NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack
Sep09

Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack

It has been two weeks since a cyberattack on the Massachusetts-based medical device manufacturer Boston Scientific prevented access to critical information systems and caused major disruption to operations globally. The attack was detected on August 25, 2026, and the company quickly activated its incident response protocol, contained the attack, and has been working round the clock to investigate the unauthorized activity and safely and securely bring systems back online. Boston Scientific notified the U.S. Securities and Exchange Commission (SEC) about the attack on August 26, 2026, although at the time it was unclear to what extent, if any, the incident would impact its financial position. On September 8, 2026, Boston Scientific submitted another Form 8-K filing with the SEC providing further information on the attack and recovery progress, confirming that the incident is likely to have a material impact on the company’s results of operations for the third quarter and the full year. Boston Scientific explained that the company is unlikely to meet its net sales growth and adjusted...

Read More
OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement
Sep08

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack and data breach that affected more than 2.65 million individuals. The cyberattack that sparked the litigation was identified on April 28, 2022, when files were encrypted on its network. The forensic investigation determined that a ransomware group first accessed its network the previous day on April 27, 2022. Data exposed and potentially stolen in the incident included names, subscriber ID numbers, diagnoses, medications, addresses, dates of birth, sex, physician demographic information, family histories, social histories, allergies, vitals, immunizations, and other information. OneTouchPoint reported the data breach to the HHS’ Office for Civil Rights as affecting 2,651,396 individuals and issued notifications to the affected individuals in April 2022. Multiple class action lawsuits were filed in response to the data breach, all of which asserted similar claims. The lawsuits alleged that the data breach should have been prevented and was due to...

Read More
NFI North Data Breach Affects Almost 50,000 Individuals
Sep08

NFI North Data Breach Affects Almost 50,000 Individuals

Data breaches have been announced by NFI North in New Hampshire, Nephrology Associates in Kansas, PAMCAH-UA Local 675 Health and Welfare Fund in Hawaii, and Indico Data Solutions in Massachusetts. NFI North, Inc. NFI North, Inc., a Contoocook, New Hampshire-based nonprofit human services organization that provides mental health, behavioral, and educational support services in New Hampshire and Maine, has notified the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) about a breach of the protected health information of 49,540 individuals. According to the NFI North substitute breach notice, suspicious activity was identified within its network on or around September 6, 2025. The investigation and data review concluded on July 6, 2026, when it was confirmed that data compromised in the incident included names, addresses, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. NFI North engaged cybersecurity professionals to assist with the investigation, and...

Read More
Luminis Health Working to Restore Systems After Cyberattack
Sep07

Luminis Health Working to Restore Systems After Cyberattack

Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey. Luminis Health, Maryland Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled. Currently, the phone system and MyChart patient portal remain offline. Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will...

Read More
June 2026 Healthcare Data Breach Report
Sep07

June 2026 Healthcare Data Breach Report

In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day. The year-to-date figures (Jan 1-Jun 30) show that healthcare data breaches are down 3.2% from the corresponding period in 2024 and down 6.4% from the corresponding period last year, although they are still occurring in significantly higher numbers than in 2022 and 2023. Across June’s 66 large healthcare data breaches, the protected health information of at least 4,499,972 individuals was exposed, stolen, or impermissibly disclosed. As data breach investigations continue, that figure is likely to increase. Based on current data,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist