25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Indiana Attorney General Drops Privacy Lawsuit Against IU Health
Aug13

Indiana Attorney General Drops Privacy Lawsuit Against IU Health

Indiana Attorney General Todd Rokita has dropped a privacy lawsuit against IU Health and IU Health Associates that alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and the Indiana Deceptive Consumer Sales Act for failing to protect a child’s protected health information. The lawsuit stemmed from comments made to the media by IU Health obstetrician-gynecologist Dr. Caitlin Bernard about an abortion she provided to a 10-year-old patient. The girl was the victim of a rape and could not legally have an abortion in her home state. She traveled to Indiana where abortions could be legally provided. The state has since updated its law and has made abortion illegal, except in very limited circumstances. IU Health investigated Dr. Bernard over the disclosure and was satisfied that the HIPAA Rules had not been violated. Dr. Bernard provided comments to a reporter from the IndyStar but did not disclose the patient’s name, only her age, home state, and gender. The Indiana Medical Board determined that sufficient information had been disclosed to allow the...

Read More
Six Healthcare Providers Added to Ransomware Data Leak Sites
Aug12

Six Healthcare Providers Added to Ransomware Data Leak Sites

Recent reports by Rapid7 and Guidepoint Security indicate the number of active ransomware groups has increased in 2024, as has the number of attacks. The healthcare industry is a prime target for ransomware groups and there has been a recent flurry of listings on ransomware groups’ data leak sites. Surgery Center of Mid Florida The Surgery Center of Mid Florida has recently alerted patients about a network encryption event (ransomware). The attack was detected on or around February 21, 2024, when unusual network activity was observed. The investigation confirmed file encryption, with the initial hacking occurring at its IT vendor. The hackers then used the connection with the IT vendor to launch an attack on its network. While the investigation found no evidence that patient information was viewed or acquired by the hackers, the decision was made to notify all 48,684 patients about the attack as unauthorized data access/theft could not be ruled out. Following the attack, the Surgery Center of Mid Florida terminated its contract with the IT vendor and contracted with a new...

Read More

PIPEDA Compliance Checklist

If your business is subject to Canada´s Personal Information Protection and Electronic Documents Act, a PIPEDA compliance checklist is a comprehensive reference to ensure the business is doing everything necessary to comply with the data privacy act. This article explains the PIPEDA requirements and who they apply to, and provides an example of a PIPEDA data privacy act compliance checklist businesses are invited to use to help them comply with the ten fair information principles of PIPEDA. A Brief Introduction to PIPEDA PIPEDA was enacted in 2000 with the objective of encouraging trust between consumers and businesses in e-commerce. The Act governs how covered businesses collect, use, and disclose personal information. It also gives individuals the right of access to information a business holds about them, and the right to challenge the accuracy and completeness of the information. Since the enactment of PIPEDA, subsequent amendments have increased compliance obligations, and further changes have been proposed in the Digital Charter Implementation Act which is currently...

Read More
Prospect Medical Holdings Data Breach Lawsuit Survives Motion to Dismiss
Aug09

Prospect Medical Holdings Data Breach Lawsuit Survives Motion to Dismiss

A lawsuit filed against Prospect Medical Holdings over a Summer 2023 Rhysida ransomware attack has survived a motion to dismiss; however, some of the asserted claims have been dismissed. Prospect Medical Holdings detected unauthorized access to its network in early August 2023 and the investigation confirmed that an unauthorized third party had access to its network for around four days prior to the discovery of the intrusion.  The review of the compromised systems confirmed they contained names, dates of birth, Social Security numbers, driver’s license numbers, financial information, diagnoses, lab test results, treatment information, medical record numbers, health insurance information, and claims information. The Rhysida ransomware group claimed responsibility for the attack and said it stole a database that contained more than 1 TB of customers’ personally identifiable information (PII) and protected health information (PHI), including more than half a million Social Security numbers. When ransoms are not paid, Rhysida is known to sell the stolen data or publish it on its...

Read More
Rite Aid Facing Class Action Lawsuit Over Data Breach Impacting 2.2 Million Customers
Aug09

Rite Aid Facing Class Action Lawsuit Over Data Breach Impacting 2.2 Million Customers

Rite Aid, the fourth largest pharmacy chain in the United States, is facing a class action lawsuit over a June 2024 data breach involving the personal information of 2.2 million customers. According to Rite Aid, an unknown third party gained access to some of its business systems on June 6, 2024, after impersonating a company employee. Rite Aid detected the unauthorized access within 12 hours, but despite the quick response, was unable to prevent the third party from exfiltrating customer data. The data stolen in the attack included names, addresses, dates of birth, and driver’s license numbers/government-issued IDs of customers who made purchases between June 6, 2017, and July 30, 2018. Customers were notified in mid-July and were offered complimentary identity monitoring services. A lawsuit – Erica Judka v. Rite Aid Corporation – was filed in the U.S. District Court for the Eastern District of Pennsylvania that alleges Rite Aid was negligent by failing to implement reasonable and appropriate cybersecurity measures, and had those measures been implemented, the data breach could...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist