25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is PHI in HIPAA?
Jan01

What is PHI in HIPAA?

PHI in HIPAA is an acronym for Protected Health Information – health information that is created, collected, maintained, or transmitted by a covered entity that relates to an individual’s past, present, or future physical or mental condition, treatment for the condition, or payment for the treatment, and that is protected by HIPAA from impermissible uses and disclosures. In addition to individuals’ health information being protected from impermissible uses and disclosures, HIPAA also applies to individually identifiable non-health information stored in the same designated record set as PHI that could identify the subject of the PHI or be used with other information stored in the same designated record set to identify the subject of the PHI. The application of HIPAA protections to non-health information can create misunderstandings about what information should be protected and when it should be protected (evidenced by multiple sources mistaking the “18 HIPAA identifiers” as PHI). This article aims to resolve potential misunderstandings about what is PHI in HIPAA by answering three...

Read More
Las Palmas Del Sol Healthcare Discovers 2-Year Insider Data Breach
Jan01

Las Palmas Del Sol Healthcare Discovers 2-Year Insider Data Breach

Cyberattacks have been announced by VisionPoint Eye Center in Illinois and Vickers Engineering in Michigan. Las Palmas Del Sol Healthcare has discovered a former employee has accessed patient records without authorization and may have disclosed patient information to other unauthorized individuals. El Paso Healthcare System (Las Palmas Del Sol Healthcare) El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare, has recently notified 1,854 patients about an insider data breach detected on February 23, 2024. A former employee was discovered to have accessed patients’ medical records without authorization and may have disclosed patient information to other unauthorized individuals. When unauthorized medical record access was detected, a review was conducted to determine the extent of the HIPAA breach. The employee was found to have accessed patient records without authorization between January 1, 2018, and March 12, 2021. The review of the records confirmed that the following information was viewed and potentially copied: name, address, date of birth, health plan...

Read More
EMR Vendor Reports Breach of Patient Data
Dec31

EMR Vendor Reports Breach of Patient Data

Data breaches have been announced by the electronic medical record company PracticeSuite, California Correctional Health Care Services, College Hospital Costa Mesa, and Western Montana Mental Health Center. PracticeSuite PracticeSuite, Inc., a Tampa, FL-based practice management software provider and electronic medical record company, has announced that a hacker accessed a data file on one of its servers on or around October 11, 2024. When the intrusion was detected, prompt action was taken to prevent further unauthorized access, and an investigation was launched to determine the extent of the unauthorized activity. The server was used by PracticeSuite for storage, and the review confirmed that it contained a data file that included the electronic medical records of patients of Texas ENT Specialists. No other systems were accessed by the hackers as the server was isolated from other parts of the network. The data review confirmed that the file contained names, dates of birth, social security numbers, addresses, diagnoses, clinical and treatment information, insurance details, and a...

Read More
Email Accounts Breached at DAP Health; Access TeleCare; Northwest Asthma and Allergy Center
Dec31

Email Accounts Breached at DAP Health; Access TeleCare; Northwest Asthma and Allergy Center

Hackers have gained access to email accounts and potentially obtained the data of patients of DAP Health, Borrego Health, Access TeleCare, and Northwest Asthma and Allergy Center. DAP Health and Borrego Health DAP Health in Palm Springs, CA, and its Borrego Springs, CA-based subsidiary Borrego Health, have recently notified patients about a cybersecurity incident detected on or around July 22, 2024. An investigation was launched to determine the cause of suspicious activity in its email system, and it was confirmed that an unauthorized third party accessed and/or acquired sensitive data contained in emails and file attachments. The review of the affected email accounts was completed on November 26, 2024. The information potentially stolen in the incident varied from individual to individual and may have included names, addresses, phone numbers, dates of birth, health insurance information, Social Security numbers, medical record numbers, passport numbers, Medicare/Medicaid numbers, patient IDs, medical treatment location, diagnoses, treatment and procedure information, medical...

Read More
Brightline Agrees to $7 Million Settlement to Resolve Class Action Data Breach Lawsuit
Dec30

Brightline Agrees to $7 Million Settlement to Resolve Class Action Data Breach Lawsuit

Brightline Inc., a Palo Alto, CA-based provider of behavioral healthcare services for children and their families, has agreed to settle a class action data breach lawsuit for $7 million. The lawsuit, Terrance Rosa et al. v. Brightline, Inc., was filed in the U.S. District Court for the Southern District of Florida in response to a January 2023 data breach that affected approximately 1 million individuals. Hackers exploited a zero-day vulnerability in file transfer software (GoAnywhere) used by Brightline, which gave them access to sensitive consumer data including names, Social Security numbers, and insurance information. The plaintiffs alleged that Brightline failed to implement reasonable and appropriate cybersecurity measures to protect sensitive consumer information and if those measures had been implemented, the data breach could have been prevented. Brightline chose to settle the lawsuit; however, it maintains there was no wrongdoing. Under the terms of the settlement, individuals who received a notification from Brightline that their information was involved in the data...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist