25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Independent Living Systems Sued Over 4 Million-Record Data Breach

It has only been a few days since the Miami-based healthcare administration and managed care solutions provider, Independent Living Systems (ILS), issued notification letters about a data breach affecting 4,226,508 individuals but a lawsuit has already been filed in response to the data breach. Since this article was published, at least 5 lawsuits have now been filed against ILS over the data breach – the largest healthcare data breach to be reported so far this year. ILS identified the breach in July 2022 and determined unauthorized individuals had access to its network between June 30, 2022, and July 5, 2022. During that time they exfiltrated files containing sensitive patient data, including names, contact information, Social Security numbers, Medicare/Medicaid IDs, health information, and health insurance information. ILS posted a HIPAA breach notice on its website in September 2022 and informed the HHS’ Office for Civil Rights, using the common placeholder of 501 records until the full extent of the breach was known. In its notification letters, ILS said it was not...

Read More

Multiple Lawsuits Filed Against Arkansas Hospitals Over Data Breaches

Multiple class action lawsuits have been filed against two healthcare providers in Arkansas – Mena Regional Health System (MRHS) and Howard Memorial Hospital – over cyberattacks in which patient data was compromised. The lawsuits are currently pending in the District Courts in Arkansas and were filed in response to two data breaches that were discovered in 2022. MRHS discovered unauthorized access to its computer systems on November 8, 2022, and determined hackers had exfiltrated files from its systems more than a year earlier on October 30, 2021. The files included the protected health information of 84,814 patients, such as names, birth dates, Social Security numbers, financial account information, health insurance information, and diagnosis and treatment information. Notification letters were sent to affected individuals on November 22, 2022. Howard Memorial Hospital in Nashville discovered a cyberattack and data breach in early December 2022 and determined hackers had access to its network for more than two weeks between November 14, 2022, and December 4, 2022. During...

Read More

Senate Committee Told How Federal Government Can Improve Healthcare Cybersecurity

On Thursday last week, the U.S. Senate Committee on Homeland Security and Governmental Affairs held a hearing to examine cybersecurity risks to the healthcare sector, how healthcare providers and the federal government are working to combat those threats, and determine what the federal government needs to do to improve defenses against cyberattacks on the healthcare sector. “Relentless cyber-attacks show that foreign adversaries and cybercriminals will stop at nothing to exploit cybersecurity vulnerabilities our critical infrastructure and most essential systems,” said Committee Chairman, Gary C. Peters (D-MI). “What is most concerning about these attacks is that they don’t just compromise personal information, they can actually affect patient health and safety.” Peters explained that the committee has already taken important steps to strengthen cybersecurity for critical infrastructure sectors, including the healthcare sector, including advancing a bipartisan bill requiring critical infrastructure organizations to report cyber-attacks and ransomware payments to the Cybersecurity...

Read More

Alabama Healthcare Provider Announces 441,000-Record Data Breach

The Birmingham, AL, Heart Hospital, Cardiovascular Associates, has recently announced that unauthorized individuals gained access to certain parts of its network between November 28, 2022, and December 5, 2022, and removed files containing patient information. The breach was detected on December 5, 2022, and immediate action was taken to contain the breach and prevent further unauthorized access. A leading digital forensics firm was engaged to investigate the breach and confirmed data theft had occurred. The review of the affected files revealed they contained the following types of information: Full names, birth dates, addresses, Social Security numbers, health insurance information, medical record numbers, dates of service, provider/facility names, visit/procedure/diagnosis information, medical tests results and images, billing and claims information, passport numbers, driver’s license numbers, credit/ debit card information, and financial account information. The types of data compromised varied from patient to patient and the usernames and passwords of a limited number of...

Read More
UC San Diego Health Announces Impermissible Disclosure of Patient Data Due to Website Analytics Code
Mar20

UC San Diego Health Announces Impermissible Disclosure of Patient Data Due to Website Analytics Code

University of California (UC) San Diego Health is the latest healthcare organization to start notifying patients that some of their protected health information has been impermissibly disclosed to third parties due to the use of website tracking technologies. UC San Diego Health said the analytics code was added to its scheduling websites by one of its business associates, Solv Health, without authorization from UC San Diego Health. UC San Diego Health contracted with Solv Health to provide website hosting and management services. The analytics code captured limited data of visitors to the scheduling websites who booked in-person or telehealth appointments. The captured information was then impermissibly disclosed to the third parties that provided the code. UC San Diego Health did not state in its breach notifications who the third parties were but said they received first and last names, birth dates, email addresses, IP addresses, third-party cookies, reasons for the appointments, and insurance type (e.g., PPO, HMO, Other). UC San Diego Health confirmed that Social Security...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist