25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Digital Marketing for Dentists
Jan15

Digital Marketing for Dentists

‘Digital marketing for dentists can help resolve “empty chair” issues by attracting new patients in order to fill gaps in schedules. However, although digital marketing can be one of the most cost-effective methods of attracting new patients and increasing profitability, dentists must be careful not to violate HIPAA or other state and federal regulations. Each quarter, the American Dentistry Association Health Policy Institute publishes a report on the economic outlook and emerging issues in dentistry based on a survey of approximately one thousand private dentists (# responses varies each quarter). In the most recent report, one of the headline questions related to how busy dentists were over the last three months. An analysis of those who responded “not busy enough” later in the report shows that gaps in schedules affect all types of dentists – i.e., solo practitioners, group practices, and DSOs. While some empty chair issues are attributable to no shows and last minute cancellations, 37% of respondents to the question “what prevented your appointment schedule from reaching...

Read More
Jail Terms for HIPAA Violations by Employees
Jan15

Jail Terms for HIPAA Violations by Employees

Jail terms for HIPAA violations by employees are relatively rare, but there have been several cases where employee HIPAA violations have been referred to the Department of Justice and have resulted in financial penalties and jail time. Some cases that have resulted in jail terms for HIPAA violations by employees are listed below, along with cases where jail time for HIPAA violations has only narrowly been avoided. The penalties for HIPAA violations by employees can be severe, especially those involving the theft of protected health information. HIPAA violations by employees can attract a fine of up to $250,000 with a maximum jail term for violating HIPAA of 10 years plus a further 2 years for aggravated identity theft. Jail Term for Former Transformations Autism Treatment Center Employee In February 2017, a former behavioral analyst at the Transformations Autism Treatment Center (TACT) was discovered to have stolen the protected health information of patients following termination. Jeffrey Luke, 29, of Collierville, TN gained access to a TACT Google Drive account containing the PHI...

Read More
Tycon Medical Systems Reports Data Breach Affecting 112,847 Individuals
Jan15

Tycon Medical Systems Reports Data Breach Affecting 112,847 Individuals

Data breaches have been confirmed by Tycon Medical Systems, North Los Angeles County Regional Center, Mohawk Valley Cardiology, and Summa Health. Tycon Medical Systems Tycon Medical Systems, a Norfolk, Virginia-based home medical equipment provider and distributor, has experienced a breach of the protected health information of 112,847 individuals. A breach notification was sent to the Massachusetts Attorney General about a cybersecurity incident involving personal information; however, the breach notification lacks any detail about the nature of the breach such as when it was discovered or the types of information involved. There is currently no substitute breach notice on the Tycon Medical Systems website. The HHS’ Office for Civil Rights website lists the data breach as a hacking/IT incident involving a network server. The affected individuals started to be notified on December 30, 2024, and have been offered complimentary credit monitoring and identity theft protection services for 24 months, which include a $1,000,000 identity theft insurance policy and credit restoration...

Read More
Solara Medical Supplies Pays $3M to Settle Alleged HIPAA Security and Breach Notification Rule Violations
Jan15

Solara Medical Supplies Pays $3M to Settle Alleged HIPAA Security and Breach Notification Rule Violations

The HHS’ Office for Civil Rights (OCR) has announced that a settlement has been reached with a direct-to-patient distributor of medical products to resolve multiple violations of the HIPAA Rules. Solara Medical Supplies, LLC, a subsidiary of AdaptHealth, claims it is the largest American supplier of continuous glucose monitors, insulin pumps, and other supplies to patients with diabetes, and is a Medicare provider that partners with more than 300 insurance providers. Solara Medical Supplies sent a breach notification to OCR in November 2019 about a phishing incident that led to the email accounts of eight employees being accessed by an unauthorized individual between April 2019 and June 2019. Solara’s investigation confirmed the accounts contained the electronic protected health information (ePHI) of 114,007 individuals. Then, in January 2020, OCR was notified that while sending breach notification letters about that incident, 1,531 letters were sent to incorrect mailing addresses, resulting in a further breach of the protected health information (PHI) – demographic...

Read More
Dignity Health Lassen Medical Clinic Cyberattack Affects 65,482 Patients
Jan14

Dignity Health Lassen Medical Clinic Cyberattack Affects 65,482 Patients

Cyberattacks have been reported by Dignity Health Lassen Medical Clinic in California, The Baker Center for Children and Families in Massachusetts, and Golden Age Home Health in Oklahoma. Sidney Health Center in Montana and The Center for Child Development in Delaware have identified HIPAA breaches by employees. Dignity Health Lassen Medical Clinic Dignity Health Lassen Medical Clinic has notified 65,482 patients of its clinics in Red Bluff and Cottonwood in California that some of their protected health information has been exposed or stolen in a September 2024 cyberattack. The attack was detected on September 20, 2024, when its IT network was disabled. Prompt action was taken to prevent further unauthorized access, and the network was restored the following day. An investigation by a third-party cybersecurity vendor determined that between September 17 and September 20, 2024, files were copied from the network that contained patient data. The electronic medical record system was not involved, but the stolen files included patient data such as names, addresses, dates of birth,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist