NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

340,000 Individuals Affected by Security Breach at St Clair Orthopaedics & Sports Medicine
Apr23

340,000 Individuals Affected by Security Breach at St Clair Orthopaedics & Sports Medicine

Data breaches have recently been announced by St Clair Orthopaedics & Sports Medicine in Michigan and Rheumatology Associates of Baltimore in Maryland. St Clair Orthopaedics & Sports Medicine During a recent check of the HHS’ Office for Civil Rights breach portal, a data breach was identified that had not been reported by The HIPAA Journal. St Clair Orthopaedics & Sports Medicine (SCOSM) in St. Clair Shores, Michigan, reported a breach to OCR on January 30, 2025, that involved the protected health information of 340,000 individuals. Suspicious activity was identified within the SCOSM network on November 24, 2024. An investigation was launched to determine the nature and scope of any unauthorized network access, with assistance provided by third-party cybersecurity experts. On December 9, 2024, SCOSM learned that unauthorized individuals had gained access to parts of its network that contained patient data, and once the investigation was completed on December 20, 2024, a comprehensive review was conducted to determine the patients affected and the types of data involved....

Read More
Navvis & Company; SSM Health Agree to $6.5 Million Data Breach Settlement
Apr23

Navvis & Company; SSM Health Agree to $6.5 Million Data Breach Settlement

Navvis & Company and SSM Health Care Corporation have agreed to a $6.5 million settlement to resolve all claims related to a 2023 data breach that affected 2.8 million individuals. Navvis & Company is a population health company that partners with health systems, physician enterprises, & health plans to help them with value-based care. SSM Health is a healthcare provider serving patients in Illinois, Missouri, Oklahoma, and Wisconsin. Between July 12, 2023, and July 25, 2023, a cybercriminal group had access to the network of Navvis & Company, exfiltrated sensitive data, and used ransomware to encrypt files. The stolen data included the protected health information of patients and plan members of SSM Health, Arkansas Health Network, Horizon Blue Cross Blue Shield of New Jersey, RWJBH Corporate Services, Hawai’i Medical Service Association, Triple-S Management Corporation, Allina Health, and Florida Medical Clinic. The forensic investigation confirmed that approximately 2.8 million individuals had their data exposed or stolen in the incident, including names, dates...

Read More
OCH Regional Medical Center Notifies 51,000 Patients About September 2023 Data Breach
Apr22

OCH Regional Medical Center Notifies 51,000 Patients About September 2023 Data Breach

OCH Regional Medical Center in Mississippi is issuing notification letters to more than 51,000 patients about a data breach detected in September 2023. Data breaches have also been announced by Blue Cross and Blue Shield of Montana, and Northwest Radiologists/Mt. Baker Imaging in Washington state. OCH Regional Medical Center OCH Regional Medical Center in Starkville, Mississippi, has recently disclosed a security incident that occurred 19 months ago. A security breach was identified by its security team in September 2023, and immediate action was taken to block the unauthorized access. The forensic investigation confirmed that a threat actor first accessed its systems on September 6, 2023; however, the unauthorized access was not detected and blocked until September 14, 2023. The subsequent file review confirmed that the threat actor gained access to the protected health information of 67,000 patients, including names, Social Security numbers, dates of birth, phone numbers, addresses, diagnoses, disability codes, account numbers, and insurance and payer information. OCH Regional...

Read More
OSHA Publishes 2024 Workplace Injury and Illness Data
Apr22

OSHA Publishes 2024 Workplace Injury and Illness Data

The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) has published the 2024 workplace injury and illness data. The 2024 data was collected from OSHA’s Injury Tracking Application (ITA) and includes data from more than 370,000 OSHA Form 300A Summary of Work-Related Injuries and Illnesses reports. The data has been augmented with partial data from more than 732,000 OSHA Form 300 Logs of Work-Related Injuries and Illnesses and Form 301 Injury and Illness Incident Reports. The remainder of the data is currently being checked to ensure it does not contain any personally identifiable information and will be made public when the review is concluded. With the exception of certain low-risk industries, employers with more than 10 employees are generally required to maintain a record of serious work-related injuries and illnesses. They include any work-related injury or illness that results in loss of consciousness, days away from work, restricted work, or transfer to another job, and any work-related injury or illness that requires medical treatment beyond...

Read More
Onsite Mammography Email Breach Affects 357,000 Patients
Apr22

Onsite Mammography Email Breach Affects 357,000 Patients

Data breaches have been announced by Onsite Mammography in Massachusetts, Bell Ambulance in Wisconsin, Kelly & Associates Insurance Group in Maryland, and Cabot Medical Care & Jacksonville Medical Care in Arkansas. Onsite Mammography Onsite Mammography, a Westfield, MA-based provider of medical imaging services to hospitals across the United States, has announced a security incident involving the protected health information of 357,265 individuals. Suspicious activity was identified in an employee’s email account in October 2024. The email account was immediately secured, and a forensic investigation was initiated to determine the nature and scope of the unauthorized activity. Third-party digital forensics experts confirmed that there had been unauthorized access to a single email account for “a brief window of time.” A data analytics vendor was engaged to review the account to determine the individuals affected and the types of information in the account. The review concluded on February 21, 2025, and confirmed that health-related information had been exposed. Additional...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist