25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breaches Reported by Medical Center Barbour; Monte Nido; Allergy Medical Group of the North Area
Aug26

Data Breaches Reported by Medical Center Barbour; Monte Nido; Allergy Medical Group of the North Area

Medical Center Barbour in Alabama, Allergy Medical Group of the North Area in California, and the nationwide eating disorder treatment provider Monte Nido have reported cyberattacks involving unauthorized access to patient data. Medical Center Barbour, Alabama Medical Center Barbour in Eufaula, AL, reported a breach of the personal information of 61,014 individuals to the Maine Attorney General and notified the affected individuals on August 22, 2024. Suspicious activity was identified within its network on October 29, 2023, and cybersecurity specialists were engaged to investigate the incident. The investigation concluded on December 8, 2023, and confirmed that an unauthorized third party had accessed files and data stored on its network and may have exfiltrated data. While the investigation was completed relatively quickly, it took until May 21, 2024, for the medical center to complete its internal review to determine the types of data involved, then a third-party data mining company was engaged to assist with the review of the data to allow notifications to be mailed. That...

Read More
Cyberattack on Help at Home Affects 26,700 Current & Former Patients
Aug26

Cyberattack on Help at Home Affects 26,700 Current & Former Patients

Data breaches have been reported by Help at Home, Kinsler Family Dentistry, ParkTree Community Health Center, and Providence Pediatrics Manito. Help at Home HAH Group Holding Company, a home healthcare provider that does business as Help at Home, has discovered the protected health information of 26,744 individuals has been exposed at one of its vendors. The vendor notified Help at Home about the intrusion on March 21, 2021; however, at the time, it was unclear to what extent personal information was involved. The unnamed former vendor conducted a review of the affected data and confirmed on June 19, 2024, that the information exposed and potentially stolen in the incident included names, dates of birth, Social Security numbers, financial account numbers, usernames and passwords, and/or certain medical, health insurance, and/or treatment information. HAH Group Holding Company mailed individual notifications on August 16, 2024, and has offered complimentary credit monitoring services. Kinsler Family Dentistry Kinsler Family Dentistry, the Frankfort, IN, dental practice of Julie D....

Read More
Karakurt Ransomware Group Member Charged in Ohio
Aug23

Karakurt Ransomware Group Member Charged in Ohio

An alleged member of the Karakurt threat group has been charged in U.S. District Court in Cincinnati with conspiracy to commit money laundering, wire fraud, and Hobbs Act extortion. Karakurt is a Russian cybercrime group thought to be a splinter group of the now-defunct Conti ransomware group. Karakurt specializes in data extortion rather than ransomware attacks, and gains access to corporate networks, steals sensitive data, and threatens to sell the stolen data if the ransom is not paid. The group maintains an auction site and if a sale cannot be arranged, the stolen data is added to the group’s data leak site where it can be downloaded for free. The group’s ransom demands have ranged from $25,000 to $13,000,000, with victims typically given a week from notification to pay the ransom. Karakurt has conducted attacks on a wide range of industry sectors, including several U.S. healthcare organizations. The group has claimed responsibility for attacks on CentroMed, Methodist McKinney Hospital, McAlester Regional Health Center, The Chattanooga Heart Institute, and most recently, Ann...

Read More
Healthcare Sector Warned About Everest Ransomware Group
Aug23

Healthcare Sector Warned About Everest Ransomware Group

The Health Sector Cybersecurity Coordination Center has issued a threat profile of the Everest Ransomware group, which was behind the recent ransomware attack on Gramercy Surgery Center in New York. The group has also claimed responsibility for attacks on Horizon View Medical Center in Las Vegas, 2K Dental in Ohio, Prime Imaging in Tennessee, and Stages Pediatric Care in Florida, and has increasingly been targeting the healthcare and public health (HPH) sector since 2021. The group has added more than 120 victims to its data leak site, around 34% of which are located in the United States, and around 27% of U.S. victims are in the healthcare industry. Between April 2021 and July 2024, the group conducted at least 20 attacks on healthcare organizations, disproportionately targeting medical imaging providers. The Everest ransomware group was first identified in December 2020 and rapidly became well-known within the cybercrime community after conducting attacks on high-profile targets including the Brazilian government and NASA. The group uses double extortion tactics, where ransomware...

Read More
Breaches of Patient Confidentiality
Aug23

Breaches of Patient Confidentiality

Breaches of patient confidentiality – defined as disclosures of private information without the patient’s consent – occur more often than most people are aware of due to blind spots in reporting requirements and “information breaches of patients” – which are permitted by the HIPAA Privacy Rule and required by law in some states. Although HHS’ Office for Civil Rights publishes an annual report which includes the total number of breach notifications it receives each year, it is impossible to accurately calculate how many breaches of patient confidentiality occur each year because of reporting failures, notifications that should be retracted, and reports made “in an abundance of caution”. In addition, there are inconsistent interpretations of the HIPAA breach notification requirements, and occasions when information breaches of patients are permitted by HIPAA. It is also the case that some healthcare providers do not qualify as HIPAA covered entities, and breaches of patient confidentiality in their organizations are subject to state notification laws. Reported Breaches of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist