25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Congress Members’ Prescription Information Compromised in RXNT Data Breach
May15

Congress Members’ Prescription Information Compromised in RXNT Data Breach

Further information has come to light about the RXNT data breach, reported by the HIPAA Journal on May 6, 2026. As detailed below, hackers had access to RXNT’s systems for two days in March and stole patient data. While the extent of the data breach has yet to be publicly disclosed, the breach is now known to have involved Congress members’ prescription data. RXNT’s medical software is used by the Office of the Attending Physician (OAP) to manage care for members of Congress. The software is used to securely transmit prescription information to pharmacies for fulfillment, and some of that information was stolen in the attack, including names, addresses, dates of birth, physician names, and prescription and pharmacy information. Attending physician Brian Monahan has notified the affected members of Congress this week about the exposure of their personal and health data. Congress members’ medical records, Social Security numbers, and financial information were not involved, as the only information entered into the RXNT software is what is required for prescription fulfillment....

Read More
Ransomware Groups Claim Responsibility for Attacks on 3 Healthcare Providers
May15

Ransomware Groups Claim Responsibility for Attacks on 3 Healthcare Providers

Ransomware groups have claimed responsibility for attacks on Advanced Family Surgery Center in Tennessee, Orem Eye Clinic in Utah, and Belmont Aesthetic & Reconstructive Plastic Surgery in Virginia/Washington D.C. Surgery Center of Oak Ridge (Advanced Family Surgery Center) Surgery Center of Oak Ridge, LLC, doing business as Advanced Family Surgery Center in Oak Ridge, Tennessee, has notified certain patients about a network intrusion first identified on or around November 26, 2025. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that certain parts of its network were accessed by an unauthorized third party who potentially viewed or acquired files containing patient information. The files were reviewed and found to contain names, addresses, dates of birth, dates of service, health insurance information, medical diagnosis information, medical record numbers, Medicare/Medicaid numbers, patient account numbers, prescription/treatment information, provider names, and Social Security numbers. Additional security measures have been...

Read More
Former Nuance Employee Sentenced for 1.2 Million-record Geisinger Health System Data Breach
May15

Former Nuance Employee Sentenced for 1.2 Million-record Geisinger Health System Data Breach

A former employee of Nuance Communications, a business associate of Geisinger Health System that provided IT and conversational AI services, has been sentenced for unlawfully accessing and copying the data of 1.2 million patients. Max Vance (now Andre J. Burk), 46, of El Cajon, California, a former principal healthcare engineer, was disgruntled after being terminated by Nuance Communications and attempted to use his login credentials to access Nuance’s systems after termination. His credentials should have been immediately revoked upon termination to prevent any attempt at unauthorized access, but his credentials were still valid two days after termination. Vance proceeded to download a huge volume of patient data – 1.2 million patient records, including names, contact information, birth dates, admission/discharge/transfer codes, medical record numbers, and race/gender information. The removal of the data was detected by Geisinger, who notified Nuance, which immediately revoked Vance’s credentials. Law enforcement was alerted, and Vance was arrested. Vance pleaded...

Read More
Free Webinar: HIPAA Email Security 101: PHI, Encryption, and What’s Required
May15

Free Webinar: HIPAA Email Security 101: PHI, Encryption, and What’s Required

According to the Paubox 2026 Healthcare Email Security Report, in 2025, 170 email-related data breaches were reported to the HHS’ Office for Civil Rights (OCR). While healthcare organizations are getting better at preventing email-related data breaches, an analysis of email security configurations found that in 2025, 41% of healthcare organizations fell into the high-risk category, an increase from the previous year. On top of those large healthcare data breaches are the thousands of smaller breaches that affect fewer than 500 individuals, a large percentage of which are due to poor email security configurations and errors by healthcare employees. Each email incident erodes trust, can be costly to resolve, and potentially puts the organization at risk of a HIPAA penalty, yet email compliance failures are easily avoided. On May 21, 2026, the leading healthcare email security company, Paubox, is hosting a webinar to explain HIPAA email security 101. The webinar consists of a practical session covering the fundamentals of HIPAA-compliant email, what constitutes PHI, and how to...

Read More
Verber Dental Group Notifies Patients About January Hacking Incident
May14

Verber Dental Group Notifies Patients About January Hacking Incident

Data breaches have recently been announced by Verber Dental Group in Pennsylvania, Northwoods Surgery Center in Minnesota, Cunningham Prosthetic Care in Maine, Healthcare In Action in California, and Preakness Healthcare Center in New Jersey. Verber Dental Group Verber Dental Group, a Camp Hill, PA-based dental group comprising 14 dental practices, has recently notified patients of unauthorized network access that exposed patient data. Suspicious network activity was identified on January 27, 2026. The network was secured, and an investigation was launched, which revealed the threat actor had access to its network from January 26, 2026, to January 27, 2026. The investigation confirmed that patient information had been exposed, including names, dates of birth, Social Security numbers, driver’s license numbers/state identification numbers, medical records, and health insurance information. Verber Dental has not identified any misuse of patient information. Complimentary credit monitoring and identity theft protection services have been offered to the affected individuals as a...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist