25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Tens of Thousands of Residents Affected HCF Management Cyberattack
Jan24

Tens of Thousands of Residents Affected HCF Management Cyberattack

More than 57,000 residents of HCF Management-operated long-term care facility residents have been notified that their data has been stolen in a hacking incident, and a mismailing incident has affected a limited number of Alliant Health Plans members. More than 57,000 Residents of HCF Facilities Affected by Data Breach HCF Management Inc., a Lima, OH-based company that manages 31 long-term care facilities in Ohio and Pennsylvania has announced that hackers gained access to its network and the data of residents of multiple long-term care facilities. HCF Management said the intrusion was detected on October 3, 2024; however, the forensic investigation confirmed that its network was infiltrated on September 17, 2024. Immediate action was taken to prevent further unauthorized access, and a third-party computer forensics firm was engaged to investigate the incident and determine the nature and scope of the unauthorized activity. On November 19, 2024, HCF Management confirmed that the hacker had exfiltrated files containing residents’ information. The types of data involved varied from...

Read More
84% of Healthcare Organizations Detected a Cyberattack in the Past 12 Months
Jan24

84% of Healthcare Organizations Detected a Cyberattack in the Past 12 Months

A recent survey of 1,309 healthcare IT and security professionals by Netwrix revealed 84% detected a cyberattack or intrusion in the past 12 months, with account hijacking and phishing the most common types of attacks. Account compromise was the most common type of attack for organizations with cloud-based infrastructure and occurred at 74% of surveyed healthcare organizations, but just 44% of organizations with on-premises infrastructure. For organizations with on-premises infrastructure, phishing was the most common type of attack with 63% of respondents having experienced at least one phishing attack in the past 12 months. Phishing was the second most common type of incident for organizations with cloud-based infrastructure, with attacks reported by 62% of respondents. Healthcare workers can be particularly vulnerable to phishing attacks and are less likely than workers in other sectors to receive regular security awareness training. “Healthcare workers regularly communicate with many people they do not know — patients, laboratory assistants, external auditors, and more —...

Read More
Lessons from 2024 Healthcare Data Breaches
Jan24

Lessons from 2024 Healthcare Data Breaches

For the fourth consecutive year, more than 700 data breaches of 500 or more healthcare records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). At present, it looks like there has finally been a fall in healthcare data breaches, although OCR has yet to finalize its data for 2024, so the total may still increase. In order to see a more significant reduction in data breaches, healthcare organizations will need to invest more time and effort into cybersecurity. As it currently stands, 2024 was a record-breaking year in terms of breached healthcare records. It has already been confirmed that the personal and healthcare data of more than 278 million individuals was exposed, stolen, or impermissibly disclosed in 2024, more than any other year to date, and there are still many investigations of 2024 data breaches that are yet to conclude. OCR’s data breach portal currently lists 66 data breaches that have been reported as affecting 500 or 501 individuals – commonly used placeholder figures when the breach reporting deadline is reached...

Read More
294,000 Allegheny Health Network Patients Affected by Business Associate Cyberattack
Jan23

294,000 Allegheny Health Network Patients Affected by Business Associate Cyberattack

Allegheny Health Network (AHN), a Pittsburgh-based 14-hospital academic medical system, has announced a significant data breach involving unauthorized access to patient data at one of its business associates. The attack occurred at IntraSystems LLC, a third-party firm contracted to host, manage, and secure certain computer systems used by AHN’s subsidiary Home Medical Equipment and Home Infusion companies. IntraSystems notified ALN about the cyberattack on November 19, 2024, with its internal investigation confirming that hackers first accessed systems containing patient data on October 11, 2024. The attack only affected limited systems, not ALN’s entire patient database. Approximately 293,900 home care patients who received AHN’s Home Medical Equipment and Home Infusion therapy services were affected and had some of their protected health information accessed or stolen in the incident. ALN has confirmed that some patient data was exfiltrated from the systems managed by IntraSystems. When the breach was detected, the affected systems were immediately taken offline to prevent...

Read More
Dr. Dorothy Fink Appointed as Acting HHS Secretary
Jan22

Dr. Dorothy Fink Appointed as Acting HHS Secretary

On January 20, 2025, President Trump appointed Dr. Dorothy Fink as Acting Secretary of the Department of Health and Human Services (HHS). Dr. Fink is board-certified in endocrinology, internal medicine, and pediatrics and a nationally certified menopause practitioner and expert on estrogen, diabetes, and bone health. Dr. Fink has practiced at the Hospital for Special Surgery, New York Presbyterian Hospital, and Cornell University. Dr. Fink was appointed as Deputy Assistant Secretary for Women’s Health during the previous Trump Administration in 2018 and has served for several years as Director of the HHS’ Office on Women’s Health, where she has led a wide-ranging collaborative effort with hospitals to improve maternal health. Fink takes over the $1.7 trillion government agency from President Biden’s HHS Secretary, Xavier Becerra. Following her appointment, Fink issued a statement confirming some of the priorities of the HHS’ Office for Civil Rights regarding the protection of rights of conscience and religious freedom and state funding of abortion procedures. OCR has been...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist