25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Lifeline Systems Company Notifies Patients About August 2022 Cyberattack

Lifeline Systems Company, a Marlborough, MA-based provider of patient alarm systems has recently notified 74,849 individuals about a data breach that occurred more than a year ago. According to the notification letters, unusual network activity was detected on August 6, 2022. Incident response protocols were immediately initiated, and a third-party computer forensic investigation was launched to investigate the nature of the incident. The investigation confirmed that an unauthorized individual had access to its systems from July 27, 2022, to August 6, 2022, and accessed certain documents on its systems during that period. On August 18, 2022, Lifeline determined the documents included information for subscribers, employees, and individuals eligible to receive Lifeline services. The exposed information included names, driver’s license numbers, and Social Security numbers. Due to the length of time taken to perform the document review, notification letters could not be sent until September 7, 2023. Complimentary credit monitoring services have been offered to individuals who had their...

Read More

Cyberattacks Reported by Bienville Orthopaedic Specialists and Just Kids Dental

A round-up of data breaches that have recently been reported to the HHS’ Office for Civil Rights, state Attorneys General, and the media. 242,986 Patients Had PHI Compromised in Cyberattack on Bienville Orthopaedic Specialists Bienville Orthopaedic Specialists in Gautier, MS, has reported a data breach to the Maine Attorney General that has affected up to 242,986 patients. A security breach was detected on March 5, 2023, and systems were immediately taken offline to prevent further unauthorized access. A forensic investigation was initiated to determine the nature and scope of the attack, which confirmed there had been unauthorized access to its systems between February 3, 2023, and March 5, 2023. The threat actor acquired files from its systems on March 4, 2023. The review of the affected files was completed on July 31, 2023, and it was determined that names and Social Security numbers had been compromised. Additional technical safeguards have now been implemented to prevent similar incidents in the future. Credit monitoring services are being offered to the affected individuals...

Read More

IBM Notifies Janssen CarePath Patients About Unauthorized Database Access

IBM has recently announced that the sensitive data of patients of the Johnson & Johnson Health Care Systems subsidiary, Janssen CarePath, has been exposed. IBM is a business associate of Johnson & Johnson and manages the application and database that supports the Janssen CarePath platform. Janssen recently became aware of a method that could be used by unauthorized individuals to gain access to the database and notified IBM, which worked with the database provider and remediated the problem. IBM also conducted an investigation to determine if the database had been accessed by unauthorized individuals and confirmed unauthorized access had occurred on August 2, 2023; however, it was not possible to determine the nature of the access and if patient data had been exfiltrated. Since patient data may have been accessed, IBM has issued notification letters to the affected Janssen CarePath customers. The data exposed included names in combination with one or more of the following data types: contact information, date of birth, health insurance information, medications, and...

Read More

Medtronic & Edward-Elmhurst Health Sued Over Web Tracker Use

The Minneapolis, MN-based medical device manufacturer Medtronic & the Illinois health system Edward-Elmhurst Health are facing class action lawsuits over the use of website tracking technologies, which passed sensitive customer data to third parties such as Google and Meta. Medtronic MiniMed and MiniMed Distribution Corp A lawsuit has been filed against Medtronic MiniMed Inc. and MiniMed Distribution Corp (Medtronic) over the use of tracking technologies in its InPen diabetes management app. The lawsuit – A.H. v. Medtronic MiniMed Inc. and MiniMed Distribution Corp – was filed in District Court for the Central District of California on behalf of plaintiff A.H, and similarly situated individuals who had their sensitive information disclosed to third parties via Google Analytics, Firebase, and Crashlytics. Medtronic reported the data breach to the HHS’ Office for Civil Rights in April as affecting 58,374 individuals and notified customers that email addresses, IP addresses, phone numbers, InPen App usernames and passwords, timestamp information for InPen App events, and...

Read More

CentroMed Facing 2 Class Action Lawsuits Over 350,000-Record Data Breach

El Centro Del Barrio, dba CentroMed in San Antonio, TX, is facing at least two class action lawsuits over a June 2023 cyberattack in which hackers gained access to the personal and protected health information (PHI) of 350,000 patients. The attack was detected on June 12, 2023, and the forensic investigation confirmed unauthorized access to IT systems first occurred on June 9, 2023. The information accessed in the attack included names, addresses, dates of birth, Social Security numbers, financial account information, medical record numbers, health insurance plan member IDs, and claims data. The affected individuals were notified by mail on August 11, 2023. CentroMed patients Jasmine Grace and Dawn Leal have each taken legal action against CentroMed over the impermissible disclosure of their personal information and allege CentroMed was negligent for failing to properly secure and safeguard their personally identifiable information, which is now in the hands of cybercriminals. They both claim they face an imminent, ongoing, and substantial risk of identity theft and fraud and have...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist