25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OSHA Terminates COVID-19 Rulemaking and Works on Standard Addressing a Broader Range of Infectious Diseases
Jan20

OSHA Terminates COVID-19 Rulemaking and Works on Standard Addressing a Broader Range of Infectious Diseases

The Occupational Safety and Health Administration (OSHA) has abandoned efforts to establish a final COVID-19 safety standard to ensure workers in healthcare settings are protected from COVID-19. OSHA issued an Emergency Temporary Standard (ETS) on June 21, 2021, after determining that COVID-19 posed a grave danger to healthcare workers. At that point, almost half a million healthcare workers had contracted COVID-19, and more than 1,600 healthcare workers had died as a result of COVID-19 infections. After issuing the ETS, OSHA received petitions from industry associations including the American Nurses Association, International Association of Fire Chiefs, and National Nurses United (NNU) urging OSHA to adopt a permanent standard to protect healthcare workers from COVID-19 and to also issue a separate standard covering a broader range of infectious diseases. OSHA submitted a draft final COVID-19 rule to the White House Office of Management and Budget on December 7, 2022; however, on April 10, 2023, House Joint Resolution 7 was signed into law by President Biden terminating the...

Read More
Email Accounts Compromised at LifeBridge Health
Jan20

Email Accounts Compromised at LifeBridge Health

LifeBridge Health has discovered unauthorized access to employee email accounts. Effortless Office Enterprises has suffered a cyberattack, and Han Van Duong, M.D. has experienced a break-in and theft of laptop computers containing patient data. LifeBridge Health LifeBridge Health in Maryland has discovered unauthorized access to several employee email accounts. The breach was detected on November 12, 2024, and the forensic investigation determined that the email accounts had been compromised between August 27, 2024, and September 21, 2024. The breach was limited to email accounts, with no other systems affected. File attachments and emails in the account were reviewed and found to contain patient information. The types of information involved varied from individual to individual and may have included names plus one or more of the following: dates of birth, dates of service, Social Security numbers, medical record numbers, health insurance claim numbers, and limited treatment information. Individual notifications were mailed to the affected individuals on January 10, 2025, and...

Read More
Is WeTransfer HIPAA Compliant?
Jan18

Is WeTransfer HIPAA Compliant?

WeTransfer is not HIPAA compliant and cannot be used to upload and send or receive files that include Protected Health Information – even if the service is used inside a HIPAA compliant file sharing service. However, there are several HIPAA-compliant alternatives to WeTransfer that organizations can use to securely transmit large files – albeit not so quickly, and not for free. WeTransfer is a file sharing service that is popular with individuals and organizations for its fast photo and video file sharing capabilities. In the healthcare industry, these capabilities would be particularly useful for sharing high resolution images between healthcare providers in order to facilitate collaboration, accelerate diagnoses, and support medical training One of the reasons for WeTransfer being so popular is that the service has excellent security features. These include two-factor authentication, encryption in transit and at rest, and password-protected access. In addition, WeTransfer is a Dutch company that complies with Dutch data protection laws and the GDPR. It is also ISO/IEC 27001...

Read More
Wolf Haldenstein Confirms 3.4 Million-record Data Breach
Jan17

Wolf Haldenstein Confirms 3.4 Million-record Data Breach

The New York City law firm Wolf Haldenstein Adler Freeman & Herz LLP (Wolf Haldenstein) has suffered a major data breach involving the personal and protected health information of 3,445,537 individuals, according to a breach notice recently submitted to the Maine Attorney General. Several states publish data breach summaries on the website of their Office for the Attorney General; however, many do not list how many individuals were affected, or only list the number of victims in their respective states. Maine lists the total number of individuals affected plus the number of state residents, in this case, 3,220 Maine residents. The breach report has revealed the scale of the data breach – one of the largest data breaches to occur at a law firm. Wolf Haldenstein has offices in New York, Chicago, Nashville, and San Diego and specializes in complex litigation, including assisting clients with data breach litigation. A cyberattack on its network was suspected on December 13, 2023, when suspicious network activity was identified. Immediate steps were taken to contain the incident and...

Read More
North Carolina Hospice Discovers 58,000-Record Data Breach
Jan17

North Carolina Hospice Discovers 58,000-Record Data Breach

Data breaches have been announced by AuthoraCare Collective in North Carolina, Lifetime Psychiatry in Missouri, and McNall & Associates in Alaska. AuthoraCare Collective AuthoraCare Collective, a nonprofit hospice in Greensboro, North Carolina, suffered a cyberattack in August 2024. Technical issues related to systems in its network were identified on August 22, 2024. Assisted by third-party IT forensics experts, it was determined that an unauthorized actor gained access to its systems between August 18 and August 22, 2024. The investigation confirmed on October 21, 2024, that the protected health information of up to 58,019 individuals was accessed or acquired. The review of the affected files confirmed they contained names, medical diagnoses, prescription information, Social Security numbers, and demographic information. Notifications were mailed to the affected individuals in January 2025, and complimentary credit monitoring services have been offered to individuals whose Social Security numbers were involved. Lifetime Psychiatry Lifetime Psychiatry, LLC, in St. Peters, MO,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist