25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Hacker Sentenced to 10 Years in Jail
Dec09

Healthcare Hacker Sentenced to 10 Years in Jail

A hacker who targeted multiple U.S. healthcare organizations, breached their networks, stole sensitive data, and attempted to extort them, has been sentenced to a decade in jail. Robert Purbeck, 45, an IT specialist who worked for Ada County in Idaho, hacked at least 19 organizations between 2017 and 2018 and stole the personal data of more than 132,000 individuals.  Purbeck, who used the monikers Lifelock and Studmaster, accessed victims’ networks using stolen credentials purchased on darknet marketplaces such as AlphaBay. Sensitive data was identified and exfiltrated and he demanded ransom payments to prevent the publication of the stolen data. One of the first U.S. victims was Family Medical Center in Griffin, Georgia. The credentials purchased by Purbeck allowed him to access the medical clinic’s network in June 2017 and exfiltrate the protected health information of more than 43,000 individuals, including names, addresses, dates of birth, and Social Security numbers. In February 2018, using darknet-purchased credentials, Purbeck accessed a server of the Police Department in...

Read More
$8.9 Million Data Breach Settlement Agreed by Elekta & Northwestern Memorial Healthcare
Dec06

$8.9 Million Data Breach Settlement Agreed by Elekta & Northwestern Memorial Healthcare

An $8.9 million settlement has been agreed to resolve a class action lawsuit over a cyberattack on the radiation therapy and radiosurgery equipment provider Elekta that exposed the protected health information of patients of Northwestern Memorial Healthcare in Illinois. The cyberattack on Elekta occurred between April 2 and April 20, 2021, and saw unauthorized individuals gain access to Elekta’s cloud-based radiology software and attempt to use ransomware to encrypt files. The attack affected several of its U.S-based customers, including Northwestern Memorial Healthcare, which reported that the data of up to 201,197 oncology patients had potentially been obtained in the attack. Lawsuits were filed in response to the data breach that named Carla Tracy, Darryl Bowsky, and. Deborah Harrington as plaintiffs, which were consolidated into a single action – Tracy v. Elekta Inc., et al – in the U.S. District Court for the Northern District of Georgia. The plaintiffs alleged negligence, negligence per se, intrusion upon seclusion/invasion of privacy, breach of implied contract...

Read More
VA Nurse Charged for Unlawfully Accessing a Patient’s Medical Records
Dec06

VA Nurse Charged for Unlawfully Accessing a Patient’s Medical Records

A Michigan Nurse at the U.S. Department of Veteran Affairs has been charged with unlawfully accessing and obtaining the medical records of a patient. Jessica Nicole Pitcher, 41, of Shelbyville, is alleged to have accessed and copied the medical records of a patient of the Veterans Affairs Medical Center in Battle Creek, Michigan, without authorization on or around November 27, 2023. The Health Insurance Portability and Accountability Act (HIPAA) sets standards covering the privacy and security of healthcare information, termed protected health information or PHI under HIPAA. There are strict rules concerning uses and disclosures of PHI, which may only be used or disclosed for purposes expressly permitted by the HIPAA Privacy Rule unless authorization is received from a patient. Healthcare professionals must abide by the HIPAA Rules and are not permitted to access the medical records of patients unless they have a valid work reason for doing so. The HIPAA Privacy Rule permits access to medical records for purposes related to treatment, payment, and healthcare operations. Nurses are...

Read More
OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265
Dec06

OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265

The HHS’ Office for Civil Rights (OCR) has announced another civil monetary penalty for a HIPAA-regulated entity to address non-compliance with the HIPAA Rules, its 7th of the year and the 15th enforcement action of 2024 to result in a financial penalty. The latest fine was imposed on Children’s Hospital Colorado Health System, a not-for-profit provider of healthcare services for children and young individuals at its main healthcare facility in Aurora, CO, and 22 other facilities in the Anschutz Medical Campus and throughout the State of Colorado. Children’s Hospital Colorado also has agreements with nursing schools and provides clinical opportunities for nursing students. On July 11, 2017, an unauthorized individual accessed a physician’s email account following a response to a phishing email. The email account contained the electronic protected health information (ePHI) of 3,370 patients. The email account was previously protected with 2-factor authentication; however, it was deactivated by the IT help desk and was not reactivated. The breach was reported to OCR, and an...

Read More
Mount Nittany Health Agrees $1.8 Million Settlement for Using Website Tracking Technologies
Dec06

Mount Nittany Health Agrees $1.8 Million Settlement for Using Website Tracking Technologies

Mount Nittany Health in Pennsylvania has agreed to pay $1.8 million to resolve a class action lawsuit that alleged sensitive patient data was shared with third parties such as Meta and Google without the knowledge or consent of patients. The plaintiffs alleged that Mount Nittany Health added tracking technologies such as pixels to its website and patient portal, which collected information about website visitors based on their interactions, such as the pages viewed and options chosen in forms. That information, which included identifiers such as IP addresses, was transferred to tech companies for marketing and advertising purposes without first obtaining user consent. The lawsuit alleged that the information collected by the tracking tools could be tied to individuals and it could be inferred they were patients of Mount Nittany Health and had or were being treated for a specific medical condition. The lawsuit alleged that around 74,000 patients had used the website and/or patient portal since 2007 and potentially had their sensitive information disclosed to third parties without...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist