25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Vi Living Settles Class Action Data Breach Lawsuit
Jan27

Vi Living Settles Class Action Data Breach Lawsuit

Classic Resident Management Limited Partnership, which does business as Chicago-based Vi Living, the operator of 10 continuing care retirement communities in Arizona, California, Colorado, Florida, Illinois, and South Carolina, has agreed to settle a class action data breach lawsuit for an undisclosed sum. A network intrusion was detected on or around March 13, 2023, and it was confirmed that an unauthorized third party accessed files containing personal data and potentially copied that information from the network. The compromised data included names, addresses, dates of birth, Social Security numbers, financial information, and medical information. Up to 61,425 individuals were affected and had their information exposed or stolen and were notified about the data breach on September 9, 2023. A class action lawsuit Givony, et al. v. Classic Residence Management Limited Partnership d/b/a Vi – was filed in the Circuit Court of Cook County, Illinois that claimed the breach could have been prevented if reasonable and appropriate cybersecurity measures had been implemented. The lawsuit...

Read More
Recent HHS-OIG Exclusions and Penalties for Employing Excluded Individuals
Jan27

Recent HHS-OIG Exclusions and Penalties for Employing Excluded Individuals

One of the consequences of convictions in enforcement actions by the Department of Health and Human Services Office of Inspector General (HHS-OIG) and prosecutions by the Department of Justice is exclusion from participating in federal health care programs. The HHS OIG Exclusions List includes individuals and organizations that have received mandatory exclusion, such as being found guilty of Medicare or Medicaid fraud, patient abuse or neglect, or financial misconduct, and permissive exclusions, which come from convictions for fraud in non-healthcare programs and obstruction of an investigation or HHS-OIG audit. The length of the exclusion depends on the nature of the offense. For some offenses, there is no minimum exclusion period while others have a minimum exclusion period is 5 years for a first offense up to permanent exclusion for multiple offenses. Recent enforcement actions that have resulted in individuals being added to the HHS-OIG exclusion list include violations of the False Claims Act (FCA), the Anti-Kickback Statute (AKS), and the Physician Self-Referral (Stark) Law....

Read More
DOJ Drops Charges Against Surgeon Who Exposed Continuing Transgender Care at Texas Children’s
Jan27

DOJ Drops Charges Against Surgeon Who Exposed Continuing Transgender Care at Texas Children’s

The Department of Justice (DOJ) has dropped all charges against Dr. Ethan Haim, a former surgeon at Texas Children’s Hospital who disclosed details of continuing transgender care on minors at Texas Children’s Hospital after the hospital had publicly stated that gender-affirming care for minors had stopped being provided. Haim faced multiple charges related to accessing the medical records of children who were not under his care and sharing that information with a reporter to blow the whistle on the practices. Haim maintained there was no wrongdoing, and both Haim and the reporter maintained all personally identifiable information in the shared documents had been redacted. Haim said his decision to speak with a reporter and blow the whistle on the continuing transgender care at Texas Children’s was because he felt the practices amounted to child abuse. At the time the alleged gender-affirming care was provided at Texas Children’s there was no federal or state law prohibiting that care. State laws have since been enacted prohibiting gender-affirming care for minors in Texas. The DOJ...

Read More
Digital Marketing for Doctors
Jan25

Digital Marketing for Doctors

Digital marketing for doctors can be a cost-effective way to generate leads, convert leads to new patients, and retain patients for as long as treatment is required. However, when adopting a digital marketing strategy for doctors, it is important to be aware of federal and state regulations that govern the content and frequency of digital communications. There is a wide range of “opinions” about how many new patients a doctor needs to acquire per month in order for a medical office to remain sustainable. Many opinions ignore factors such as relationships with Primary Care Physicians and insurance networks, the type of healthcare services provided, and how healthcare services are provided (i.e., remotely). The location of a medical office and health inequalities in that location can also be factors. Consequently, when an “opinion” advocates a digital marketing strategy for doctors in order to acquire “xx” new patients per month, the opinion often goes overboard on the number of marketing activities required and/or sets unrealistic expectations for the power of digital marketing for...

Read More
The Ransomware Groups Targeting Healthcare Organizations
Jan24

The Ransomware Groups Targeting Healthcare Organizations

Research recently published by Black Kite has confirmed that ransomware groups are disproportionately targeting the healthcare sector, with some ransomware-as-a-service groups having a strong healthcare focus. The groups with the biggest healthcare focus were Everest, which conducted 25% of its attacks on healthcare organizations, followed by INC Ransom (21.7%), Monti (20.8%), Rhysida (18.5%), BianLian (15%), and Qilin (14%) and Black Suit (14%). Healthcare is the third-most targeted sector behind manufacturing and professional services, according to Black Kite’s Research Intelligence Team (BRITE), which reports a sizeable increase in healthcare ransomware attacks in 2024. From Q1, 2023, to Q3, 2023, healthcare was the 6th or 7th most targeted sector; however, there was a jump in attacks in Q4, 2023 when healthcare rose to the third most targeted sector and has remained in third spot ever since. Healthcare ransomware attacks increased throughout 2024. BRITE identified 66 healthcare victims in Q1, 87 in Q2, 99 in Q3, and 121 in Q4, 2024, when 8.22% of all ransomware attacks were on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist