Orthopaedic Institute of Western Kentucky Patients Affected by Vendor Data Breach
Mar13

Orthopaedic Institute of Western Kentucky Patients Affected by Vendor Data Breach

Orthopaedic Institute of Western Kentucky has notified patients that their PHI was compromised in two security incidents at their managed IT services provider. Supportive Home Health Care and Patriot Outpatient has identified unauthorized access to an employee’s email account. Orthopaedic Institute of Western Kentucky Orthopaedic Institute of Western Kentucky (now Mercy Health — Western Kentucky Orthopedics) in Paducah, Kentucky, has been affected by two security incidents at one of its business associates, the managed IT services provider Keystone Technologies. Keystone Technologies notified the orthopedic institute about unauthorized access to Keystone systems on two occasions: the first between April 21, 2025, and April 26, 2025, and the second between July 19, 2025, and August 1, 2025. During both periods, unauthorized individuals exfiltrated files containing patient information. The affected files were reviewed, and the affected individuals were identified in December 2025 and January 2026. Data compromised in the incident included names, addresses, dates of birth, medical...

Read More
Proliance Surgeons Settles Data Breach Litigation for $4,450,000
Mar12

Proliance Surgeons Settles Data Breach Litigation for $4,450,000

The Seattle, Washington-based surgical group, Proliance Surgeons, has agreed to a settlement to resolve class action litigation over a February 2023 cyberattack and data breach. Hackers gained access to the surgical group’s network on February 11, 2023, and exfiltrated files containing patient information. Notification letters were mailed to the 437,392 affected individuals in November 2023. Shortly thereafter, class action lawsuits started to be filed. The HIPAA Journal reported on one of those lawsuits in December 2023 (see below). That lawsuit was one of eleven class action complaints filed by victims of the data breach. Due to overlapping claims, and to conserve resources, the lawsuits were consolidated into a single complaint – In re: Proliance Surgeons Data Breach Litigation – in the Superior Court of the State of Washington in and for King County. The consolidated lawsuit alleged that Proliance Surgeons failed to implement the necessary safeguards to protect private personal and protected health information on its network and as a direct consequence of that failure,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist