25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Southern Illinois Ob-Gyn Associates Announces Data Breach Affecting 38,700 Individuals
Jun08

Southern Illinois Ob-Gyn Associates Announces Data Breach Affecting 38,700 Individuals

A data breach at Southern Illinois Ob-Gyn Associates has affected 38,700 individuals. Data breaches have also been reported by Wellpoint Washington – involving Independent Clinics of Washington – and Dillon Family Medicine, part of McLeod Health. Southern Illinois Ob-Gyn Associates Southern Illinois Ob-Gyn Associates has notified 38,700 current and former patients about a breach of their personal and protected health information. The cybersecurity incident was identified on November 24, 2025, and after securing its systems, third-party cybersecurity experts were engaged to investigate and determine the nature and scope of the incident. They confirmed that its systems had been subject to unauthorized access, and on January 28, 2026, it was confirmed that there was unauthorized access to patient data. Data compromised in the incident included names, dates of birth, Social Security numbers, demographic information, health information, and health insurance information. Southern Illinois Ob-Gyn Associates said it has implemented additional technical safeguards and has...

Read More
Henderson & Walton Women’s Center Settles Class Action Data Breach Lawsuit
Jun08

Henderson & Walton Women’s Center Settles Class Action Data Breach Lawsuit

Henderson & Walton Women’s Center, a Birmingham, AL-based provider of women’s healthcare services, has agreed to settle a class action lawsuit stemming from a 2022 data breach that exposed the personal and protected health information of 34,306 individuals. The forensic investigation confirmed that an unauthorized third party had access to an employee’s email account between February 11, 2022, and February 14, 2022, and potentially obtained information such as names, dates of birth, driver’s license or state ID numbers, and medical and treatment information. Plaintiff Kim Townsel filed a lawsuit – Townsel v. Henderson & Walton Women’s Center, P.C. – against Henderson & Walton Women’s Center in the Circuit Court for Jefferson County, Alabama, over the data breach, alleging a failure to properly secure and safeguard the sensitive and confidential information of patients through the use of encryption and other cybersecurity measures. The lawsuit alleged that the failure amounted to negligence. In addition to the negligence and negligence per se claims, the...

Read More
HSCC Issues Guidance on Cyber Governance Frameworks for Secure AI Implementation
Jun08

HSCC Issues Guidance on Cyber Governance Frameworks for Secure AI Implementation

The Health Sector Coordinating Council (HSCC) AI cybersecurity governance task force has published new guidance for healthcare CISOs and other leaders to help them establish cybersecurity governance frameworks for secure AI implementation. Adoption of AI-based technologies in healthcare is progressing at a pace, with AI tools increasingly embedded into critical healthcare functions; however, these tools introduce new and often poorly understood cyber risks into already complex ecosystems. AI-specific cyber risks, such as data poisoning, model drift, and bias, can threaten successful implementation and HIPAA compliance, and the tools can create vulnerabilities that can be exploited by threat actors in attacks that impact patient privacy, safety, and care. Healthcare organizations should implement a strong governance structure that integrates cybersecurity principles into the full AI product lifecycle, from assessment, design, development, deployment, and decommissioning of AI systems. The guidance can be used to implement a cybersecurity governance framework for identifying and...

Read More
Episource 2025 Cyberattack Affected 6.7 Million Individuals
Jun08

Episource 2025 Cyberattack Affected 6.7 Million Individuals

Episource, a provider of medical coding, risk adjustment services, and software solutions, experienced a cyberattack in early 2025, in which files containing patient data were exfiltrated from its network. In June 2025, the forensic investigation had progressed, and it was confirmed that 5.4 million individuals had been affected. The investigation has since revealed the data breach was more extensive, involving unauthorized access to the electronic protected health information of 6,725,572 individuals, according to updated figures provided to the HHS’ Office for Civil Rights. With more than 6.7 million affected individuals, the data breach currently ranks as the third-largest healthcare data breach of 2025, behind the 13.9 million-record data breach at Aflac and the 62.2 million-record data breach at Conduent Business Services, and ranks as the 16th-largest healthcare data breach of all time. The threat group behind the incident remains unknown. In August last year, U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee Chairman, Sen. Bill Cassidy, M.D. (R-LA),...

Read More
Largest Healthcare Data Breaches of 2025
Jun05

Largest Healthcare Data Breaches of 2025

2025 was another bad year for healthcare data breaches. As of June, 2026, 2025, 772 healthcare data breaches affecting 500 or more individuals are listed on the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) breach portal, involving the exposure or theft of the protected health information of 139,721,832 individuals. That total is likely to increase further as there are several data breach investigations that have yet to conclude. Based on the current totals, 2025 was the worst ever year for large healthcare data breaches, beating the previous record of 746 data breaches set in 2023 by 3.49%.  In terms of affected individuals, 2025 was the third-worst year, behind the 289.8 million affected individuals in 2024 and the 183 million affected individuals in 2023. You can view the latest figures and how they compare to previous years on our Healthcare Data Breach Statistics page. Large healthcare data breaches increased by 4.18% year over year, although there was a 51.79% year-over-year decrease in affected individuals. Such a large decrease in affected...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist