25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Can a Nurse be Fired for a HIPAA Violation?

A nurse can be fired for a HIPAA violation if the nature of the violation is sufficiently serious to warrant a termination of contract or if the nurse has demonstrated a pattern of noncompliance through a series of HIPAA violations. Whether or not a nurse will be fired for a HIPAA violation depends on the terms of their employer’s sanctions policy. Violate HIPAA Rules and having your employment contract terminated may not be the worst thing that will happen. There may also be criminal charges for HIPAA violations. Jail time is likely if protected health information (PHI) is stolen and passed on to an identity thief, although HIPAA Privacy Rule violations alone can result in a jail term. If there is aggregated identity theft, there will be a mandatory two-year sentence tacked on to the sentence. When a nurse is fired for a HIPAA violation, finding alternative employment can be problematic. Few healthcare organizations would be willing to hire an employee that has previously been fired for violating HIPAA Rules. In January 2022, a nurse aide was fired from Wayne Memorial Hospital for...

Read More

Judge Grants Preliminary Approval of Salud Family Health’s Proposed Data Breach Settlement

Salud Family Health Inc. has agreed to settle a class action lawsuit that was filed in response to a cybersecurity incident that saw unauthorized individuals gain access to its network and sensitive patient data in early September 2022. More than 427,540 individuals had their protected health information exposed in the incident, including names, Social Security numbers, driver’s license numbers, state identification card numbers, credit card numbers, passport numbers, financial account information, medical treatment/ diagnosis information, health insurance information, biometric data, and usernames and passwords. The Lorenz ransomware group claimed responsibility for the attack and claimed to have exfiltrated more than 400,000 Social Security numbers. In February 2023, the law firm Shub & Johns LLC filed a class action lawsuit in the United States Court for the District of Colorado on behalf of the individuals affected by the data breach. A consolidated amended complaint was subsequently filed in the 19th District Court for the State of Colorado in Weld County, Alexander, et...

Read More
Indiana Attorney General Sues IU Health for Violating Rape Victim’s Privacy
Sep18

Indiana Attorney General Sues IU Health for Violating Rape Victim’s Privacy

On Friday, Indiana Attorney General, Todd Rokita, filed a lawsuit in the U.S. District Court for the Southern District of Indiana on behalf of the people of Indiana against University of Indiana Health (IU Health) and IU Health Associates, doing business as IU Health Physicians. The 7-count lawsuit alleges the defendants violated the Health Insurance Portability and Accountability Act (HIPAA) and state laws for failing to protect the privacy of a patient. The patient in question was a 10-year-old rape victim who sought abortion care at IU Health. The patient and her mother checked into an IU Health-operated hospital on June 29, 2022, to terminate a pregnancy that resulted from the rape. While Indiana has now implemented a near-total ban on abortions following the decision of the Supreme Court to overturn Roe v. Wade, the termination was provided legally at IU Health before the ban took effect. The lawsuit relates to a news report in the Indianapolis Star that was printed the day after the termination procedure was performed. The newspaper article included a quote from the girl’s...

Read More

Amerita Confirms 219,700 Patients Affected by PharMerica Cyberattack

The Kansas-based pharmaceutical and infusion product provider Amerita has recently notified 219,707 individuals that some of their protected health information was exposed in a cyberattack on the computer network of Amerita and its parent company, PharMerica. According to the notification letters, suspicious activity was detected in its computer systems on March 13, 2023. The forensic investigation confirmed that unauthorized individuals had access to its network from March 12 to March 13, 2023, and during that time, files may have been obtained from its systems. Amerita confirmed that the information potentially compromised in the incident included names, addresses, medical histories, diagnoses, medications, and health insurance information. No evidence was found to suggest Social Security numbers and driver’s license numbers were compromised. Amerita and PharMerica have enhanced their technical security measures to prevent similar incidents in the future. Amerita did not state the exact nature of the attack in its notification letters; however, this appears to have been a...

Read More

OCR; ONC Release Updated Security Risk Assessment Tool

The HHS’ Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) have released an updated version of their Security Risk Assessment (SRA) Tool. The risk analysis is one of the most important requirements of the HIPAA Security Rule. HIPAA-regulated entities are required to conduct a risk analysis to identify and assess all potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). If a thorough and accurate organization-wide risk analysis is not conducted, risks and vulnerabilities are likely to remain unaddressed and can be exploited by malicious actors to gain access to ePHI. Despite its importance, many HIPAA-regulated entities fail to comply with this requirement and the HIPAA Security Rule. Risk analysis failures are one of the most common HIPAA violations uncovered by OCR in its data breach investigations and HIPAA compliance reviews. The SRA tool is a downloadable desktop application that was developed by ONC in collaboration with OCR to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist