25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Akeela Data Breach Settlement Gets First Nod from the Court
Mar23

Akeela Data Breach Settlement Gets First Nod from the Court

In June of last year, we reported that a settlement had been agreed to resolve a class action lawsuit against Akeela, Inc., over a June 2023 cybersecurity incident and data breach. The case was stayed until July 18, 2025, and ahead of that date, the plaintiff was required to move for preliminary approval of class certification. Ahead of that date, the plaintiff, Jessica McRorie, dismissed her complaint without prejudice and immediately joined a separate complaint, Batin et al. v. Akeela, Inc., which made substantially similar allegations. The Batin case, filed in the Superior Court for Anchorage, Alaska, has recently been settled, and the settlement has received preliminary approval from the court. The Batin case lists Jessica McRorie, Elynnie Batin, Jane Doe, Rocky Hawley, Andrew Metcalf, Thomas Maxim, and Kathleet Yarr (Personal Representative for the Estate of Ian Christiansen) as plaintiffs, who allege that their names, Social Security numbers, dates of birth, and medical diagnosis and treatment information were exposed to cybercriminals as a result of the negligence of Akeela....

Read More
Navia Benefit Solutions Discloses Data Breach Affecting 2.7 Million Individuals
Mar20

Navia Benefit Solutions Discloses Data Breach Affecting 2.7 Million Individuals

Over a three-week period between December 2025 and January 2026, hackers had access to the network of a Washington-based employee benefits administrator and potentially acquired the data of almost 2.7 million* current and former participants and their dependents. Renton, WA-based Navia Benefit Solutions, Inc., provides employee benefits administration services, including Health Care Flexible Spending Accounts and COBRA benefits. The company works with employers to manage tax-advantaged healthcare and dependent care accounts, and as such, maintains large amounts of employee data. The company has more than 10,000 clients nationwide and more than 1 million participants. The intrusion was identified on or around January 15, 2026, and the forensic investigation confirmed that its computer environment was subject to unauthorized access from December 22, 2025, to January 15, 2026. According to the breach notice provided to the Maine Attorney General, 2,697,540 individuals have been affected. Navia Benefit Solutions uploaded a substitute breach notice to its website on March 13, 2026, and...

Read More
Essen Medical Associates Agree to $4 Million Settlement to Resolve Class Action Data Breach Lawsuit
Mar20

Essen Medical Associates Agree to $4 Million Settlement to Resolve Class Action Data Breach Lawsuit

Essen Medical Associates has agreed to pay $4,000,000 to resolve class action litigation over a March 2023 cyberattack and data breach that affected 904,672 current and former patients. Essen Medical, a New York-based healthcare provider, experienced a cyberattack that saw hackers access its network between March 14, 2023, and March 22, 2023. Data exposed in the incident included personally identifiable information and protected health information such as names, driver’s license numbers/state identification numbers, U.S. alien registration numbers, non-U.S. identification numbers, passport numbers, financial account information, dates of birth, Social Security numbers, medical treatment information, and health insurance information. The data breach sparked several class action lawsuits, which were consolidated – Rivera, et al. v. Essen Medical Associates, P.C – in the Supreme Court of the State of New York, County of Bronx. The consolidated lawsuit alleged that the cyberattack was preventable and was the result of the defendant’s failure to implement adequate and appropriate...

Read More
FDA Issues Recall Notice for GE HealthCare Centricity Universal Viewer
Mar20

FDA Issues Recall Notice for GE HealthCare Centricity Universal Viewer

A class 2 recall has been issued by the U.S. Food and Drug Administration (FDA) for certain GE HealthCare Centricity medical imaging products due to a vulnerability that could potentially be exploited by an unauthorized individual to manipulate data or impact system availability. Centricity Universal Viewer is a device that displays medical images such as mammograms and data from various imaging sources. The vulnerability affects the following Centricity Universal Viewer software versions: Versions 5.0 SP6 through UV 5.0 SP7.1 Versions 6.0 through 6.0 Sp10.4.1 Versions 7.0 through 7.0 Sp2.0.1 The recall was issued as the vulnerability may cause temporary or medically reversible adverse health consequences, but where the probability of serious adverse health consequences is remote. The vulnerability is due to user login credentials being exposed on the local client workstation. As such, an unauthorized individual could obtain the credentials and potentially impact system availability and/or manipulate data; however, the potential for exploitation is limited, as direct physical...

Read More
Final Rule Implementing HIPAA Security Rule Updates Edges Closer
Mar20

Final Rule Implementing HIPAA Security Rule Updates Edges Closer

The HIPAA Security Rule update proposed by OCR in the final days of the Biden administration is only two months away from a final rule, should OCR stick to the proposed timescale for release. OCR has yet to confirm when a final rule will be released or if the proposed rule will actually progress to a final rule. OCR issued its Notice of Proposed Rulemaking (NPRM) on December 27, 2024, to strengthen cybersecurity protections for electronic protected health information (ePHI). The proposed update, the first significant update to the HIPAA Security Rule in more than two decades, introduced significant new security requirements to ensure the confidentiality, integrity, and availability of ePHI, taking into account changes to business practices and technology since the original rule was enacted. Several months earlier, in January 2024, OCR published its voluntary Health Care and Public Health Cybersecurity Performance Goals (HPH CPGs) – two sets of voluntary goals (essential and enhanced) that HPH sector organizations were encouraged to adopt to improve resilience to cyber threats, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist