25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

LockBit Leader Named and Sanctioned
May08

LockBit Leader Named and Sanctioned

The UK’s National Crime Agency (NCA) has named the leader of the infamous LockBit ransomware group as Russian national Dmitry Yuryevich Khoroshev, also known as LockBitSup. Lockbit is a ransomware-as-a-service group that has been in operation for four years. During that time, the group became the most prolific ransomware operation and targeted thousands of companies worldwide. According to the U.S. Department of Justice, LockBit has claimed more than 2,000 victims worldwide, has obtained more than $500 million in ransom payments, and has caused billions of dollars in losses. In February 2024, an international law enforcement operation – Operation Cronos – headed by the NCA successfully infiltrated the group’s systems, took control of its infrastructure, and locked the group out of its systems. The NCA took control of the group’s administrative systems, which the group’s affiliates used to conduct ransomware attacks, and the group’s public-facing data leak site where victims are named and stolen data are published. According to the NCA, information was gathered on LockBit’s 194...

Read More
OrthoConnecticut Data Breach Affects 118,000 Patients
May07

OrthoConnecticut Data Breach Affects 118,000 Patients

OrthoConnecticut has confirmed that the protected health information of more than 118,000 patients has been exposed in a cyberattack. Data breaches have also been reported by Green Diamond Resource Company and Empath Health. OrthoConnecticut OrthoConnecticut, a Danbury, CT-based multi-specialty orthopedic practice with 9 locations in Connecticut, recently identified unauthorized access to its network. The forensic investigation confirmed that an unauthorized third party had access to its network between November 24, 2023, and November 28, 2023, and during that time, may have removed files from the network that contained patients’ protected health information. OrthoConnecticut conducted a comprehensive review of all files on the network to determine which patients were affected, and it was confirmed on March 27, 2024, that the protected health information of 118,141 patients had been exposed. The types of information involved varied from patient to patient and may have included full names in combination with one or more of the following: Social Security number, date of birth, and...

Read More
Email Breaches Reported by MedStar Health, Bluebonnet Trails Community Services, Bluegrass Care Navigators
May07

Email Breaches Reported by MedStar Health, Bluebonnet Trails Community Services, Bluegrass Care Navigators

MedStar Health is notifying more than 118,000 patients about an email security incident that exposed their protected health information. Email accounts have also been compromised at Bluebonnet Trails Community Services and Bluegrass Care Navigators. MedStar Health MedStar Health, a non-profit healthcare provider that operates 10 hospitals in the Baltimore-Washington area, said hackers gained access to its network and may have obtained the protected health information of 183,000 patients, including names, addresses, dates of birth, dates of service, provider names, and health insurance information. MedStar Health did not say when the unauthorized access was first detected but confirmed that the email accounts of three employees were accessed by unauthorized individuals intermittently between January 2023 and October 2023. MedStar Health said it has no reason to believe that patient data was accessed or acquired, but it was not possible to rule out data theft with a high degree of certainty. As required by HIPAA, MedStar Health had implemented technical, physical, and administrative...

Read More
Presbyterian Healthcare Services Agrees to Settle Email Breach Lawsuit
May07

Presbyterian Healthcare Services Agrees to Settle Email Breach Lawsuit

Presbyterian Healthcare Services has proposed a settlement to resolve a class action lawsuit that was filed by patients whose protected health information was compromised in a 2019 phishing attack. In June 2019, the New Mexico-based healthcare system discovered hackers had gained access to the email accounts of some of its employees when they responded to phishing emails. The email accounts contained the names, dates of birth, Social Security numbers, clinical information, and health plan information of 183,370 patients and health plan members. A class action lawsuit was filed in response to the data breach that alleged Presbyterian Healthcare Services had failed to implement reasonable cybersecurity measures, did not follow industry-standard cybersecurity practices, and could have prevented the breach if those measures had been implemented. Presbyterian Healthcare Services did not agree with the allegations but has chosen to settle the lawsuit with no admission of wrongdoing or liability. Under the terms of the settlement, individuals who were notified about the breach by...

Read More
OSHA Proposes $163K Fine for Home Health Agency After Murder of Home Health Worker
May07

OSHA Proposes $163K Fine for Home Health Agency After Murder of Home Health Worker

The Occupational Safety and Health Administration (OSHA) has proposed a $163, 627 fine for a home healthcare provider that the agency alleged failed to protect workers from serious hazards of workplace violence. OSHA cited Jordan Health Care Inc. and New England Home Care Inc., which do business as Elara Caring – one of the largest home healthcare providers in the United States with more than 200 branches in 17 states. OSHA initiated an investigation following the attempted sexual assault and murder of visiting nurse, Joyce Grayson, in October 2023. Grayson visited a halfway house in Willimantic, Connecticut on October 28, 2023, to provide medications to a client. The police were called after Grayson failed to attend subsequent appointments, and her body was found in the basement of the residence. The client she was visiting, Michael Reese, 39, had previously been convicted of rape and had served 14 years in prison after sexually assaulting and stabbing a woman in 2006. He has since been charged with murder, felony murder, and attempted first-degree sexual assault. OSHA...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist