25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cyberattack on Fort Worth Revenue Cycle Management Firm Affects 77,000 Individuals
Dec10

Cyberattack on Fort Worth Revenue Cycle Management Firm Affects 77,000 Individuals

Data breaches have been announced by the revenue cycle management company ESHA Inc., the pulmonary rehabilitation provider Citadel of Northbrook, the health IT company Datavant Group, and the Florida dental practice operator Smile Design Management. ESHA, Inc., Texas ESHA, Inc., a Fort Worth, TX-based revenue cycle management company, has notified 76,922 individuals that some of their personal and protected health information was potentially viewed and/or copied in a security incident over the summer. Unauthorized access to its server infrastructure was detected on July 19, 2024, and the servers were immediately taken offline to prevent further unauthorized access. Digital forensics specialists were engaged to investigate the incident and determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized actor accessed its servers from July 13 to July 17, 2024. The file review was completed on or around September 16, 2024, and individual notifications were mailed to the affected individuals on November 15, 2024. Complimentary credit...

Read More
Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack
Dec09

Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack

Beth Israel Lahey Health’s Anna Jaques Hospital in Newburyport, Massachusetts, has recently notified regulators and patients about a cyberattack and data breach that occurred on Christmas Day in 2023. According to the notification sent to the Maine Attorney General, the personal information of 316,342 individuals was potentially compromised in a cyberattack that caused disruption to some of its systems – a phrase commonly used to describe a ransomware attack, although ransomware was not mentioned in the notification. Anna Jaques Hospital did not state in the notification letters when the attack was detected or when its network was compromised. The Maine Attorney General’s website erroneously states the breach occurred on December 25, 2024, and was discovered on December 22, 2024. At the time of writing, there is no breach listed on the HHS’ Office for Civil Rights website. Data breaches tend to be added to the OCR breach portal up to two weeks after OCR receives the notification. Anna Jaques Hospital explained in the notification letter that when the incident was detected, the...

Read More
Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks
Dec09

Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks

Over Thanksgiving weekend, Watsonville Community Hospital and PIH Health in California fell victim to ransomware attacks and continue to experience disruption to their computer systems. Jefferson Dental Center in Indiana has confirmed it has recovered from a November 15, 2024, ransomware attack. Watsonville Community Hospital Grappling with November 29 Ransomware Attack Watsonville Community Hospital in California is currently dealing with a cyberattack and is facing continued disruption to its computer systems. The hospital has implemented downtime protocols due to computer systems being unavailable and is recording patient information manually on charts and issuing paper prescriptions while its IT team and third-party IT specialists work to restore its computer systems. The hospital’s emergency department remains open, and the full spectrum of care continues to be provided; however, patients are facing delays. The cyberattack caused network disruption on November 29, 2024, which has continued for more than a week. The last update on the cyberattack on the hospital’s website was...

Read More
Healthcare Hacker Sentenced to 10 Years in Jail
Dec09

Healthcare Hacker Sentenced to 10 Years in Jail

A hacker who targeted multiple U.S. healthcare organizations, breached their networks, stole sensitive data, and attempted to extort them, has been sentenced to a decade in jail. Robert Purbeck, 45, an IT specialist who worked for Ada County in Idaho, hacked at least 19 organizations between 2017 and 2018 and stole the personal data of more than 132,000 individuals.  Purbeck, who used the monikers Lifelock and Studmaster, accessed victims’ networks using stolen credentials purchased on darknet marketplaces such as AlphaBay. Sensitive data was identified and exfiltrated and he demanded ransom payments to prevent the publication of the stolen data. One of the first U.S. victims was Family Medical Center in Griffin, Georgia. The credentials purchased by Purbeck allowed him to access the medical clinic’s network in June 2017 and exfiltrate the protected health information of more than 43,000 individuals, including names, addresses, dates of birth, and Social Security numbers. In February 2018, using darknet-purchased credentials, Purbeck accessed a server of the Police Department in...

Read More
$8.9 Million Data Breach Settlement Agreed by Elekta & Northwestern Memorial Healthcare
Dec06

$8.9 Million Data Breach Settlement Agreed by Elekta & Northwestern Memorial Healthcare

An $8.9 million settlement has been agreed to resolve a class action lawsuit over a cyberattack on the radiation therapy and radiosurgery equipment provider Elekta that exposed the protected health information of patients of Northwestern Memorial Healthcare in Illinois. The cyberattack on Elekta occurred between April 2 and April 20, 2021, and saw unauthorized individuals gain access to Elekta’s cloud-based radiology software and attempt to use ransomware to encrypt files. The attack affected several of its U.S-based customers, including Northwestern Memorial Healthcare, which reported that the data of up to 201,197 oncology patients had potentially been obtained in the attack. Lawsuits were filed in response to the data breach that named Carla Tracy, Darryl Bowsky, and. Deborah Harrington as plaintiffs, which were consolidated into a single action – Tracy v. Elekta Inc., et al – in the U.S. District Court for the Northern District of Georgia. The plaintiffs alleged negligence, negligence per se, intrusion upon seclusion/invasion of privacy, breach of implied contract...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist