25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Northern Arizona VA Healthcare System Failed to Protect Workers from Patient Violence
Jul11

Northern Arizona VA Healthcare System Failed to Protect Workers from Patient Violence

A VA medical center in Prescott, AZ, has failed to protect its workers from serious and potentially deadly patient violence. This is the second time that the Occupational Safety and Health Administration (OSHA) has cited the VA medical center for exposing its staff to violence in the past 4 years. The latest OHSA investigation of the Northern Arizona VA Healthcare System’s Bob Stump VA Medical Center was initiated in December 2023 in response to claims that nurses, nursing assistants, and housekeeping staff had been bitten, kicked, struck, punched, slapped, and sexually harassed by unit residents. OSHA’s investigation found the Bob Stump VA Medical Center had failed to protect healthcare workers from violence from unit residents, similar to the findings of a previous investigation in 2019. Executive Order 12196 requires federal agencies to comply with the same safety and health standards as private-sector employers. They must provide safe working conditions and address potential hazards. In contrast to private sector employers, federal agencies are generally exempt from...

Read More
What is a HIPAA Email Disclaimer?
Jul10

What is a HIPAA Email Disclaimer?

A HIPAA email disclaimer is a section of text located at the end of an email that informs recipients that the email includes Protected Health Information (PHI) and advises them what to do if they receive the email in error. There are circumstances in which the addition of a disclaimer can be beneficial, but it does not absolve the sender of a HIPAA violation. Around 8% of all data breaches notified to HHS’ Office for Civil Rights each year are attributable to misdeliveries. It is not known how many are misdeliveries through the mail and how many are misdeliveries by email, but it is known that in 2022 (the most recent year for which data are available) HHS’ Office for Civil Rights received 64,592 data breach notifications. An equal split of mail/email misdeliveries implies around 2,600 data breach events each year are attributable to emails being sent to the wrong recipients. To clarify, this does not mean 2,600 recipients received emails containing other people’s PHI. Some bulk misdeliveries of email can impact tens of thousands of patients or – in this case – plan members. What...

Read More
LivaNova Facing Multiple Class Action Lawsuits Over October 2023 Cyberattack
Jul09

LivaNova Facing Multiple Class Action Lawsuits Over October 2023 Cyberattack

The Houston, TX-based medical device company, LivaNova, is facing multiple class action lawsuits over an October 2023 cyberattack that exposed the protected health information of 180,000 patients. The attack was detected on November 19, 2023, and the investigation confirmed that unauthorized individuals first accessed its network on October 26, 2023. The data compromised in the incident included names, addresses, phone numbers, Social Security numbers, birth dates, diagnoses, treatment information, prescriptions, physician names, medical record numbers, device serial numbers, and health insurance information. Notifications were issued in May 2024, and complimentary credit monitoring services were offered to the affected individuals. At least two lawsuits have now been filed by patients whose information was exposed in the incident. One of those lawsuits was filed in the U.S. District Court for the Southern District of Texas, Houston Division, on behalf of J.W., by and through her guardian, Angela Johnson. The lawsuit alleges LivaNova maintained sensitive information in a reckless...

Read More
SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks
Jul09

SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks

SouthCoast Health and Privia Medical Group in Georgia have notified patients about a cyberattack and HIPAA compliance data breach that occurred in June 2023. Unauthorized activity was identified in South Coast Health’s network on June 18, 2023, and assisted by forensic specialists, it was determined that its network was accessed by an unauthorized third party between June 15 and June 18, 2023. During that time, files on the network were viewed or copied. South Coast Health confirmed that the intrusion was limited to its own network, with Privia Medical Group’s network unaffected; however, some Privia Medical Group patients did have their information exposed. The substitute breach notice provided to the South Carolina Attorney General does not list the types of data compromised in the attack, but that information is detailed in the individual notifications. A substitute notice was posted on its website last year warning patients that they may have been affected, but at the time it was unclear how many patients had been affected or the types of data involved. The review of the...

Read More
Patient Data Compromised in Palomar Health Medical Group Cyberattack
Jul08

Patient Data Compromised in Palomar Health Medical Group Cyberattack

Palomar Health Medical Group has warned patients that they may have been affected by an April 2024 cyberattack, and DaVita has learned that tracking tools on its website and mobile app may have sent user data to third-party vendors. Palomar Health Medical Group Announces April 2024 Cyberattack Palomar Health Medical Group, a provider of primary and specialty care to communities in North San Diego County, has informed patients about a recent cyberattack that exposed some of their protected health information. A security breach was detected on or around May 5, 2024, and immediate action was taken to prevent further unauthorized access to its systems. An investigation was launched to determine the nature and scope of the incident, which confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Palomar Health Medical Group said the attack “may have caused certain files to files to become unrecoverable,” which suggests that ransomware was used. Palomar Health Medical Group has confirmed that certain files were exfiltrated from its network and the review of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist