25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Releases Video on HIPAA Security Rule Risk Management Requirements
Apr09

OCR Releases Video on HIPAA Security Rule Risk Management Requirements

Earlier this year, Paula M. Stannard, Director of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), provided an update on OCR’s enforcement priorities in 2026 and confirmed that OCR’s risk analysis enforcement initiative will continue, and that it will evolve to also target noncompliance with the risk management requirement of the HIPAA Security Rule. The risk analysis provision – § 164.308(a)(1)(ii)(A) – requires HIPAA-regulated entities to “Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by the covered entity or business associate.” OCR has previously issued guidance on the risk analysis requirement, and has issued a risk assessment tool for small- and medium-sized entities to guide them through the process of comprehensively assessing risks to ePHI. A risk analysis is one of four required implementation specifications under the security management process of the administrative...

Read More
New Jersey Long Term Care Pharmacy Data Breach Affects 133,800 Patients
Apr09

New Jersey Long Term Care Pharmacy Data Breach Affects 133,800 Patients

The New Jersey long-term care pharmacy Innovative Pharmacy Packaging Corp (IPPC Inc), and the affiliated entities IPPC of New York LLC, and Innovative Pharmacy LLC have confirmed in a breach report to the HHS’ Office for Civil Rights (OCR) that the protected health information of 133,862 patients has been exposed and potentially obtained in a recent security incident. IPPC identified anomalous network activity in September 2025 and launched an investigation to determine the nature and scope of the activity. The forensic investigation confirmed that an unauthorized third party accessed its network between September 18, 2025, and September 19, 2025, and exfiltrated files from its network. IPPC conducted a review of the affected files, which concluded on February 9, 2026, when it was confirmed that they contained a range of personal and protected health information. The types of information involved vary from individuals to individual and may include names in combination with dates of birth, driver’s license/ government-issued identification numbers, Medicare/Medicaid...

Read More
2025 Losses to Cybercrime Exceeded $20 Billion
Apr08

2025 Losses to Cybercrime Exceeded $20 Billion

In 2025, another unwanted record was set for losses to cybercrime, with almost $21 billion in reported losses, beating the previous record of $16.6 in losses set in 2024 by 26%, according to the Federal Bureau of Investigation (FBI) Internet Crime Report 2025. The report was compiled based on complaints filed with the FBI’s Internet Crime Complaint Center (IC3), which topped 1 million for the first time, increasing from 859,000 complaints in 2024. This is the 25th year that the FBI has released its annual report, which started with a few thousand complaints filed per month to an average of almost 3,000 complaints per day in 2025. The increase in losses was largely driven by an increase in losses to investment fraud ($8,648,617,756), which was the largest cause of losses in 2025, followed by business email compromise – BEC – ($3,046,598,558) and tech support scams ($2,134,675,818). In terms of complaint volume, phishing topped the list (191,561 complaints), followed by extortion (89,129 complaints), investment fraud (72,984 complaints), and personal data breaches (67,456),...

Read More
OrthopedicsNY Settles Class Action Data Breach Lawsuit for $1.45M
Apr08

OrthopedicsNY Settles Class Action Data Breach Lawsuit for $1.45M

A $1,450,000 settlement has been agreed upon to resolve a class action lawsuit against the New York orthopedic medicine and surgery practice OrthopedicsNY. The class action complaint was filed in response to a December 2023 ransomware attack and data breach that exposed the personal and electronic protected health information of 656,086 patients. OrthopedicsNY, which operates almost 20 clinics in the Capital Region in New York State, was attacked by the INC Ransom threat group on or around December 28, 2023. Prior to encrypting files, INC Ransom exfiltrated sensitive patient data, including names, contact information, financial information, protected health information, Social Security numbers, passport numbers, and driver’s license numbers. The affected individuals were notified on November 4, 2024. Several class action lawsuits were filed in response to the data breach, which were consolidated in a single action – Michael Sayers, et al. v. OrthopedicsNY, LLP – in the Circuit Court of the 17th Judicial Circuit in and for Broward County, Florida. The plaintiffs alleged...

Read More
Data Breaches Reported by Southern Illinois Dermatology; Heart South Cardiovascular Group
Apr08

Data Breaches Reported by Southern Illinois Dermatology; Heart South Cardiovascular Group

Patient data has potentially been compromised in data incidents at Southern Illinois Dermatology and Heart South Cardiovascular Group in Alabama. Southern Illinois Dermatology, Illinois Southern Illinois Dermatology has notified an unspecified number of individuals about a data security incident it identified on November 28, 2025. An investigation was immediately launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity experts. The investigation confirmed unauthorized access to parts of its network where patient data was stored, and potentially, files were copied from its network. The affected data was reviewed and found to contain personal information and protected health information, including full names, addresses, dates of birth, Social Security numbers, telephone numbers, email addresses, person numbers, and medical record numbers. The types of data involved vary from individual to individual. Notification letters started to be mailed to the affected individuals on April 2, 2026. Southern Illinois Dermatology has taken...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist