25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cybersecurity is Now a Patient Safety Issue, Suggests Sen. Warner In Congressional Report
Nov04

Cybersecurity is Now a Patient Safety Issue, Suggests Sen. Warner In Congressional Report

Senator Mark Warner (D-VA), Chairman of the Senate Select Committee on Intelligence, has recently published a white paper – Cybersecurity is Patient Safety – that highlights the current cybersecurity challenges facing the healthcare industry and suggests several potential policy changes that could help to improve healthcare cybersecurity and better protect all health information, including health data not currently protected under the HIPAA Rules. Sen. Warner suggests the only way to improve healthcare cybersecurity rapidly is through a collaborative effort involving the public and private sectors, with the federal government providing overall leadership. While further regulation may be necessary, the overall consensus of healthcare industry stakeholders is the best approach is to introduce incentives for improving cybersecurity, rather than mandating cybersecurity improvements with a threat of financial penalties for noncompliance. The healthcare industry is under attack from cybercriminals and nation-state threat actors and cyberattacks and data breaches are increasing at...

Read More

Advocate Aurora Health and WakeMed Sued Over Meta Pixel Privacy Breaches

Two class action lawsuits have been filed on behalf of patients whose protected health information (PHI) was impermissibly disclosed to Meta/Facebook as a result of the use of the Meta Pixel JavaScript code snippet on the websites and web applications of Advocate Aurora Health and WakeMed Health and Hospitals. Advocate Aurora Health said the PHI of up to 3 million patients had potentially been disclosed to Meta/Facebook, and WakeMed said around 495,000 patients were affected due to the inclusion of the code on the MyChart patient portal and its appointment scheduling page. Both healthcare providers have admitted to an impermissible disclosure of PHI but said at the time of issuing notifications that they were unaware of any cases of misuse of patient information and that there are no indications that employees of Meta or Facebook viewed the transmitted data. The lawsuit against Advocate Aurora Health, which also names Meta as a defendant, was filed in the U.S. District Court for the Northern District of Illinois and names Alistair Stewart, of Illinois, as the lead plaintiff. The...

Read More
Georgia Home Health Company Settles Phishing Investigation and Pays $425,000 Penalty
Nov04

Georgia Home Health Company Settles Phishing Investigation and Pays $425,000 Penalty

Aveanna Healthcare has agreed to pay a $425,000 financial penalty to the Office of the Attorney General of Massachusetts for failing to implement appropriate safeguards to prevent phishing attacks, in violation of state and federal laws. Aveanna Healthcare operates in 33 states and is the nation’s largest provider of pediatric home care. In the summer of 2019, Aveanna Healthcare was targeted in a phishing campaign that saw more than 600 phishing emails sent to its employees. The phishing emails attempted to trick the recipients into providing credentials, money, or other sensitive information. The first email account was breached in July 2019, with the attacks continuing throughout the summer. Aveanna Healthcare discovered the breach on August 24, 2019. The forensic investigation revealed multiple employees had been tricked into disclosing their account credentials, which provided the attackers with access to parts of the network that contained the protected health information (PHI) of 166,000 patients, including the PHI of approximately 4,000 Massachusetts residents. The patient...

Read More
OSHA was Created in What Year?
Nov03

OSHA was Created in What Year?

There are two answers to the question OSHA was created in what year because the acronym OSHA has two meanings – the Occupational Safety and Health Act and the Occupational Safety and Health Administration – and each were “created” in different years. Strictly speaking, both the Occupational Safety and Health Act and the Occupational Safety and Health Administration evolved in different years – rather than were created. This is because although Congress passed the Act in 1970, and the Administration started enforcing the Act the following year, the regulation of occupational safety and health started almost 200 years earlier. The History of Safety and Health Legislation The earliest recorded safety and health legislation was passed by the First Congress of the United States in 1790. The legislation gave a ship´s crew the authority to order a vessel into the nearest port if the majority of the crew and the first mate believed the ship was unseaworthy. Although the legislation was unenforceable, it demonstrated some federal responsibility towards workers´ safety. Further...

Read More

Anesthesia, Eye Care, and Telehealth Providers Announce Third-Party Data Breaches

Several more providers of anesthesia services have confirmed they have been affected by a data breach at their management services organization (MSO). Last month, HIPAA Journal reported that 13 providers of anesthesia services to hospitals had been affected by the breach. At least nine more healthcare providers are now known to have been affected, bringing the total to at least 22. The latest announcements bring the breach total up to 433,826 records. Somnia Pain Mgt of Kentucky – 10,849 individuals Primary Anesthesia Services – 9,517 individuals Saddlebrook Anesthesia Services PC – 8,861 individuals Resource Anesthesiology Associates Of KY PSC – 8,980 individuals Resource Anesthesiology Associates of NM Inc – 7,054 individuals Resource Anesthesiology Associates of VA LLC – 3,305 individuals Resource Anesthesiology Associates of CT PC – 3,123 individuals Somnia, Inc. – 1,326 individuals Mid-Westchester Anesthesia Services – 707 individuals The breach was detected by the MSO on July 11, 2022, with the forensic investigation determining information...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist