25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Two Men Indicted for Role in February 2024 Cyberattack on Cedars-Sinai
Oct23

Two Men Indicted for Role in February 2024 Cyberattack on Cedars-Sinai

Two Sudanese nationals have been charged for their role in a series of cyberattacks on corporate networks, government agencies, and critical infrastructure entities in the United States, including a February 2024 attack on Cedars-Sinai Medical Center in Los Angeles that caused patients to be diverted to alternative facilities for 8 hours. The two men – Ahmed Salah Yousif Omer, 22, and Alaa Salah Yusuuf Omer, 27 – are alleged members of an online cybercriminal group called Anonymous Sudan, a group that has been active since mid-January 2023 and has conducted more than 35,000 distributed denial-of-service (DDoS) attacks worldwide. While many cybercriminal groups are primarily financially motivated, Anonymous Sudan claims to be a hacktivist group that conducts attacks against targets it considers to be anti-muslim, in part in support of Palestine, although the group has attempted to extort money from some victims. Due to the sophistication of the group’s attacks and the financial resources required, there have been suggestions that the group has significant backing, and...

Read More
Patient Data Compromised in Email Breaches in Indiana, New York & Wisconsin
Oct23

Patient Data Compromised in Email Breaches in Indiana, New York & Wisconsin

Email accounts have been compromised in security incidents at Tower Clock Eye Center in Wisconsin, DMEScripts in Indiana, and General Physician, P.C. in New York. Tower Clock Eye Center Tower Clock Eye Center in Green Bay, Wisconsin, has identified unauthorized activity in its email system. A security breach was detected on July 9, 2024, and action was taken to prevent further unauthorized access. Third-party cybersecurity experts were engaged to investigate and determine the extent of the unauthorized activity. The investigation confirmed that a limited number of employee email accounts had been accessed by an unauthorized third party who may have viewed or obtained patient data. The breach was confined to email accounts, which were found to contain limited patient data. The types of data involved varied from individual to individual and may have included names in combination with one or more of the following: address, date of birth,  financial account number, payment card number, medical record number, patient ID or account number, Medicare number, Medicaid number, health...

Read More
Texas Doctor Sues HHS to Prevent Enforcement of Reproductive Health Care Privacy Rule
Oct23

Texas Doctor Sues HHS to Prevent Enforcement of Reproductive Health Care Privacy Rule

A lawsuit has been filed against the Department of Health and Human Services (HHS), HHS Secretary Xavier Becerra, the Office for Civil Rights (OCR), and OCR Director Melanie Fontes Rainer over the recent update to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to strengthen reproductive health care privacy. The HIPAA Privacy Rule to Support Reproductive Health Care Privacy Final Rule was published in the Federal Register on April 26, 2024, took effect on June 25, 2024, and the compliance date is December 23, 2024.  The new rule was introduced to strengthen privacy protections for reproductive healthcare information and prevent HIPAA-regulated entities from disclosing reproductive health care information to law enforcement when that information is sought to investigate or impose liability on individuals or healthcare providers for seeking, obtaining, or providing legal reproductive health care. The lawsuit was filed by attorneys from Alliance Defending Freedom in the United States District Court for the Northern District of Texas, Amarillo Division,...

Read More
September 2024 Healthcare Data Breach Report
Oct23

September 2024 Healthcare Data Breach Report

Apart from a blip in August, the number of healthcare data breaches reported each month has fallen from an annual high of 97 breaches in March 2024. September saw the lowest number of healthcare data breaches since May 2020, with just 34 data breaches of 500 or more records reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). In the first half of the year it was looking like another new record would be set for healthcare data breaches, but as the year draws to an end, 2024 is now looking like it will be a rare year where the number of healthcare data breaches reduces year-over-year. So far in 2024, 531 data breaches of 500 or more records have been reported to OCR.  In the first half of 2024, data breaches were reported at a rate of 67 a month. In the second half of 2024, data breaches have been reported at a rate of 44 a month. Across the 34 reported data breaches, the records of 4,839,018 individuals were exposed or impermissibly disclosed – The third lowest monthly total of the year to date, and well below the average of 7,082,007 records...

Read More
Great Expressions Dental Centers Settle Data Breach Lawsuit for $2.7 Million
Oct22

Great Expressions Dental Centers Settle Data Breach Lawsuit for $2.7 Million

Great Expressions Dental Centers has agreed to settle a class action lawsuit stemming from a 2023 data breach involving the personal and protected health information of 1,925,397 individuals. Great Expressions Dental Centers, a Bloomfield Hills, MI-based chain of 246 dental practices in 9 U.S. states, experienced a cyberattack in February 2023 that disrupted its IT systems. The hackers had access to its systems for 6 days between February 17 and February 22, 2024, during which time files containing patient data were exfiltrated from its systems. Those files contained information such as names, birth dates, contact information, Social Security numbers, driver’s license numbers, financial account information, credit/debit card numbers, billing records, health insurance information, prescription information, diagnoses, treatment information, x-ray images, and medical and dental histories. Individual notification letters were mailed to the affected individuals in early May 2023. Several lawsuits were filed in response to the data breach that were consolidated into a single action in...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist