25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Settlement Proposed to Resolve Gifted Healthcare Data Breach Lawsuit
May08

Settlement Proposed to Resolve Gifted Healthcare Data Breach Lawsuit

Gifted Healthcare has proposed a settlement to resolve a class action lawsuit that alleged negligence for failing to implement reasonable cybersecurity measures, resulting in a data breach. The Metairie, LA-based nursing agency identified suspicious activity in an employee email account and the forensic investigation confirmed that three email accounts had been accessed by unauthorized individuals between August 25, 2021, and December 10, 2021. The review of the accounts was completed in July 2022 and confirmed that the personal information of 13,221 prospective, current, and former employees had been exposed, including names, Social Security numbers, and financial account information. A class action lawsuit – Cheryl Covington V. Gifted Nurses LLC d/b/a Gifted Healthcare – was filed in response to the breach that alleged the plaintiff and class suffered injuries from the misuse of their data, including fraudulent attempts to open bank accounts, decreased credit scores, and out-of-pocket expenses spent on mitigation measures. The lawsuit also alleged the victims of the...

Read More
Connecticut Lawmakers Pass Bill to Improve Preparedness for Cyberattacks and Safety for Home Health Care Workers
May08

Connecticut Lawmakers Pass Bill to Improve Preparedness for Cyberattacks and Safety for Home Health Care Workers

On May 6, 2024, lawmakers in Connecticut passed a bill that improves protections for home care workers and requires healthcare facilities to demonstrate they have a plan for responding to cyberattacks. The House passed the bill with a vote of 112-37 and it now awaits Governor Ned Lamont’s signature. The home healthcare worker provisions of the bill were prompted by the attempted sexual assault and murder of visiting nurse Joyce Grayson, who was killed by a convicted sex offender in October 2023 while she was working at a halfway house in Willimantic. The bill requires home health agencies to collect information on clients, such as if they have a history of violence against healthcare workers, domestic abuse, and substance use, as well as information on their psychiatric history, if there are weapons or safety hazards in their homes and the crime rate in the area where they live. That information must be made available to any employee assigned to clients, but healthcare agencies are not permitted to deny services to clients based on the information collected. The bill also requires...

Read More
DocGo Says Patient Data Stolen in Recent Cyberattack
May08

DocGo Says Patient Data Stolen in Recent Cyberattack

DocGo, a provider of mobile medical services and transportation in 26 US states and the United Kingdom, has announced that it has fallen victim to a cyberattack in which patient data was stolen. In a filing with the US Securities and Exchange Commission (SEC), DocGo explained that the attack targeted systems used to support its ambulance transportation business. The breach was rapidly contained, the threat actor has been removed from its systems, and a third-party cybersecurity company has been assisting with the investigation. The security breach was limited to DocGo’s ambulance transportation business and no other business lines were affected. DocGo said the incident has had no significant effect on its overall financial condition. The attackers obtained a limited number of healthcare records of patients who used its ambulance service, and notifications are now starting to be sent to those individuals. DocGo has not publicly stated how many patients have been affected nor the types of data compromised in the incident. At this stage, no threat actors appear to have claimed...

Read More
LockBit Leader Named and Sanctioned
May08

LockBit Leader Named and Sanctioned

The UK’s National Crime Agency (NCA) has named the leader of the infamous LockBit ransomware group as Russian national Dmitry Yuryevich Khoroshev, also known as LockBitSup. Lockbit is a ransomware-as-a-service group that has been in operation for four years. During that time, the group became the most prolific ransomware operation and targeted thousands of companies worldwide. According to the U.S. Department of Justice, LockBit has claimed more than 2,000 victims worldwide, has obtained more than $500 million in ransom payments, and has caused billions of dollars in losses. In February 2024, an international law enforcement operation – Operation Cronos – headed by the NCA successfully infiltrated the group’s systems, took control of its infrastructure, and locked the group out of its systems. The NCA took control of the group’s administrative systems, which the group’s affiliates used to conduct ransomware attacks, and the group’s public-facing data leak site where victims are named and stolen data are published. According to the NCA, information was gathered on LockBit’s 194...

Read More
OrthoConnecticut Data Breach Affects 118,000 Patients
May07

OrthoConnecticut Data Breach Affects 118,000 Patients

OrthoConnecticut has confirmed that the protected health information of more than 118,000 patients has been exposed in a cyberattack. Data breaches have also been reported by Green Diamond Resource Company and Empath Health. OrthoConnecticut OrthoConnecticut, a Danbury, CT-based multi-specialty orthopedic practice with 9 locations in Connecticut, recently identified unauthorized access to its network. The forensic investigation confirmed that an unauthorized third party had access to its network between November 24, 2023, and November 28, 2023, and during that time, may have removed files from the network that contained patients’ protected health information. OrthoConnecticut conducted a comprehensive review of all files on the network to determine which patients were affected, and it was confirmed on March 27, 2024, that the protected health information of 118,141 patients had been exposed. The types of information involved varied from patient to patient and may have included full names in combination with one or more of the following: Social Security number, date of birth, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist