25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New Jersey Dermatology Practice Suffers 380,000-Record Data Breach
May15

New Jersey Dermatology Practice Suffers 380,000-Record Data Breach

Morristown, NJ-based Affiliated Dermatologists & Dermatologic Surgeons (ADDS) has announced a major breach of patient data. On March 5, 2024, ADDS found a ransom note on its network that claimed its network had been breached and data had been stolen. ADDS notified its third-party IT provider and brought in cybersecurity specialists to investigate and verify the threat actor’s claims and determined that there had been unauthorized access to the network between March 2, 2024, and March 5, 2024. Evidence was also found confirming files had been copied from its network. A review was conducted to determine the extent of the breach and on April 10, 2024, it was confirmed that the threat actor had access to the personal information of patients and employees. The breach has recently been reported to the HHS’ Office for Rights as involving the protected health information of up to 380,000 patients. The types of information involved varied from individual to individual. Patient information potentially compromised in the attack includes names, mailing addresses, birth dates, Social...

Read More
Rural Hospital Achieves 40% Reduction in No-Shows by Improving Patient Engagement
May14

Rural Hospital Achieves 40% Reduction in No-Shows by Improving Patient Engagement

A rural hospital in Illinois has reduced no-shows by 40% and achieved a 50% reduction in the clinical burden on staff through the use of EHR-integrated patient-facing communication technology. No-shows have a direct impact on patient health, interrupting continuity of care, delaying treatment, and increasing the risk of complications for chronic conditions. No-shows are also a significant drain of resources, with one study finding no-shows cost U.S. healthcare organizations more than $150 billion a year. A recent study by the consulting firm Chartis found half of rural hospitals are operating at a loss and are having to cut services with 418 rural hospitals are at risk of closure. The losses caused by no-shows are adding to the problem. Sparta Community Hospital in Rural Illinois has managed to significantly reduce no-shows by improving patient engagement. The hospital is using proactive, patient-facing communication technology that integrates with its electronic medical record system and delivers appointment reminders and information directly to patients. The one-way communication...

Read More
Email Incidents Affect Patients of Winter Haven Hospital & The Kennedy Collective
May14

Email Incidents Affect Patients of Winter Haven Hospital & The Kennedy Collective

Patient and Employee Data Exposed in Phishing Attack on The Kennedy Collective The Kennedy Collective, a Trumball, CT provider of disability services formerly known as The Kennedy Center, has fallen victim to a phishing attack that exposed patient and employee data. An employee responded to a phishing email and disclosed their credentials, which allowed the attacker to access the employee’s email account. The account has been secured; however, the review of emails and attachments revealed they contained personal health information, and for a subset of those individuals, Social Security numbers and driver’s license information. The breach has been reported to the HHS’ Office for Civil Rights as involving the protected health information of 851 individuals. It is unclear how many employees have been affected. All affected individuals have been notified by mail and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. The Kennedy Collective has taken steps to improve email security and has provided additional anti-phishing...

Read More
Black Basta Ransomware Group Targeting Healthcare Organizations
May13

Black Basta Ransomware Group Targeting Healthcare Organizations

All healthcare and public health (HPH) sector organizations have been warned to be on high alert and to implement mitigations against Black Basta ransomware attacks, as the ransomware-as-a-service (RaaS) group has the HPH sector in its crosshairs. In 2023, Black Basta was the third-most prolific ransomware group behind LockBit and ALPHV/Blackcat, but with the latter now shut down, Black Basta has taken second spot and attacks have been increasing, especially on critical infrastructure entities. Black Basta affiliates have conducted data theft and encryption attacks in 12 of the 16 critical infrastructure sectors, and recently the group has accelerated attacks on healthcare organizations. According to multiple CNN sources, Black Basta was behind the recent ransomware attack on Ascension which disrupted clinical operations at its 140 hospitals. Black Basta first emerged as a RaaS group in April 2022 and is thought to include members of the now-defunct Conti ransomware group. The RaaS group has been linked to the FIN7 threat actor. The group engages in double extortion tactics, where...

Read More

Palomar Health Medical Group Investigating Potential Cyberattack

Palomar Health Medical Group in California is investigating a potential cyberattack, Prudential Insurance Company of America and West Idaho Orthopedics and Sports Medicine have experienced ransomware attacks, and patient data has been exposed in a cyberattack on Georgia Institute for Plastic Surgery. Palomar Health Medical Group Investigating Potential Cyberattack Palomar Health Medical Group, a provider of primary and specialty care in North San Diego County, CA, is investigating a potential cyberattack after detecting suspicious activity within its computer network. The activity was detected on May 5, 2024, and the affected systems were taken offline to contain any malware. As a result of breach response processes, the patient portal, phones, and faxes are temporarily unavailable. With most communication systems down, patients have been advised to visit their physicians in person and to expect delays due to the disruption. Third-party cybersecurity specialists have been engaged to investigate the incident and identify the source of the disruption, and systems will be brought back...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist