NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit
Jul20

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.) to resolve alleged cybersecurity failures that led to an October 2023 data breach affecting 6.9 million of its customers. The settlement also includes a commitment to implement new data security measures to better secure consumer data and prevent further data breaches. The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform. These attacks can only succeed if individuals reuse the same credentials across multiple accounts. When the credential stuffing campaign was discovered, 23andMe maintained that there had not been a breach, and that the compromised accounts were the result of customers’ poor security practices. While 23andMe customers took risks by reusing their credentials on the 23andMe site, the multistate investigation found that 23andMe was at fault as the company lacked basic cybersecurity measures...

Read More
Abbott Investigating Cyberattack Claims From Two Threat Actors
Jul20

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal. Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results. The ShinyHunters data theft and extortion group claimed...

Read More
Centers Laboratory Discloses Data Breach Affecting 542K Individuals
Jul20

Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a Hanover, New Jersey-based diagnostic testing laboratory that provides medical and diagnostic testing services to healthcare providers, has announced an August 2025 cybersecurity incident affecting more than half a million patients of its healthcare provider clients. Suspicious activity was identified within its computer systems on August 25, 2025. Systems were isolated to contain the incident, and steps were taken to prevent further unauthorized access. The forensic investigation confirmed that an unauthorized third party gained limited access to certain systems between August 9, 2025, and August 14, 2025. The forensic investigators determined that files containing patient data were exfiltrated from its systems by an unauthorized third party. Centers Lab engaged third-party data review specialists to perform a detailed review of the impacted data, and after that process was completed, the findings were internally validated. The validation process has recently been completed, and notification letters have been mailed to the affected individuals.  The...

Read More
All About Women’s Care Data Breach Affects Up to 12,000 Patients
Jul17

All About Women’s Care Data Breach Affects Up to 12,000 Patients

All About Women’s Care in Colorado has notified 12,000 patients that their data has been compromised in a data breach, and Mid-South Pulmonary Sleep Specialists in Tennessee is assessing the impact of a November 2025 ransomware attack. All About Women’s Care, Colorado All About Women’s Care, an Englewood, CO-based obstetrics and gynecology practice, has identified unauthorized access to its IT environment. Suspicious activity was identified involving an employee VPN account. Third-party cybersecurity experts were engaged to investigate the activity and confirmed that an unauthorized actor obtained the credentials for the VPN account and used them to access its network environment. Files were copied in the attack, the review of which was completed on June 5, 2026. The file review confirmed that the impacted data included names, dates of birth, Social Security numbers, driver’s license numbers, other ID numbers, clinical/treatment information, lab results, prescription information, provider information, medical documents, ultrasound images, copies of identification...

Read More
Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit
Jul17

Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit

Charlotte-Mecklenburg Hospital Authority, doing business as Atrium Health, has agreed to pay up to $1,800,000 to settle a class action lawsuit stemming from its use of pixels and other tracking technologies on its MyAtriumHealth (formerly called MyCarolinas) patient portal. North Carolina-based Atrium Health operates a dozen hospitals in North and South Carolina, along with more than 900 care facilities in the two states. Like many health systems, Atrium Health used tracking technologies on its patient portal. These tools have important uses for website operators; however, their use on healthcare websites risks impermissible disclosures of sensitive data. When these tools are added to authenticated web pages such as patient portals, patients’ protected health information may be disclosed to the third-party providers of the tools, such as Meta (Facebook) and Google. Following an investigation, Atrium Health determined that between January 1, 2015, and July 31, 2019, the protected health information of up to 585,959 patients may have been impermissibly disclosed to third parties as a...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist