25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cummins Behavioral Health Settles Data Breach Lawsuit for Up to $2.1 Million
Nov13

Cummins Behavioral Health Settles Data Breach Lawsuit for Up to $2.1 Million

Cummins Behavioral Health, a behavioral healthcare provider in Central and Western Indiana, has agreed to a $2.1 million settlement to resolve a class action lawsuit filed by individuals affected by a 2023 data breach. On March 9, 2023, Cummins Behavioral Health discovered a ransom note left by a threat actor who alleged to have infiltrated its systems and exfiltrated sensitive data. An investigation was launched to verify that a breach had occurred, and it was confirmed that there had been unauthorized access to its network between February 2, 2023, and March 9, 2023. The file review confirmed that a range of sensitive data had been stolen, including names, addresses, dates of birth, Social Security numbers, health insurance information, and payment card information. The breach was reported to the HHS Office for Civil Rights on April 12, 2024, using a placeholder figure of 501 affected individuals, and that total remains on the OCR breach portal as of November 2024; however, the breach was reported to the Maine Attorney General as involving the personal information of 157,688...

Read More
The Three Pillars of HIPAA Compliance
Nov12

The Three Pillars of HIPAA Compliance

The three pillars of HIPAA compliance are to develop, implement and continuously improve a HIPAA compliance program, a HIPAA training program, and an information technology security program. Achieving compliance with the Rules of the Health Insurance Portability and Accountability Act (HIPAA) can be a challenge for healthcare organizations and their business associates. The HIPAA Rules were developed to cover healthcare organizations of different types and sizes, so the Rules needed to be flexible to accommodate this diversity. They also needed to be capable of standing the test of time without requiring regular updates in response to changing technology and operating practices. While HIPAA sets standards for privacy, security, and administrative processes, the Rules can seem complex and often lack important details and they do not include an easy-to-follow HIPAA compliance checklist, so it’s no surprise that achieving and maintaining HIPAA compliance can be a daunting prospect. One of the biggest challenges for compliance professionals is interpreting the HIPAA Rules and...

Read More
Data Breaches Announced by New Jersey Rehabilitation Center & Rhode Island Orthopedic Practice
Nov12

Data Breaches Announced by New Jersey Rehabilitation Center & Rhode Island Orthopedic Practice

Cyberattacks involving unauthorized access to patient information have been reported by Physical Medicine & Rehabilitation Center in New Jersey and Orthopedics Rhode Island. The Physical Medicine & Rehabilitation Center In July 2024, the Physical Medicine & Rehabilitation Center in New Jersey experienced a cybersecurity incident that caused disruption to its network. Third-party digital forensics experts were engaged to investigate the incident and confirmed that an unauthorized third party had access to its network from July 8, 2024, to July 9, 2024, and during that time, accessed and potentially acquired files containing patient information. The types of information involved varied from patient to patient and may have included names along with one or more of the following: address, email address, phone number, date of birth, Social Security number, driver’s license/state ID number, credit/debit card number, treatment/diagnosis information, prescription information, provider name, date of service, patient ID, Medicare/Medicaid number, medical record number, treatment...

Read More
Health & Palliative Services of the Treasure Coast & Universal Health Corporation Suffer Email Breaches
Nov12

Health & Palliative Services of the Treasure Coast & Universal Health Corporation Suffer Email Breaches

Health & Palliative Services of the Treasure Coast in Florida and Universal Health Corporation in Virginia have discovered unauthorized access to their email systems and the exposure of patients’ protected health information. Health & Palliative Services of the Treasure Coast Health & Palliative Services of the Treasure Coast, a Florida-based provider of end-of-life care, has recently confirmed that 22,459 individuals had some of their personal and protected health information compromised in an email security incident. Suspicious activity was identified in an employee’s email account on February 27, 2024. A third-party cybersecurity firm was engaged to conduct an investigation and confirmed on April 15, 2024, that there had been unauthorized access to a single email account. The data mining process to identify the individuals affected and the types of data involved was completed on July 17, 2024; however, virtually none of the affected individuals had addresses on file. The final list of affected patients was manually reviewed, and that process was completed on...

Read More
Data Breaches Confirmed by South West Family Medicine Associates & Sango Family Dentistry
Nov11

Data Breaches Confirmed by South West Family Medicine Associates & Sango Family Dentistry

Cyberattacks have recently been confirmed by South West Family Medicine Associates in Texas and Sango Family Dentistry in Tennessee that involved unauthorized access to patient data. South West Family Medicine Associates South West Family Medicine Associates in Dallas, Texas, has notified 36,959 current and former patients and employees that some of their protected health information was compromised in an August security breach. Suspicious activity was identified within its network on August 7, 2024, and cybersecurity professionals were engaged to investigate the activity and confirmed that unauthorized individuals accessed its network and viewed or acquired files containing patient and employee information. The affected files were reviewed, and on October 24, 2024, it was confirmed that they contained patient and employee information including names, addresses and zip codes, dates of birth, Social Security numbers, driver’s license numbers, medical histories, lab results, diagnosis/condition information, medication information, passwords, passport numbers, personal identification...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist