25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse
Dec11

OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse

The U.S. Department of  Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged HIPAA Privacy and Security Rule violations with the Puerto Rican healthcare clearinghouse, Inmediata Health Group. The alleged HIPAA violations were discovered during an investigation of the exposure of individuals’ electronic protected health information (ePHI) via the Internet. OCR received a complaint on November 16, 2018, alleging patients’  ePHI held by Inmediata was accessible over the Internet. OCR’s investigation substantiated the allegations and determined that between May 16, 2016, and January 23, 2019, the ePHI of 1,565,338 individuals was publicly available on the Internet and had been indexed and cached by search engines. Inmediata analyzed the exposed data and determined that names, dates of birth, home addresses, Social Security numbers, claims information, diagnosis/conditions, and other treatment information had been exposed online. OCR determined that the exposure of ePHI violated the HIPAA Privacy Rule, and HIPAA Security Rule violations were...

Read More
HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability
Dec10

HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability

A New York healthcare provider that experienced a breach of the personal and protected health information of 242,641 New Yorkers has been ordered to pay a financial penalty of $550,000 and take steps to strengthen its data security practices. HealthAlliance serves patients in Ulster and Delaware counties in New York State and operates HealthAlliance Hospital in Kingston, Margaretville Hospital in Margaretville, and Mountainside Residential Care Center in Margaretville. In July 2023, HealthAlliance was notified by its vendor, Citrix, that three vulnerabilities had been identified in its NetScaler networking products, including the critical zero-day vulnerability CVE-2023-3519 that affected two of the NetScaler products deployed on the HealthAlliance network. The cybersecurity advisory explained that threat actors were actively exploiting the vulnerability to deploy a web shell, that gave them remote access to victims’ networks. HealthAlliance attempted to patch the vulnerabilities but was unable to install the patch for the CVE-2023-3519 due to technical issues. HealthAllinace...

Read More
Cyberattack on Fort Worth Revenue Cycle Management Firm Affects 77,000 Individuals
Dec10

Cyberattack on Fort Worth Revenue Cycle Management Firm Affects 77,000 Individuals

Data breaches have been announced by the revenue cycle management company ESHA Inc., the pulmonary rehabilitation provider Citadel of Northbrook, the health IT company Datavant Group, and the Florida dental practice operator Smile Design Management. ESHA, Inc., Texas ESHA, Inc., a Fort Worth, TX-based revenue cycle management company, has notified 76,922 individuals that some of their personal and protected health information was potentially viewed and/or copied in a security incident over the summer. Unauthorized access to its server infrastructure was detected on July 19, 2024, and the servers were immediately taken offline to prevent further unauthorized access. Digital forensics specialists were engaged to investigate the incident and determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized actor accessed its servers from July 13 to July 17, 2024. The file review was completed on or around September 16, 2024, and individual notifications were mailed to the affected individuals on November 15, 2024. Complimentary credit...

Read More
Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack
Dec09

Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack

Beth Israel Lahey Health’s Anna Jaques Hospital in Newburyport, Massachusetts, has recently notified regulators and patients about a cyberattack and data breach that occurred on Christmas Day in 2023. According to the notification sent to the Maine Attorney General, the personal information of 316,342 individuals was potentially compromised in a cyberattack that caused disruption to some of its systems – a phrase commonly used to describe a ransomware attack, although ransomware was not mentioned in the notification. Anna Jaques Hospital did not state in the notification letters when the attack was detected or when its network was compromised. The Maine Attorney General’s website erroneously states the breach occurred on December 25, 2024, and was discovered on December 22, 2024. At the time of writing, there is no breach listed on the HHS’ Office for Civil Rights website. Data breaches tend to be added to the OCR breach portal up to two weeks after OCR receives the notification. Anna Jaques Hospital explained in the notification letter that when the incident was detected, the...

Read More
Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks
Dec09

Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks

Over Thanksgiving weekend, Watsonville Community Hospital and PIH Health in California fell victim to ransomware attacks and continue to experience disruption to their computer systems. Jefferson Dental Center in Indiana has confirmed it has recovered from a November 15, 2024, ransomware attack. Watsonville Community Hospital Grappling with November 29 Ransomware Attack Watsonville Community Hospital in California is currently dealing with a cyberattack and is facing continued disruption to its computer systems. The hospital has implemented downtime protocols due to computer systems being unavailable and is recording patient information manually on charts and issuing paper prescriptions while its IT team and third-party IT specialists work to restore its computer systems. The hospital’s emergency department remains open, and the full spectrum of care continues to be provided; however, patients are facing delays. The cyberattack caused network disruption on November 29, 2024, which has continued for more than a week. The last update on the cyberattack on the hospital’s website was...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist