25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The Chattanooga Heart Institute Doubles 2023 Cyberattack Victim Count

The Chattanooga Heart Institute in Tennessee has confirmed that the protected health information of 411,383 individuals was compromised in a cyberattack that was discovered on April 17, 2023. On July 28, 2023, the Chattanooga Heart Institute notified the HHS’ Office for Civil Rights and the Maine attorney general about the cyberattack, which was thought to have involved the protected health information of 170,450 individuals. A supplemental breach notification has now been sent to the Maine Attorney General, confirming the data breach was more extensive than the initial investigation suggested. The investigation into the attack is ongoing, but it has now been confirmed that an unauthorized third party had access to its network between March 8 and March 16, 2023, and exfiltrated files containing patients’ protected health information. While its electronic medical record system remained secure, files were accessed and exfiltrated that contained information such as names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers,...

Read More

FBI: Plastic Surgery Offices Targeted by Extortion Groups

U.S. plastic surgery offices are being targeted by cybercriminal groups that gain access to their networks, steal data, and attempt to extort the practices and their patients, according to a recent public service announcement from the U.S. Federal Bureau of Investigation (FBI). There have been several attacks on plastic surgery providers in recent months. While ransomware may be used in these attacks, the primary purpose of the attacks is to steal sensitive patient data, which can include medical records and sensitive pre- and post-surgery photographs. Plastic surgery centers are issued with a ransom demand, payment of which is required to prevent the release of the stolen data. In some cases, sensitive patient data and images have been released online, and the threat actors have attempted to extort the patients directly. One attack on the Hollywood, CA-based plastic surgeon, Gary Motykie, M.D. in May 2023, required payment of a $2.5 million ransom to prevent the release of the stolen data. Some of the practice’s patients were contacted directly and told to pay to have their...

Read More
Healthcare Clearinghouse Settles Multi-state HIPAA Investigation for $1.4 Million
Oct18

Healthcare Clearinghouse Settles Multi-state HIPAA Investigation for $1.4 Million

Inmediata has agreed to a $1.4 million settlement to resolve a multi-state investigation of potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state breach notification laws. On January 15, 2019, the Department of Health and Human Services’ Office for Civil Rights (OCR) notified the Puerto Rico-based healthcare clearinghouse that a server containing the protected health information that it maintained had not been properly secured, resulting in files being indexed by search engines that could be found, accessed, and downloaded by anyone with Internet access. The files on the server contained the protected health information of 1,565,338 individuals and some of those files dated as far back as May 2016. The HIPAA Breach Notification Rule requires HIPAA-covered entities to issue notifications to individuals affected by a data breach without undue delay and no later than 60 days from the discovery of a data breach. Despite being notified about the breach by OCR, the primary HIPAA regulator, Inmediata waited three months to mail notification...

Read More
What is OSHA Certification?
Oct17

What is OSHA Certification?

OSHA certification is a recognition workers obtain for completing courses in OSHA’s Safety and Health Fundamentals Program. Some OSHA certification courses are designed to teach general workplace safety, while others may be geared towards specific hazards or specific roles. Examples include: Job Hazard Analysis Health Hazard Awareness Electrical Standards Industrial Hygiene Machinery and Machine Guarding Standards Permit-Required Confined Space Entry Bloodborne Pathogen Exposure Control Occupational Noise Exposure Hazards Training Guidelines for Safe Patient Handling Fall Hazard Awareness for the Construction Industry How to Obtain OSHA Certification in the Fundamentals Program OSHA’s Safety and Health Fundamentals Program awards certificates to participants who complete a minimum of seven courses. The courses vary in length from 4 hours up to 35 hours, and participants must complete at least 68 contact hours of training for a construction or general industry certificate, or 77 contact hours of training for a maritime certificate. The courses are run at OSHA Training...

Read More

Governor Newsom Signs California Delete Act into Law

The California Delete Act enables state residents to request that data brokers delete all personal data maintained about them via a centralized database maintained on the CPPA website rather than having to make a request to each data broker in California. The Act also requires data brokers to visit the database at least once every 45 days to review and process new deletion requests. On October 10, 2023, California Governor Gavin Newsom signed the Delete Act (Senate Bill 362) into law. The bill was introduced in April 2023 by Senator Josh Becker to give California residents greater control over their personal information and how it is used by data brokers. Data brokers sell millions of consumers’ data points to the highest bidder. That information includes purchasing data, which can be accessed by retailers and used to serve targeted ads. More sensitive information may also be collected and sold, such as geolocation information and even reproductive health information. The new law will allow state residents to request that data brokers delete their personal data and/or forbid them...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist