25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Mulkay Cardiology Consultants Agrees Settlement to Resolve Ransomware-related Lawsuit
Jan29

Mulkay Cardiology Consultants Agrees Settlement to Resolve Ransomware-related Lawsuit

In Early November 2023, Mulkay Cardiology Consultants in New Jersey announced it had fallen victim to a ransomware attack that involved unauthorized access to the protected health information of up to 79,582 individuals. Legal action was taken by victims of the breach and a settlement has been agreed to bring the litigation to an end. The forensic investigation determined a threat actor had access to its network from September 1 through September 5, 2023, and exfiltrated files containing patient data. The stolen data included names, addresses, dates of birth, Social Security numbers, driver’s license numbers or state IDs, medical treatment information, and health insurance information. The NoEscape ransomware group claimed responsibility for the attack and started leaking the stolen data on its dark web data breach site, although the listing was later removed. Multiple class action lawsuits were proposed in response to the breach which were consolidated into a single lawsuit – Wilkins, et al. v. Mulkay Cardiology Consultants at Holy Name Medical Center PC, et al – which was...

Read More
More Than 1.7 Billion Individuals Had Personal Data Compromised in 2024
Jan29

More Than 1.7 Billion Individuals Had Personal Data Compromised in 2024

There was a slight fall (1%) in data compromises in 2024, although only 44 fewer than last year’s record-breaking total. There was not a corresponding fall in the number of victims of data compromises, with victim notices increasing by 312% from 419 million notices in 2023 to 1,728,519,397 in 2024, according to the 2024 Annual Data Breach Report from the Identity Theft Resource Center (ITRC). The vast majority of data compromises (80%) in 2024 were caused by cyberattacks, with those incidents accounting for 93% of breach notices, followed by system and human error, supply chain attacks, and physical attacks. The massive increase in victim notices was largely due to a handful of mega data breaches. In 2024, 6 data breaches were reported that each involved more than 100 million records. While the data breach at Change Healthcare was the largest healthcare data breach in history, involving 190 million compromised healthcare records, it only ranked in third place last year due to two colossal data breaches. A breach at Advance Auto Parts Inc. took second spot with 380 million consumer...

Read More
Settlement Resolves Rise Interactive Media & Analytics Class Action Data Breach Lawsuit
Jan29

Settlement Resolves Rise Interactive Media & Analytics Class Action Data Breach Lawsuit

The digital marketing agency Rise Interactive Media & Analytics has agreed to settle a class action lawsuit filed in response to a November 2022 cyberattack. Rise Interactive Media & Analytics worked with RGH Enterprises, which does business as Edgepark Medical Supplies, which had data compromised in the cyberattack such as names, email addresses, phone numbers, provider information, diagnoses, expected delivery dates, and health insurance information. Rise Interactive reported the data breach to the HHS’ Office for Civil Rights as involving the protected health information of 54,509 individuals. Notification letters were issued by Edgepark Medical Supplies in February 2023. A class action lawsuit – Roper, et al. v. Rise Interactive Media & Analytics LLC – was filed on behalf of Tiffany Roper by Wolf Haldenstein Adler Freeman & Herz LLC in the U.S. District Court of the Northern District of Illinois Eastern Division soon after the notification letters were issued. The lawsuit alleged Rise Interactive was at fault for the data breach due to the failure to...

Read More
SonicWall & Apple Issue Patches for Actively Exploited Zero-Days
Jan28

SonicWall & Apple Issue Patches for Actively Exploited Zero-Days

Hackers are exploiting a critical zero-day vulnerability in SonicWall Secure Mobile Access (SMA) 1000 series appliances. SonicWall customers should ensure they update their firmware to the latest patched version as soon as possible to prevent exploitation of the flaw. The vulnerability is tracked as CVE-2025-23006 and has a CVSS severity score of 9.8 out of 10. The pre-authentication remote code execution vulnerability is in the SMA1000 Appliance Management Console (AMC) & Central Management Console (CMC). The vulnerability is due to the deserialization of untrusted data. The SonicWall Firewall and SMA 100 series products are not affected by the vulnerability. Under certain conditions, an unauthenticated attacker can exploit the vulnerability to execute arbitrary commands on the operating system. Researchers at Microsoft Threat Intelligence identified activity associated with the exploitation of the flaw. It is currently unclear to what extent the flaw is being exploited in the wild. SonicWall appliances are attractive targets for cybercriminals, and several ransomware groups...

Read More
Frederick Health Recovering from Ransomware Attack
Jan28

Frederick Health Recovering from Ransomware Attack

Frederick Health in Maryland is investigating a ransomware attack, Holdrege Memorial Homes in Nebraska has mailed notification letters to individuals affected by a 2023 data breach, and Square Medical Group in Massachusetts has identified an email breach at an IT vendor. Frederick Health Recovering from Ransomware Attack Frederick Health Medical Group in Maryland announced on January 27, 2025, that it is currently dealing with a ransomware attack that forced it to take its systems offline. The attack is disrupting patient services due to the lack of access to IT systems, resulting in delays to certain services. Frederick Health has confirmed that all its facilities remain open with care provided using established backup and other downtime processes. Most appointments are continuing as scheduled. Frederick Health is working with third-party cybersecurity experts to investigate the breach, determine the extent of unauthorized access, and bring its IT systems back online quickly and safely while prioritizing patient care. The primary focus is restoring its IT systems; however, the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist