25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Benefytt, EMSA, Lindsay Municipal Hospital Affected by Cyberattacks

Health Plan Intermediaries Holdings (Benefytt) has been affected by a cyberattack on a vendor, Emergency Medical Services Authority said patient data was exposed in a February cyberattack, and the Bian Lian group has claimed responsibility for a cyberattack on Lindsay Municipal Hospital. Patient Data Stolen in Cyberattack on Emergency Medical Services Authority The Emergency Medical Services Authority (EMSA) in Oklahoma City, OK, has announced that it fell victim to a cyberattack that saw unauthorized individuals gain access to its network between February 10, 2024, and February 13, 2024. The intrusion was detected on February 13, 2024, and systems were shut down to prevent further unauthorized access. The forensic investigation confirmed that the attackers exfiltrated files containing patient data including names, addresses, dates of birth, dates of service, and, for some individuals, the name of their primary care provider and/or Social Security number. Notification letters have started to be mailed to the affected individuals and complimentary credit monitoring and identity...

Read More
New Compliance Requirements for Florida Hospitals with Emergency Departments
Mar25

New Compliance Requirements for Florida Hospitals with Emergency Departments

Florida Governor Ron De Santis has signed the “Live Healthy” legislative package into law, which enhances current policies and includes $716 million in health care investments. The purpose of the legislative package is to strengthen Florida’s health care workforce, broaden access to quality health care, and foster innovation in the industry. The new laws introduce new compliance requirements for hospitals with emergency departments. The bills signed by Governor DeSantis on March 21, 2024, are: SB 7016, which creates and expands training programs that will help to develop and retain Florida’s health care workforce. SB 7018, which harnesses the innovation and creativity of entrepreneurs and industry leaders to meet the needs and challenges of Florida’s evolving health care system. SB 1758, which formalizes some of the work already underway within the Agency for Persons with Disabilities through the First Lady’s Hope Florida initiative. SB 330, which creates a new category of teaching hospitals dedicated to advancing behavioral health care through research, collaboration, and...

Read More

Med-Data Settles Data Breach Lawsuit for $7 Million

The Spring, TX-based revenue cycle management company Med-Data has agreed to a $7 million settlement to resolve all claims stemming from a data breach between 2018 and 2019 that involved the protected health information of approximately 136,000 individuals. Between December 2018 and September 2019, an employee of Med-Data uploaded patient data to the public-facing software development hosting platform GitHub. The files were added to personal folders on GitHub Arctic Code Vault and contained the protected health information of patients of several of its clients. The exposed data included names, addresses, dates of birth, Social Security numbers, diagnoses, medical conditions, claims information, dates of service, subscriber IDs, medical procedure codes, provider names, and health insurance policy numbers. Med-Data removed the files when it was alerted to the data exposure and offered the affected individuals complimentary credit monitoring and identity protection services. A lawsuit was filed in response to the data breach that claimed Med-Data failed to adequately protect the...

Read More
Healthcare Cyber Security Summit June 12-13 with 20% Discount
Mar24

Healthcare Cyber Security Summit June 12-13 with 20% Discount

The HealthSec: Cyber Security for Healthcare Summit returns for its 2nd edition in Boston, Massachusetts on June 12th – 13th! As operations in healthcare and life sciences industries are becoming increasingly digitized and internet-connected, the attack surface is expanding and cybersecurity risks are growing. In light of this, healthcare security leaders from hospitals & healthcare systems, healthcare equipment and services, medical devices, and the pharma and biotech industries are preparing to gather at the summit to learn how to protect their sensitive data from cyberattacks.   CPD Certified Event This CPD-certified event is your chance to unite with cybersecurity leaders from the likes of Abbott, GSK, Moderna, Pfizer, and Johnson & Johnson through interactive sessions, as well as 6+ hours of networking, including seated lunches and a drinks reception. Over 2 days, you’ll learn how to build resilience, mitigate risks, and strengthen your cybersecurity strategy to combat new and ongoing threats through thought leadership talks, in-depth case studies, panel...

Read More

Roper St. Francis Healthcare Settles Data Breach Lawsuit for $1.5 Million

Roper St. Francis Healthcare has agreed to a $1.5 million settlement to resolve a class action lawsuit that was filed in response to a data breach in 2020. Roper St. Francis Healthcare is a South Carolina-based healthcare system with 4 hospitals and more than 117 healthcare facilities in the state. In late October 2020, Roper St. Francis Healthcare discovered three email accounts had been compromised after employees responded to phishing emails. The email accounts were accessed by unauthorized individuals between October 14 and October 29, 2020. The compromised accounts contained the protected health information of 89,761 patients, including names, medical record numbers, patient account numbers, dates of birth, and limited treatment and clinical information, such as dates of service, locations of service, providers’ names, and billing information. A lawsuit was filed in response to the breach that claimed Roper St. Francis Healthcare was negligent by failing to implement reasonable and appropriate cybersecurity measures, and that Roper St. Francis Healthcare should have been aware...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist