25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Acuity HIPAA Compliant?
Jan11

Is Acuity HIPAA Compliant?

Acuity is HIPAA compliant for covered entities and business associates that subscribe to a HIPAA-enabled Powerhouse or Enterprise account, configure the account to support HIPAA compliance, and disable non-compliant integrations and services. Depending on if and how payments are accepted via Acuity, it may also be necessary to change payment processors. Acuity is a versatile online scheduling solution that was acquired by Squarespace in 2019. Acuity Scheduling can be used with – or independently of – Squarespace websites to schedule appointments, send automated text and email reminders, and process payments. It also integrates with many client engagement, video conferencing, and accounting solutions to increase productivity and efficiency. When using Acuity to create, receive, store, or transmit personal information that is considered Protected Health Information (PHI) under HIPAA, it is necessary for Acuity to be HIPAA compliant. Acuity states it supports HIPAA compliance, but only under certain conditions. These conditions include subscribing to a Powerhouse or...

Read More
Eskenazi Health Pays $2.5 Million to Resolve Class Action Data Breach Lawsuit
Jan10

Eskenazi Health Pays $2.5 Million to Resolve Class Action Data Breach Lawsuit

Eskenazi Health has agreed to settle litigation stemming from an August 2021 ransomware attack in which the protected health information of more than 1.5 million patients was compromised. The ransomware attack was detected on or around August 4, 2024, when files were encrypted on its systems. The forensic investigation confirmed that a ransomware group first accessed its systems on May 19, 2021, and disabled its security systems, allowing them to remain in its network undetected. The initial investigation found no evidence of data theft; however, data exfiltration was later identified. Data stolen in the attack included names, addresses, telephone numbers, email addresses, dates of birth, medical record numbers, patient account numbers, diagnoses, clinical information, insurance information, prescriptions, driver’s license numbers, passport numbers, face photographs, Social Security numbers, and credit card information. Patients were notified about the data breach in November 2021 and were offered complimentary credit monitoring services. Eskenazi Health was able to recover the...

Read More
BayMark Health Services Notifies Patients About October Ransomware Attack
Jan10

BayMark Health Services Notifies Patients About October Ransomware Attack

Texas-based BayMark Health Services, North America’s largest provider of substance use disorder treatment and recovery services and a provider of administrative services to BAART Programs, Healthcare Resource Centers, and MedMark Treatment Centers, has started notifying patients that some of their protected health information was compromised in a recent cyberattack. According to the patient notification letters, BayMark Health Services discovered the cyberattack on October 11, 2024, when its IT systems were disrupted. The forensic investigation confirmed that an unauthorized third party had access to its network for almost 3 weeks between September 24, 2024, and October 14, 2024. During that time, the threat actor accessed and acquired files containing patient data. BayMark Health Services has reviewed the affected files and confirmed that they contained information such as patient names, dates of birth, services received, dates of service, Social Security numbers, driver’s license numbers, health insurance information, diagnostic and treatment information, and treating provider...

Read More
Patch Warning: Critical Ivanti Connect Secure Zero-day Exploited
Jan10

Patch Warning: Critical Ivanti Connect Secure Zero-day Exploited

Ivanti has released patches for two Connect Secure vulnerabilities including a critical zero-day remote code execution vulnerability that is being actively exploited in the wild to install malware. The first instances of exploitation are believed to have occurred in mid-December. The vulnerability was identified by Ivanti after the Ivanti Integrity Checker Tool (ICT) revealed the presence of malware on users’ appliances. The malware was installed after a threat actor exploited a previously unknown remote code execution flaw, which is being tracked as CVE-2025-0282 and has a CVSS severity score of 9.0. The critical stack buffer overflow flaw affects all Ivanti Connect Secure (Pulse Secure) VPN appliances running versions 22.7R2 through 22.7R2.5, Ivanti Policy Secure versions 22.7R1 through 22.7R1.2, and Ivanti Neurons for ZTA Gateways versions 22.7R2 through 22.7R2.3, although to date, the flaw only appears to have been exploited to compromise Ivanti Connect Secure appliances. A second stack buffer overflow flaw has also been patched, although it is not currently being exploited....

Read More
Eastern Idaho Public Health Discovers Insider Data Breach
Jan09

Eastern Idaho Public Health Discovers Insider Data Breach

Eastern Idaho Public Health has discovered an insider data breach, Pacific Pulmonary Medical Group has identified unauthorized access to its scheduling software, and Ingham County Medical Care Facility (Dobie Road) said patient data was accessed in a security incident at its electronic health records portal manager. Eastern Idaho Public Health Discovers Insider Data Breach Eastern Idaho Public Health has started notifying certain patients that one of its former employees has accessed their medical records without authorization. When unauthorized access to medical records was suspected, a review was conducted of the employee’s access logs and interviews were conducted with staff members. The employee was discovered to have viewed patient records, specifically patient clinic notes. The information potentially viewed included health screening information, patient histories, assessments, orders, and test results. Eastern Idaho Public Health was able to confirm that copies of the records had not been made and Eastern Idaho Public Health is confident that the information in the medical...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist