25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

QualDerm Partners Data Breach Affects More Than 3 Million Individuals
Mar03

QualDerm Partners Data Breach Affects More Than 3 Million Individuals

In late February, The HIPAA Journal reported on a QualDerm Partners data breach, the scale of which was currently unknown, except that it affected 174,837 Texas residents. The data breach was likely to have affected considerably more individuals, given that QualDerm Partners does business in 17 U.S. states and serves more than 15 million patients annually. The scale of the data breach is now clearer, as the Oregon Attorney General and the HHS’ Office for Civil Rights have been notified that 3,117,874 individuals have been affected. Notification letters started to be mailed to those individuals on February 22, 2026. February 25, 2026: QualDerm Partners Confirms Significant Data Breach QualDerm Partners, LLC, a provider of healthcare management services to 158 dermatology and skin care practices in 17 U.S. states, has announced a security incident involving unauthorized access to its computer network. Unauthorized network activity was identified on December 24, 2025, and immediate action was taken to contain the incident and secure its network and computer systems. Third-party...

Read More
University of Hawai’i Cancer Center: 1.15 Million Individuals Affected by 2025 Ransomware Attack
Mar02

University of Hawai’i Cancer Center: 1.15 Million Individuals Affected by 2025 Ransomware Attack

The University of Hawai’i Cancer Center (UHCC) has confirmed that up to 1.15 million individuals may have been affected by its August 2025 ransomware attack. The HIPAA Journal previously reported on the incident in January 2026 (see below), when the attack and data breach were first announced; however, at the time, the file review was ongoing, and the number of affected individuals had yet to be announced. UHCC explained that the notification delay was due to the volume of data impacted, the complexity of the encrypted data, and the age of the studies and records. In a report to the state legislature, UHCC provided additional information about the attack and data breach, confirming that the ransomware attack had no impact on patient care, clinical trials operations, its Basic Science and Prevention Division, and there was no unauthorized access to student records. The forensic investigation determined that the threat actor accessed the UHCC Epidemiology Division’s research files, exfiltrated files, and encrypted data. The initial findings of the investigation found that a majority...

Read More
Trizetto Data Breach: PHI of 3.4 Million Individuals Exposed
Mar02

Trizetto Data Breach: PHI of 3.4 Million Individuals Exposed

It has been more than four months since TriZetto Provider Solutions discovered unauthorized access to its IT environment, and it has now been confirmed that the protected health information of at least 3,433,965 individuals was exposed or compromised in the incident. The data breach has recently been added to the HHS’ Office for Civil Rights breach portal. At more than 3.4 million affected individuals, it ranks as one of the largest healthcare data breaches to be confirmed this year. TriZetto identified suspicious activity within its web portal on October 2, 2025. The web portal is used by its clients to access TriZetto systems. TriZetto took immediate action to prevent further unauthorized access to its systems and has not detected any further unauthorized activity since that date. The forensic investigation revealed that the threat actor first gained access to data almost a year before the unauthorized access was detected. The first unauthorized access to records occurred in November 2024. The data breach affected the revenue cycle management side of the business and the...

Read More
Asheville Eye Associates Settles Lawsuit Stemming from DragonForce Ransomware Attack
Feb27

Asheville Eye Associates Settles Lawsuit Stemming from DragonForce Ransomware Attack

Asheville Eye Associates, an eye care provider serving patients in Western North Carolina, has agreed to settle class action litigation stemming from a November 2024 cyberattack and data breach. A cyber threat actor accessed its network and potentially viewed or obtained patient information, including names, addresses, health insurance information, and medical treatment information. The Asheville Eye Associates data breach was reported to the HHS’ Office for Civil Rights as affecting 204,984 individuals. The DragonForce ransomware group took credit for the attack and claimed to have exfiltrated 540 GB of data before encrypting files. The data was leaked when the ransom was not paid. The affected individuals were notified about the attack in early February 2024. Multiple lawsuits were filed in response to the data breach by plaintiffs Robert Woodsmall, Mimi Reynolds, Dena Brito, Robert Ricchetti, and Christopher Miller. The lawsuits were consolidated, In re Asheville Eye Associates Data Incident Litigation, in South Carolina’s General Court of Justice Superior Court Division. The...

Read More
January 2026 Healthcare Data Breach Report
Feb27

January 2026 Healthcare Data Breach Report

The HHS’ Office for Civil Rights (OCR) healthcare data breach portal shows a slight month-over-month decline in large healthcare data breaches, which fell by 13.2% from December 2025 to 46 data breaches in January 2026. The OCR breach portal lists healthcare data breaches affecting 500 or more individuals, which have been reported far less frequently during the past 5 months than in the first half of 2025. From September 2025 to January 2026, an average of 46.2 large data breaches were reported to OCR each month, compared to an average of 68.6 breaches per month in the preceding 5 months (April to August). Should this trend continue, 2026 could well see the lowest number of data breaches reported for several years. We previously suggested that there may be a delay in adding data breaches to the OCR breach portal due to the government shutdown in late 2025, which lasted for 43 days between October 1 and November 12, 2025, during which time no healthcare data breaches were added to the OCR data breach portal. Since we last compiled breach data in January, a further two breaches have...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist