25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Texas Attorney General Investigates 25M+ Conduent Business Services Data Breach
Feb13

Texas Attorney General Investigates 25M+ Conduent Business Services Data Breach

Texas Attorney General Ken Paxton has announced that his office has launched an investigation into the data breach at Conduent Business Services, stating that this could potentially be the largest healthcare data breach in U.S. history. While it is certain that the data breach is one of the largest, the 2024 data breach at Change Healthcare will take some beating. That data breach affected 192.7 million individuals. The U.S. list of confirmed victims has continued to grow, with Premera Blue Cross, Humana, Volvo Group North America (17,000 employees), and various Blue Cross and Blue Shield (BCBS) branches (Texas, Montana, Illinois) known to have been affected. The full list of affected entities has not been disclosed. As reported below, the Conduent data breach involved unauthorized access to information such as names, birthdates, addresses, Social Security numbers, medical information, and health insurance information. Hackers had access to its systems from October 21, 2024, to January 13, 2025, and more than a year after the incident was detected, the total number of affected...

Read More
Healthcare Sector Most Targeted by Ransomware Groups as Attacks Increase 49% YOY
Feb12

Healthcare Sector Most Targeted by Ransomware Groups as Attacks Increase 49% YOY

A new record was set for ransomware attacks last year, with disclosed ransomware attacks increasing by 49% year-over-year to a record-high of 1,174 attacks, according to Black Fog’s 2025 State of Ransomware Report. There was also a 37% year-over-year increase in undisclosed attacks, with 7,079 victims added to dark web data leak sites in 2025. The figures indicate that globally, 86% of ransomware attacks are not disclosed by victims. Data theft almost always occurs with ransomware attacks. In 2025, 96% of attacks involved data exfiltration prior to file encryption, which results in greater organizational harm. Data exfiltration has contributed to the significant increase in breach costs, as data theft results in greater reputational harm and increased regulatory exposure. In 2025, the average cost of a data breach was $4.44 million globally, and $7.42 million for healthcare data breaches. Healthcare retained its position as the sector most targeted by ransomware groups in 2025, accounting for 22% of disclosed attacks. All sectors experienced an increase in attacks in 2025, apart...

Read More
Data Breaches Announced by MedRevenu & EyeCare Partners
Feb12

Data Breaches Announced by MedRevenu & EyeCare Partners

Data breaches have been confirmed by the revenue cycle management company MedRevenu Inland Physicians Hospitalist Services, and the Missouri-based eye care provider, EyeCare Partners. MedRevenu Inland Physicians Hospitalist Services MedRevenu Inland Physicians Hospitalist Services, a Montclair, CA-based vendor that provides revenue cycle management services to healthcare providers, has recently notified the California Attorney General about a cybersecurity incident. The incident occurred on or around December 12, 2024, and caused disruption to its network. The forensic investigation determined that files containing personal and protected health information may have been accessed or acquired in the incident, including names, dates of birth, Social Security numbers, driver’s license numbers/government identification numbers, health insurance information, medical information, financial account numbers, payment card numbers, and access information. MedRevenu said it is reviewing and enhancing its cybersecurity measures and has offered the affected individuals complimentary...

Read More
Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised
Feb12

Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised

We previously reported that the Aflac data breach had affected 22.65 million individuals worldwide; however, it was unclear exactly how many of those individuals were in the United States or how many individuals had protected health information (PHI) compromised in the incident. PHI is personally identifiable information related to healthcare that is afforded additional protections under the Health Insurance Portability and Accountability Act (HIPAA). The HIPAA Breach Notification Rule requires notifications to be issued to the affected individuals and for the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) to be notified about a data breach within 60 days of the discovery of a breach. If the number of affected individuals has not been determined by the breach reporting deadline, OCR requires an estimate to be provided for the number of affected individuals. Many entities use a placeholder figure of 500 or 501 affected individuals in such cases. Aflac reported the data breach using a 500 placeholder figure. Aflac has recently provided an update to OCR...

Read More
Pinehurst Radiology Associates & Tallahassee Memorial HealthCare Settle Class Action Data Breach Lawsuits
Feb12

Pinehurst Radiology Associates & Tallahassee Memorial HealthCare Settle Class Action Data Breach Lawsuits

Pinehurst Radiology Associates has agreed to settle a class action lawsuit over a January 2025 data breach, and Tallahassee Memorial HealthCare has agreed to settle class action litigation over its use of pixels on its website. Pinehurst Radiology Associates Settlement Pinehurst Radiology Associates, a medical diagnostic imaging center in Pinehurst, North Carolina, has agreed to settle a class action lawsuit over a January 2025 security incident that affected 8,682 individuals. Pinehurst Radiology Associates identified a cybersecurity incident on January 20, 2025, and determined that patients’ protected health information had been exposed. Data exposed in the incident included names, addresses, dates of birth, Social Security numbers, diagnoses, treatment information, medical record numbers, health insurance information, and Medicare/Medicaid numbers. The affected patients were notified on or around May 22, 2025. Two class action lawsuits were filed in response to the data breach, which were consolidated in the Superior Court of Moore County, North Carolina – McNeill, et al....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist