25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities
May22

May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities

A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program. University of Nebraska Medical Center University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible...

Read More
Radiology Associates of Richmond Data Breach Affects 266K Individuals
May22

Radiology Associates of Richmond Data Breach Affects 266K Individuals

Radiology Associates of Richmond in Virginia, one of the oldest, continuously operating private radiology practices in the United States, has announced another major data breach. Two years ago, the protected health information of more than 1.4 million individuals was compromised in a cybersecurity incident. A little over one year later, another cybersecurity incident was experienced that exposed the personal and protected health information of 266,183 current and former patients. The most recent incident has been reported to the Maine Attorney General as involving unauthorized access to the electronic personal and protected health information of 266,183 individuals. The breach notice does not state when the intrusion was detected; only that the forensic investigation determined that the unauthorized access occurred on or around July 25, 2026. The extensive forensic investigation and manual data review concluded on April 6, 2026, when it was confirmed that personal and protected health information was potentially viewed or acquired in the incident. A substitute data breach notice...

Read More
California & Washington Healthcare Providers Announce Data Breaches
May21

California & Washington Healthcare Providers Announce Data Breaches

Data breaches have been announced by Totem Lake Family Dentistry, Family Health Centers of San Diego, and Glendora Surgery Center. Totem Lake Family Dentistry Totem Lake Family Dentistry, a Kirkland, WA-based family dental practice, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 3,464 patients. According to the notification letters, suspicious activity was identified within an employee’s email account. The investigation confirmed unauthorized access to the account between May 28, 2025, and June 2, 2025. During that time, information in the account may have been viewed or copied. It has taken 11 months to review the contents of the account and mail notification letters to the affected individuals. At the time of issuing notification letters, Totem Lake Family Dentistry was unaware of any attempted or actual misuse of patient data. Credit monitoring and identity theft protection services do not appear to have been offered. Family Health Centers of San Diego Family Health Centers of San Diego is sending notification letters to...

Read More
Verizon: Healthcare Sector Facing Sustained, Multi-vector Attacks
May20

Verizon: Healthcare Sector Facing Sustained, Multi-vector Attacks

Verizon has published its 2026 Data Breach Investigations Report, which shows that the healthcare sector continues to be targeted by cybercriminal groups. The sector is having to contend with sustained multi-vector attacks, including ransomware, unpatched vulnerabilities, and human error. Regardless of the cause, the attacks are putting patient privacy, safety, and care at risk. Verizon tracked 1,492 healthcare incidents for its 2026 report, including 1,438 confirmed data disclosures, a majority of which were due to ransomware-driven system intrusions achieved through multiple attack vectors, including the exploitation of vulnerabilities (20%), phishing attacks (14%), stolen credentials (11%), and employee errors (11%). Threat actors are being given far too big a window of opportunity to exploit known vulnerabilities. Verizon found that in 2025, only 26% of critical vulnerabilities were fully remediated, with a median time for resolution stretching to 43 days. In healthcare, where complex legacy systems are the norm, the window of opportunity is greater, giving threat actors a wide...

Read More
HHS Announces Restructuring of Office for Civil Rights
May20

HHS Announces Restructuring of Office for Civil Rights

The U.S. Department of Health and Human Services (HHS) has announced it is restructuring its Office for Civil Rights (OCR), which will split into three divisions, each with specific responsibilities. HHS has recreated the Conscience and Religious Freedom Division (CRFD), which was established in January 2018 under the first Trump administration and operated until March 2023, when it was disbanded by the Biden administration. The Civil Rights Division has also been reestablished, following the amalgamation of both into the Policy Division under the Biden administration. CRFD is tasked with raising awareness of religious freedom laws and ensuring religious liberty, combating antisemitism and anti-Christian bias, and enforcing conscience protections. OCR enforces civil rights laws, including those that prohibit discrimination on the basis of race, color, national origin, sex, disability, age, or membership in patriotic youth organizations. These responsibilities will be handled by the Civil Rights Division, which will focus on addressing race-based discrimination in a color-blind...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist