25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Tampa General Hospital Settles Data Breach Lawsuit for $6.8M
Jan06

Tampa General Hospital Settles Data Breach Lawsuit for $6.8M

Tampa General Hospital has agreed to pay $6,800,000 to resolve a class action lawsuit related to a 2023 cyberattack that involved unauthorized access to systems containing the protected health information of more than 2 million patients. The intrusion was detected on May 31, 2023, and the forensic investigation confirmed that hackers had access to its network for almost three weeks between May 12 and May 30, 2023. During that time the hackers exfiltrated files containing patient data such as names, dates of birth, contact information, Social Security numbers, health insurance information, and limited treatment information. The breach was initially thought to affect around 1.2 million patients but was later reported to the HHS’ Office for Civil Rights as affecting up to 1,313,636 patients. The breach report was then amended to state that up to 2,430,920 individuals had been affected. Several class action lawsuits were filed and consolidated into a single action – DiPierro, et al. v. Florida Health Sciences Center Inc. d/b/a Tampa General Hospital – in the 13th Judicial Circuit...

Read More
New York Data Breach Notification Requirements Updated
Jan06

New York Data Breach Notification Requirements Updated

In late December 2024, the Governor of New York, Kathy Hochul, signed two bills into law updating the New York data breach notification requirements under New York’s general business law (§ 899-aa). The bills expand the definition of personal information and set a time limit for issuing notifications. Prior to the law change, notifications had to be issued by companies that experienced a breach of system security that resulted in unauthorized access to the personal data of New York residents or if it was reasonably believed to have resulted in unauthorized access to the personal data of New York residents. Those notifications had to be issued to the affected individuals and the state Attorney General, Department of State, and the Division of State Police “in the most expedient time possible and without reasonable delay.” Effective immediately, a time limit has been stipulated for issuing those notifications, which must now be sent within 30 days of the discovery of a breach. The Department of Financial Services has also been added to the list of entities to be notified. The law...

Read More
Examples of Avoidable HIPAA Violations by Employers
Jan04

Examples of Avoidable HIPAA Violations by Employers

Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to an employer’s failure to implement adequate privacy and security measures, failure to effectively train members of the workforce, or failure to monitor HIPAA compliance. Over the next few years, these failures may become expensive for employers in – or providing a service to – the healthcare industry. Employers in their role as a covered entity or business associate have the ultimate responsibility for HIPAA compliance. They are responsible for complying with all applicable federal and state regulations, for developing workplace policies and procedures, and for ensuring the policies and procedures are complied with. While these responsibilities may sometimes be delegated to a third party, employers are usually responsible for selecting the third party. When avoidable HIPAA violations occur, they represent a compliance failure by an employer. Although the violations most often manifest as a data breach, unauthorized access to PHI, or an...

Read More
Colorado Fertility Center Ransomware Attack Affects 80,000 Patients
Jan03

Colorado Fertility Center Ransomware Attack Affects 80,000 Patients

Conceptions Reproductive Associates of Colorado has suffered a ransomware attack, hacking incidents have been reported by Lexington Diagnostic Center, In-Home Attendant Services, and Youth Eastside Services, and email accounts have been compromised at Summit Medical Group. Conceptions Reproductive Associates of Colorado The fertility clinic, Conceptions Reproductive Associates of Colorado, has recently confirmed that it was the victim of a ransomware attack that involved unauthorized access to its network and the theft of the information of up to 80,000 current and former patients and their partners. The incident was detected in mid-April when disruption was caused to some of its legacy computer systems. Incident response procedures were immediately implemented, the intrusion was reported to law enforcement, and an investigation was launched to determine the nature and extent of the unauthorized activity. The investigation confirmed that the ransomware group gained access to certain legacy systems earlier in the month and exfiltrated data. The file review has recently been...

Read More
HIPAA Administrative Safeguards
Jan02

HIPAA Administrative Safeguards

Compared to the specific HIPAA administrative safeguards of the Security Rule (the Administrative, Physical, and Technical Safeguards), most other references to safeguards in the text of HIPAA are intentionally flexible to accommodate the different types of covered entities and business associates that have to comply with them. While this flexibility means it can be easier for some organizations to comply with the HIPAA safeguards, other organizations may find the lack of direct guidance unhelpful. To demonstrate the difference between the safeguards of the Security Rule and the safeguards of the Privacy Rule, we have provided a synopsis of the Security Rule Administrative, Physical, and Technical Safeguards to compare against the safeguards mentioned in the Privacy Rule Administrative Requirements. There is also a section relating to the Organization Requirements of the Privacy and Security Rules – both of which include further HIPAA administrative safeguards. HIPAA Security Rule Safeguards The HIPAA Security Rule is dominated by the Administrative, Physical, and Technical...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist