25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

PHI Exposed in Data Breaches at Cedar Valley Services; Community Nurse; Health Dimensions Group
Mar18

PHI Exposed in Data Breaches at Cedar Valley Services; Community Nurse; Health Dimensions Group

Data breaches have recently been reported by Cedar Valley Services and Health Dimensions Group in Minnesota, and Community Nurse in Massachusetts. Cedar Valley Services, Minnesota Cedar Valley Services, a provider of vocational rehabilitation services to individuals in Southern Minnesota, has notified the HHS’ Office for Civil Rights about a data incident that involved the exposure of individuals’ protected health information. Little information about the incident has been publicly disclosed by Cedar Valley Services at this point, other than it being a hacking/IT incident affecting at least 501 individuals. The 501 total provided to the HHS’ Office for Civil Rights is a commonly used placeholder figure when the number of affected individuals has yet to be determined. This appears to have been a ransomware attack by the Qilin ransomware group, which added Cedar Valley Services to its dark web data leak site in December 2025. Qilin claims to have exfiltrated sensitive data in the attack. The listing was added on December 21, 2025, and screenshots of data allegedly stolen in the...

Read More
CommonSpirit Health Patients Affected by Vendor Data Breach
Mar17

CommonSpirit Health Patients Affected by Vendor Data Breach

The Chicago, IL-based Catholic health system CommonSpirit Health has announced that it has been affected by a security incident at a vendor of one of its business associates.  The healthcare consulting company Pinnacle Holdings Ltd experienced network disruption on November 25, 2024, as a result of a ransomware attack. The ransomware group had access to Pinnacle’s network from November 11, 2024, to November 25, 2024. During that time, files were exfiltrated from Pinnacle’s network. Pinnacle was a vendor of CommonSpirit Health’s vendor, NorthGauge Healthcare Advisors. In a breach notice issued to the Washington Attorney General on behalf of CommonSpirit Health, NorthGauge explained that Pinnacle immediately isolated its network when the attack was detected and has since implemented additional security measures to prevent similar incidents in the future. NorthGauge explained that Pinnacle had strict policies and procedures in place concerning data retention and data destruction, which limited the amount of data compromised in the incident. Pinnacle engaged a third-party vendor to...

Read More
Ransomware Group Claims Attacks on Meadowlark Hills Retirement Community & MedPeds
Mar17

Ransomware Group Claims Attacks on Meadowlark Hills Retirement Community & MedPeds

Meadowlark Hills retirement community in Kansas and MedPeds Associates of Sarasota in Florida have announced data breaches. The Beast ransomware group has claimed responsibility for both attacks. Manhattan Retirement Foundation (Meadowlark Hills), Kansas Manhattan Retirement Foundation, doing business as Meadowlark Hills, has reported a breach of the protected health information of 14,442 individuals to the HHS’ Office for Civil Rights. The Manhattan, KS-based non-profit retirement community and skilled nursing facility explained that unauthorized access to its network was identified on or around July 21, 2025. The forensic investigation determined that there had been unauthorized network access between July 12, 2025, and July 21, 2025. During that time, files containing personal and protected health information were exfiltrated from its network. The review of the files on the compromised parts of its network was completed on January 28, 2026, when it was confirmed that the following data elements were involved: name, date of birth, Social Security number, Driver’s license...

Read More
California Dental Care Provider; Childcare Referral Agency Announce Data Breaches
Mar16

California Dental Care Provider; Childcare Referral Agency Announce Data Breaches

Data breaches have been reported by two entities in California – Tieu Dental Corporation has announced a July 2025 hacking-related data breach affecting an as of yet undisclosed number of individuals. The Children’s Council of San Francisco has determined that more than 12,650 individuals have been affected by an August 2025 ransomware attack. Tieu Dental Corporation Announces July 2025 Data Breach Tieu Dental Corporation, a California-based provider of oral and maxillofacial surgery services, has started notifying patients about unauthorized access to its computer network last summer. The intrusion was identified on or around July 29, 2025, and the forensic investigation confirmed that an unauthorized third party accessed its network between July 28 and July 29, 2025. The compromised parts of its network were reviewed, and on January 11, 2026, Tieu Dental confirmed that the compromised files included patient data such as names, dates of birth, Social Security numbers, medical records, treatment plans, prescription information, and health insurance information. Tieu Dental...

Read More
EMR Practice Management Software Buyer’s Guide
Mar13

EMR Practice Management Software Buyer’s Guide

Selecting EMR practice management software requires evaluating scheduling, specialty support, charting flexibility, billing, patient engagement tools, support, integrations, future product development, and HIPAA compliance so the platform can support clinical operations, administrative workflows, and long-term practice growth without creating avoidable operational or regulatory risk. An EMR practice management platform affects how a practice books appointments, documents care, collects payment, communicates with patients, coordinates prescriptions and lab work, and protects electronic protected health information. A poor fit creates friction across the entire organization. A strong fit supports daily workflows, reduces administrative burden, and gives the practice room to expand services without replacing core systems. This buyer’s guide is built around the questions that matter during product evaluation. It focuses on workflow fit, support access, integration depth, product maturity, and compliance controls so practices can assess whether a platform meets current operational needs...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist