25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS Final Rule Sets Financial Disincentives for Information Blocking by Healthcare Providers
Jun25

HHS Final Rule Sets Financial Disincentives for Information Blocking by Healthcare Providers

The Department of Health and Human Services (HHS) has published a final rule that sets financial disincentives for healthcare providers that engage in information blocking – practices that are known to be unreasonable and interfere with patient access to electronic health information or discourage the access, exchange, or use of electronic health information (EHI). Any healthcare provider that is determined by the HHS Office of Inspector General (OIG) to have committed information blocking and is referred to the Centers for Medicare and Medicaid Services will receive reduced annual incentive payments. These payments are issued as an incentive for participation in HHS programs, including being a meaningful user of electronic health records under the Medicare Promoting Interoperability Program or the Promoting Interoperability performance category of the Merit-Based Incentive Payment System. Under the Medicare Promoting Interoperability Program, an eligible hospital or critical access hospital (CAH) will no longer be considered to be a meaningful user of electronic health...

Read More
Warning Issued to HPH Sector About Qilin Ransomware Group
Jun25

Warning Issued to HPH Sector About Qilin Ransomware Group

A warning has been issued to the healthcare and public health (HPH) sector about the Qilin ransomware group, which is known to attack healthcare organizations due to their reliance on uptime and the sensitivity of the data they hold. Around 7% of the ransomware attacks conducted by the group have been on healthcare organizations. One of the most recent attacks has caused massive disruption to healthcare services in London. The group attacked a National Health Service (NHS) pathology vendor (Synnovis), which manages blood tests for NHS trusts and GP offices in south-east London. The attack did not directly affect any NHS hospitals as it was confined to Synnovis systems, but it has caused massive disruption with thousands of NHS surgeries and appointments canceled, and blood testing services have been reduced to around 10% of normal levels. The attack has caused major problems with blood matching, leading to a shortage of O-positive and O-negative blood. Synnovis expects the recovery to take weeks and anticipates a full recovery will take several months. Qilin is a...

Read More
May 2024 Healthcare Data Breach Report
Jun24

May 2024 Healthcare Data Breach Report

There has been a fall in the number of reported healthcare data breaches for the second consecutive month to the lowest monthly total since October 2023. In May, 51 data breaches of 500 or more healthcare records were reported to the Department of Health and Human Services Office for Civil Rights (OCR), well below the 12-month average of 65 large data breaches a month. Such a low total has not been seen in May since 2020, with reported breaches down 7.3% from the previous month and 33.8% from May 2023. While there has been a reduction in reported data breaches, they are still up by 22% for the year. 333 data breaches of 500 or more records were reported to OCR between January 1, 2024, and May 31, 2024. , compared to 273 for the corresponding period last year. The average breach size in 2024 is 123,785 records and the median data breach size is 3,716 records. Across those 333 data breaches, the records of 41,220,380 individuals have been exposed or stolen. Even with two massive data breaches of 2.8 million and 2.5 million records in May, there was a fall in the number of breached...

Read More
Texas Judge Vacates OCR’s Website Tracking Technology Guidance
Jun21

Texas Judge Vacates OCR’s Website Tracking Technology Guidance

On Thursday, a federal judge in Texas ruled that the guidance issued by the HHS’ Office for Civil Rights on website tracking technologies was unlawful, ruling that OCR overstepped its authority when it issued the guidance. The judge ruled that metadata collected from an unauthenticated web page does not qualify as individually identifiable health information when combined with an IP address. In 2022, the extent to which hospitals and health systems used tracking technologies became clear and OCR responded by issuing guidance on HIPAA and website tracking technologies in December 2022. These technologies, which include Meta Pixel code, are added to websites and provide beneficial functions; however, they also collect data on website users and transfer that information to third parties. The information collected may reveal diagnoses, reasons for appointments, health concerns, and other potentially sensitive information that can be tied to individuals by identifiers such as IP addresses. In the case of Meta pixel code, collected data is sent to Meta (Facebook) and may be made...

Read More
Sav-Rx Sued Over 2.8 Million-record Data Breach
Jun21

Sav-Rx Sued Over 2.8 Million-record Data Breach

A class action lawsuit has been filed against A&A Services, a medication benefits management service provider that operates as Sav-Rx, over a data breach in October 2023 that affected 2.8 million individuals. On or around October 3, 2023, hackers accessed the Sav-Rx network and exfiltrated files containing the protected health information of employees and clients’ health plan members. The breach was detected on October 8, 2023, and the file review confirmed names, contact information, dates of birth, and Social Security numbers had been stolen. Sav-Rx said it was provided with the final results of its file review on April 30, 2024, and the affected individuals were notified about the breach on May 10, 2024, and were offered complimentary credit monitoring and identity theft protection services. On June 5, 2024, a class action lawsuit was filed in the U.S. District Court for the District of Nebraska by Rodney Hill, whose protected health information was compromised in the cyberattack. The lawsuit alleges the defendant failed to implement reasonable and appropriate cybersecurity...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist