25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

General Physician Pays $2.5 Million to Settle Data Breach Litigation
Mar04

General Physician Pays $2.5 Million to Settle Data Breach Litigation

General Physician, P.C., a medical group serving patients in Western New York, has agreed to pay $2.5 million to settle a class action lawsuit over a 2024 data breach. Suspicious activity was identified within its email environment on June 12, 2024. The forensic investigation confirmed that an unauthorized third party had access to its email system from April 6, 2024, to June 12, 2024. Patient information exposed and potentially stolen in the incident included full names, addresses, Social Security numbers, financial account information, dates of birth, medical history information, mental and physical treatment information, diagnosis information, treating physician names, medical record numbers, and health insurance information. The data breach was initially reported to the HHS’ Office for Civil Rights using a placeholder figure of 501 individuals. The total was later updated to 167,387 individuals. Several class action lawsuits were filed in response to the data breach, which were consolidated – Newhart v. General Physician, P.C. – in the Supreme Court of the State of New...

Read More
Two California Medical Groups Announce Data Breaches
Mar04

Two California Medical Groups Announce Data Breaches

Data breaches have recently been announced by two California medical groups – Valley Radiology Consultants Medical Group, which serves San Diego County, and Nephrology Associates Medical Group, which serves the Riverside and San Bernardino counties. Valley Radiology Consultants Medical Group Valley Radiology Consultants Medical Group in California has announced a security incident and data breach that was first identified on September 15, 2025. Immediate action was taken to secure its network, and third-party cybersecurity experts were engaged to determine the nature and scope of the unauthorized activity. The investigation confirmed unauthorized access to its network and files containing patient information. On February 18, 2026, the file review was concluded, and Valley Radiology Consultants Medical Group obtained the final list of individuals to notify. There is currently no substitute data breach notice on its website, and the notice submitted to the California Attorney General has the types of data involved redacted. Individual notices include the types of information...

Read More
What is HIPAA Certification?
Mar04

What is HIPAA Certification?

HIPAA certification for individuals is certified HIPAA training combined with testing to verify awareness of HIPAA compliance requirements, typically conducted on an annual basis. Successful trainees receive a HIPAA compliance certificate. HIPAA Certification Requirements for Healthcare Professionals and Administrators Certifying that an organization’s workforce is HIPAA compliant can have similar benefits to those discussed above inasmuch as a compliant workforce is less likely to violate HIPAA or make mistakes that could result in data breaches. Achieving HIPAA certification demonstrates a reasonable amount of care to abide by the HIPAA Rules in the event of an OCR investigation or audit. For individual members of the workforce, HIPAA certification can help foster patient trust, support applications for promotion, and increase prospects in the job market. However, it is what workforce members learn during a certification program that can have the biggest impact on their professional lives, as this can help prevent unintentional violations that can have significant...

Read More
Insight Hospital and Medical Center Announces Cyberattack & Data Breach
Mar03

Insight Hospital and Medical Center Announces Cyberattack & Data Breach

Data breaches have been announced by Insight Hospital and Medical Center in Chicago and Community Health Action of Staten Island. BlueCross BlueShield of Tennessee has confirmed it was one of the healthcare organizations affected by the Conduent Business Services data breach. Insight Hospital and Medical Center Insight Hospital and Medical Center in Chicago has announced a data security incident that was first identified in September 2025.  Unusual activity was identified within its IT environment, and the forensic investigation confirmed unauthorized access to its network between August 22, 2025, and September 11, 2025. The data review is ongoing to determine the individuals affected and the data involved; however, the likely information compromised in the incident may include names, dates of birth, Social Security numbers, passport numbers, financial account information, treatment-related information, and health insurance information. Notification letters will be mailed to the affected individuals when the data review is completed. Two threat groups have claimed attacks on...

Read More
Senate HELP Committee Advances Healthcare Cybersecurity Bill
Mar03

Senate HELP Committee Advances Healthcare Cybersecurity Bill

The Senate Health, Education, Labor, and Pensions (HELP) Committee has advanced the Health Care Cybersecurity and Resiliency Act, with a 22-1 vote in favor of the bill. The Health Care Cybersecurity and Resiliency Act was first introduced in November 2025, followed by a largely unchanged bill that was reintroduced in December 2025. As the name suggests, the bill seeks to introduce new cybersecurity requirements to strengthen healthcare cybersecurity. Many of the bill’s requirements were included in the proposed update to the HIPAA Security Rule issued by the HHS’ Office for Civil Rights in the final days of the Biden administration. It remains to be seen whether the current administration will push ahead with the HIPAA Security Rule update, which has proven to be unpopular with health systems and provider associations. The Health Care Cybersecurity and Resiliency Act was proposed by a bipartisan group of senators – HELP Committee Chair Sen. Bill Cassidy (R-LA), and Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX), and could attract more support than the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist