25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Two California Medical Groups Announce Data Breaches
Mar04

Two California Medical Groups Announce Data Breaches

Data breaches have recently been announced by two California medical groups – Valley Radiology Consultants Medical Group, which serves San Diego County, and Nephrology Associates Medical Group, which serves the Riverside and San Bernardino counties. Valley Radiology Consultants Medical Group Valley Radiology Consultants Medical Group in California has announced a security incident and data breach that was first identified on September 15, 2025. Immediate action was taken to secure its network, and third-party cybersecurity experts were engaged to determine the nature and scope of the unauthorized activity. The investigation confirmed unauthorized access to its network and files containing patient information. On February 18, 2026, the file review was concluded, and Valley Radiology Consultants Medical Group obtained the final list of individuals to notify. There is currently no substitute data breach notice on its website, and the notice submitted to the California Attorney General has the types of data involved redacted. Individual notices include the types of information...

Read More
Insight Hospital and Medical Center Announces Cyberattack & Data Breach
Mar03

Insight Hospital and Medical Center Announces Cyberattack & Data Breach

Data breaches have been announced by Insight Hospital and Medical Center in Chicago and Community Health Action of Staten Island. BlueCross BlueShield of Tennessee has confirmed it was one of the healthcare organizations affected by the Conduent Business Services data breach. Insight Hospital and Medical Center Insight Hospital and Medical Center in Chicago has announced a data security incident that was first identified in September 2025.  Unusual activity was identified within its IT environment, and the forensic investigation confirmed unauthorized access to its network between August 22, 2025, and September 11, 2025. The data review is ongoing to determine the individuals affected and the data involved; however, the likely information compromised in the incident may include names, dates of birth, Social Security numbers, passport numbers, financial account information, treatment-related information, and health insurance information. Notification letters will be mailed to the affected individuals when the data review is completed. Two threat groups have claimed attacks on...

Read More
Senate HELP Committee Advances Healthcare Cybersecurity Bill
Mar03

Senate HELP Committee Advances Healthcare Cybersecurity Bill

The Senate Health, Education, Labor, and Pensions (HELP) Committee has advanced the Health Care Cybersecurity and Resiliency Act, with a 22-1 vote in favor of the bill. The Health Care Cybersecurity and Resiliency Act was first introduced in November 2025, followed by a largely unchanged bill that was reintroduced in December 2025. As the name suggests, the bill seeks to introduce new cybersecurity requirements to strengthen healthcare cybersecurity. Many of the bill’s requirements were included in the proposed update to the HIPAA Security Rule issued by the HHS’ Office for Civil Rights in the final days of the Biden administration. It remains to be seen whether the current administration will push ahead with the HIPAA Security Rule update, which has proven to be unpopular with health systems and provider associations. The Health Care Cybersecurity and Resiliency Act was proposed by a bipartisan group of senators – HELP Committee Chair Sen. Bill Cassidy (R-LA), and Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX), and could attract more support than the...

Read More
Ransom Demands Increase as Ransom Payments Fall to Record Low
Mar03

Ransom Demands Increase as Ransom Payments Fall to Record Low

Faced with diminishing returns from their attacks, ransomware groups conducted attacks in greater volume in 2025 and increased their ransom demands. In 2025, the number of claimed attacks increased by 50% year-over-year to the highest ever level; however, ransomware payments decreased by 8% year-over-year to $820 million, down from $892 million in 2024 and $1,023 million in 2023, according to the blockchain analytics firm Chainalysis. The analysis reveals that ransomware groups are having to work much harder due to fewer victims choosing to pay ransoms. In 2024, 64% of victims of ransomware attacks paid the ransom to recover their data, prevent a data leak, or both. In 2025, the percentage of victims paying ransoms fell to a record low of just 28%. In addition to conducting more attacks, ransom demands have increased. Chainalysis reports a 368% increase in median payment size, rising from $12,738 in 2024 to $59,556 in 2025. Law enforcement operations appear to be having a positive effect, with ransom payments falling for two consecutive years. While there have been major operations...

Read More
Free Webinar: How to Avoid HIPAA Fines for HIPAA Violations
Mar03

Free Webinar: How to Avoid HIPAA Fines for HIPAA Violations

Incidents are an expected part of healthcare operations, even in the strongest organizations. Regulatory risk is rarely caused by the incident alone, but rather by gaps in how incidents are identified, documented, escalated, and resolved across teams. The real difference is how quickly and consistently your team can detect, document, and respond. This webinar focuses on building a repeatable incident management approach that supports consistent handling across privacy, safety, clinical, and patient driven events, while keeping you prepared for audits and regulatory scrutiny. Join Compliancy Group for an educational webinar on incident management and its role in a strong, defensible compliance program. Webinar attendees Will learn how to: Define what qualifies as a healthcare incident and apply consistent criteria Categorize incidents across privacy, safety, clinical events, and patient reported concerns Align incident management with the seven elements of an effective compliance program Build reporting and response workflows that support documentation, corrective action, and a...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist