NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

AdaptHealth Data Breach Affects 4.1 Million Individuals
Sep10

AdaptHealth Data Breach Affects 4.1 Million Individuals

In early July, we reported that AdaptHealth had notified the U.S. Securities and Exchange Commission that it had experienced a cybersecurity incident involving the theft of patient data. At the time of the Form 8-K filing, AdaptHealth had not determined the extent to which patient data was compromised in the incident. The HHS Office for Civil Rights has now been informed that the electronic protected health information of 4,115,802 individuals was compromised in the incident. AdaptHealth added a notice to its website on August 14, 2026, that provided further information on the data compromised in the incident.  The notice explains that the forensic investigation determined that the attack occurred on June 5, 2026, and the threat actor exfiltrated files containing names, contact information, demographic information, health insurance information, and health information. AdaptHealth explained that it is unaware of any actual or attempted misuse of that data; however, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft...

Read More
Medical Groups Settle Class Action Data Breach Lawsuits
Sep10

Medical Groups Settle Class Action Data Breach Lawsuits

Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee. Palomar Health Medical Group Data Breach Settlement Palomar Health Medical Group, a non-profit healthcare organization serving patients at 20 locations in North San Diego County and South Riverside County in Southern California, has agreed to settle class action litigation stemming from a Spring 2024 cybersecurity incident involving the protected health information of 1,140,221 individuals. The incident was identified on May 5, 2024, and the forensic investigation confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Data potentially stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, medical histories, health information, health insurance information, and other sensitive data. Several class action lawsuits were filed in response to the data breach, all of which alleged that the data...

Read More
FBI Raises Alarm About OAuth Consent Phishing Activity
Sep09

FBI Raises Alarm About OAuth Consent Phishing Activity

The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as OAuth consent phishing. Since late 2025, the FBI has observed malicious cyber actors using OAuth consent phishing in targeted attacks on prominent individuals, their family members, and personal acquaintances to gain persistent access to their accounts. Similar to other forms of targeted phishing, the campaign involves impersonation of a trusted entity and tricks the victim into granting access to their account; however, this approach does not require the victim to disclose their username and password. The technique relies on OAuth, a commonly used authorization framework that allows websites and web applications to request access to a user’s account on another application, without exposing their login credentials. With OAuth consent phishing, an attacker creates a malicious application and registers it with a legitimate OAuth provider. The application is configured with high-level privileges, such as the ability to access contacts, read and...

Read More
Wellstar Health System & Cone Health Settle Pixel Lawsuits
Sep09

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating Corporation (Cone Health). The lawsuits stem from the defendants’ use of pixels and other website tracking tools, which are alleged to have resulted in impermissible disclosures of patient data to third parties such as Meta and Google. Wellstar Health System Pixel Settlement Wellstar Health System, a Marietta, Georgia-based health system with more than 400 care locations in the state, was sued over its use of tracking tools on its website that are alleged to have resulted in the disclosure of personally identifiable information and protected health information to third parties such as Alphabet Inc. (Google) and Meta Platforms (Facebook), without website users’ knowledge or consent. The first lawsuit was filed on April 23, 2024, and an amended complaint was filed on August 2, 2024, adding three additional plaintiffs. The lawsuit – Doe v. Wellstar Health System, Inc. –  is pending in the United States District Court for the Northern...

Read More
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider
Sep09

Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider

Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by Crystal Coast Pain Management, Golden State Orthopedics & Spine, Gardiner Family Chiropractic, and BestCare Treatment Services. Interim HealthCare of Oklahoma City Interim HealthCare, a home healthcare provider operating in 40 U.S. states, has been added to the data leak sites of two ransomware groups. The first listing was added to the Genesis ransomware group’s data leak site on August 10, 2026. Genesis claimed to have exfiltrated data in the incident and threatened to publish it if the ransom was not paid. Genesis claims the stolen data relates to Interim Healthcare of Oklahoma and Tulsa, and that 1TB of data was exfiltrated, including medical records, healthcare data, personal data, patient lists, clinical data, and company data. While a list of the compromised files was added to the data leak site, the data allegedly stolen has yet to be published. Then on August 21, 2026, a second ransomware group listed Interim HealthCare as one of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist