25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

20,000-Record Data Breaches Reported by Axis Health System & Gandara Mental Health Center
Nov06

20,000-Record Data Breaches Reported by Axis Health System & Gandara Mental Health Center

Data breaches have recently been announced by Axis Health System in Colorado, Gandara Mental Health Center in Massachusetts, Valleygate Dental Surgery Centers in North Carolina, and Family Medical Center in Maryland. Axis Health System Southwest Colorado Mental Health Center, doing business as Axis Health System, has discovered unauthorized access to its computer systems. Suspicious activity was detected on August 26, 2024, and steps were immediately taken to contain the incident. The forensic investigation confirmed that an unauthorized third party had access to its internal network between July 9, 2024, and September 4, 2024. During that time, there may have been unauthorized access to files containing patient information and that information may have been exfiltrated. The file review confirmed that the protected health information of 23,385 patients had been exposed. The affected information varied from individual to individual and may have included one or more of the following: names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, driver’s...

Read More
Kaiser Permanente, Soliant Health & Potomac Medical Aesthetics Report Email Breaches
Nov06

Kaiser Permanente, Soliant Health & Potomac Medical Aesthetics Report Email Breaches

Email-related HIPAA data breaches have been reported by Kaiser Permanente in California, Soliant Health in Georgia, and Potomac Medical Aesthetics in Maryland. Kaiser Permanente Kaiser Permanente has recently discovered unauthorized access to two employee email accounts. The account compromises were detected on September 3, 2024, and the accounts were immediately secured and passwords were reset. The investigation confirmed that the accounts contained the protected health information of patients and members in Southern California, including first and last names, dates of birth, medical record numbers, and medical information, but not Social Security numbers, financial information, or usernames/passwords. While there are no indications that any of the exposed information has been misused, Kaiser Permanente has recommended that the affected individuals should monitor their accounts, explanation of benefits statements, and credit reports for signs of misuse of their personal information. Kaiser Permanente said it is taking steps to prevent similar incidents in the future, including...

Read More
HHS-OIG Settles Patient Dumping Statute Violations with Three Healthcare Providers
Nov06

HHS-OIG Settles Patient Dumping Statute Violations with Three Healthcare Providers

In the past two months, the Department of Health and Human Services Office of Inspector General has settled alleged violations of the federal patient dumping statute – The Emergency Medical Treatment and Labor Act (EMTALA) – with three healthcare providers. The settlements included penalties ranging from $60,000 to $100,000. EMTALA was part of the Consolidated Omnibus Budget Reconciliation Act (COBRA) that was passed in 1986 and requires hospitals that receive payments from the HHS’ Centers for Medicare and Medicaid Services (CMS) to provide a medical screening examination (MSE) to all patients seeking treatment for a health condition regardless of the patient’s legal status or ability to pay. Stabilizing treatment must be provided unless the patient’s condition requires the patient to be transferred to another healthcare provider better equipped to administer stabilizing treatment. Organizations found to have violated EMTALA can face stiff financial penalties and, potentially, exclusion from federally funded healthcare programs. Big South Fork Medical Center In September,...

Read More
Memorial Hospital and Manor Recovering from Ransomware Attack
Nov05

Memorial Hospital and Manor Recovering from Ransomware Attack

Memorial Hospital and Manor in Georgia warned patients about a ransomware attack less than 24 hours after the attack was detected. Cornerstone Healthcare Group Management Services has notified patients about a cyberattack detected in mid-December 2023. Memorial Hospital and Manor Recovering from Ransomware Attack A small rural hospital in Georgia has alerted patients about a recent ransomware attack that has prevented access to its IT systems, including its electronic medical record (EMR) system, email system, and website. Memorial Hospital and Manor, an 80-bed hospital and 107-bed long-term care facility in Bainbridge, Georgia, issued a statement on its Facebook page on November 3, 2024, warning patients that a ransomware attack was detected in the morning of November 2, 2024. The hospital told patients that while access to IT systems has been disrupted, care continues to be provided to patients and the attack is not having any impact on the level or quality of care; however, since the hospital has switched to downtime procedures and is recording patient information manually,...

Read More
Texas Attorney General Sues 2 Texas Physicians for Providing Gender-Affirming Care to Minors
Nov05

Texas Attorney General Sues 2 Texas Physicians for Providing Gender-Affirming Care to Minors

Texas Attorney General Ken Paxton is actively enforcing Senate Bill 14 (SB 14) which prohibits physicians and other licensed medical professionals in the state of Texas from providing gender-affirming care to patients under 18 years of age. At least two lawsuits have now been filed against physicians accusing them of violating state law by providing gender-affirming care to minors. SB14 took effect on September 1, 2023, and prohibits medical providers in the state of Texas from providing treatments for gender dysphoria to minors, including puberty blockers, hormone therapies, and transition surgeries, and health plans are not permitted to provide coverage for those treatments. The law does not extend to mental health care. Under SB14, any medical professional who provides care in violation of state law can face financial penalties and have their medical license revoked by the Texas Medical Board. Last month, Attorney General Paxton filed two lawsuits against physicians alleged to have violated state law by prescribing and distributing puberty blockers and hormone therapies to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist