25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Ransomware Gangs Attack Sault Ste. Marie Tribe of Chippewa Indians & SimonMed Imaging
Feb18

Ransomware Gangs Attack Sault Ste. Marie Tribe of Chippewa Indians & SimonMed Imaging

SimonMed Imaging and the Sault Ste. Marie Tribe of Chippewa Indians have suffered ransomware attacks, and the San Diego trade union, UFCW Local 135, has reported a breach of the personal data of more than 62,000 individuals. SimonMed Imaging SimonMed Imaging, a radiology practice in Scottsdale, Arizona, was targeted by a ransomware group. A spokesperson for the practice said the attack was identified and interrupted before any files were encrypted. Some systems were temporarily taken offline, which caused a delay to some services; however, the practice remained fully operational throughout. The spokesperson said there was no unauthorized access to any clinical systems. The Medusa ransomware group has claimed responsibility for the attack and added SimonMed Imaging to its data leak site, along with apparent proof of data theft. 45 files were added to the listing, and the group claimed it stole 212 GB of data in the attack and demanded a $1 million ransom payment. Medusa gave SimonMed Imaging until February 21, 2025, to pay the ransom. Medusa claims to have stolen data such as...

Read More
Email Account Breaches Reported by Kansas & West Virginia Medical Centers
Feb18

Email Account Breaches Reported by Kansas & West Virginia Medical Centers

Heartland Community Health Center in Kansas and Charleston Area Medical Center in West Virginia have identified unauthorized access to employee email accounts that contained patient data. Heartland Community Health Center Heartland Community Health Center in Lawrence, Kansas, identified unauthorized access to an employee’s email account on October 1, 2024. The forensic investigation confirmed that the breach was limited to a single email account and no other systems were affected. The file review confirmed that the email account contained electronic protected health information such as names, addresses, phone numbers, email addresses, Social Security numbers, driver’s license/state ID numbers, dates of birth, medical diagnosis/treatment information, prescription information, dates of service, patient ID numbers, provider names, medical record numbers, Medicare/Medicaid numbers, health insurance information, health insurance claim numbers, health insurance policy numbers, and/or treatment cost information. Heartland Community Health Center added a substitute breach notice to its...

Read More
Data Breaches Confirmed by City of McKinney and Innovative Renal Care
Feb17

Data Breaches Confirmed by City of McKinney and Innovative Renal Care

Data breaches have recently been announced by the City of McKinney in Texas and Innovative Renal Care in Tennessee. City of McKinney The City of McKinney has recently confirmed that the protected health information of 17,751 individuals was compromised in an October 2024 cyberattack. The security breach was detected on November 14, 2024, with the forensic investigation confirming government systems were first breached on October 31, 2024. City officials did not provide further information on the nature of the attack, such as if ransomware was involved, and no ransomware group appears to have claimed responsibility for the attack. City officials said the unauthorized access was immediately severed and the Federal Bureau of Investigation, Department of Homeland Security, and the Texas Department of Information were contacted and provided assistance. The forensic investigation confirmed on November 16, 2024, that files had been exposed and may have been stolen, and on December 30, 2024, it was confirmed that some of those files contained protected health information. The review of the...

Read More
Former UPS/Amazon Safety Executive Nominated to Head OSHA
Feb17

Former UPS/Amazon Safety Executive Nominated to Head OSHA

On February 12, 2025, President Trump nominated the former UPS and Amazon safety executive, David Keeling, to head the Occupational Safety and Health Administration (OSHA) at the Department of Labor. OSHA’s mission is to “assure safe and healthy working conditions for working men and women by setting and enforcing standards and by providing training, outreach, education, and assistance,” as well as enforce whistleblower statutes and regulations. Keeling served as Director, Global Safety Compliance at the global shipping and logistics company UPS between 2011 and 2018, before becoming Vice President – Global Health & Safety, a position he held until 2021. Keeling moved to Amazon in 2021, serving as Director – Global Road & Transportation Safety for two years. “I want to express my heartfelt gratitude to President Trump for nominating me to be the next OSHA administrator at the U.S. Department of Labor,” Keeling said in a post on LinkedIn. “It is an incredible honor, and if confirmed, I am excited about the opportunity to work with Secretary Lori...

Read More
Is Microsoft Forms HIPAA Compliant?
Feb16

Is Microsoft Forms HIPAA Compliant?

Microsoft Forms is HIPAA compliant inasmuch as the app is an in-scope service included in Office 365 and Microsoft 365 subscriptions that support HIPAA compliance. However, due to a reported issue with the form footer, Microsoft Forms is not an effective option for collecting Protected Health Information. Microsoft Forms is an app included with most Office 365 and Microsoft 365 subscriptions which can be used by organizations to create online surveys, quizzes, and polls. Links to surveys, quizzes, and polls can be distributed by URL, QR code, or via a contact link in the Outlook and Teams portals to selected individuals, everyone in the organization, or to “anyone”. Respondents can complete the surveys, quizzes, and polls via a web browser without having to download the app, and organizations can see real-time responses as they are submitted. The responses can then be analyzed and evaluated in the Forms app, or exported to Excel for more granular analyses. The results can also be exported and saved in OneDrive for easier distribution. Is Microsoft Forms HIPAA Compliant? When...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist