25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Ransomware Attack on New York Billing Company Affects 942K Individuals
Aug17

Ransomware Attack on New York Billing Company Affects 942K Individuals

Practice Resources, a Syracuse, NY, provider of billing and other professional services, has suffered a data breach involving the records of 942,138 individuals. According to the breach notification sent to the California Attorney General, Practice Resources was the victim of a ransomware attack on April 12, 2022. Assisted by third-party digital forensics experts, Practice Resources determined that there had been unauthorized access to parts of the network where the protected health information of its clients was stored and the attackers may have infiltrated that information prior to file encryption. A review of the documents potentially affected by the attack confirmed they contained information such as names, addresses, dates of treatment, health plan numbers, and medical record numbers. Practice Resources has offered affected individuals a complimentary membership to an identity theft protection and credit monitoring service. Practice Resources said it has issued notification letters to affected individuals on behalf of 28 clients that were affected by the data breach. Achieve...

Read More

United Health Centers of San Joaquin Valley Notifies Patients About August 2021 Ransomware Attack

In August 2021, the Vice Society ransomware operation published data on its data leak site that had allegedly been obtained in a ransomware attack on United Health Centers of San Joaquin Valley.  On August 31, 2021, Bleeping Computer was made aware of the data leak and made multiple attempts to notify United Health Centers. The website DataBreaches was also made aware of the data breach and similarly attempted to notify United Health Centers on multiple occasions. HIPAA Journal reported on the incident in September 2021. Almost a year on and individuals whose protected health information was exposed or stolen in the attack have been notified by United Health Centers. The breach notification provided to the California Attorney General on August 12, 2022, explains that technical difficulties were experienced by United Health Centers on August 28, 2021, which caused disruption to its computer systems. Steps were immediately taken to secure its network and systems, and an investigation was launched to determine the nature of the incident. United Health Centers said it discovered on...

Read More

Novant Health Notifies 1.36 Million Patients About Unauthorized Disclosure of PHI via Meta Pixel Code on Patient Portal

Novant Health has recently notified 1,362,296 patients about a breach of their protected health information due to the incorrect configuration of Meta Pixel code on its patient portal. Code Snippet Sending Sensitive Patient Data to Meta Earlier this year, an investigation conducted by The Markup into the use of Meta Pixel code on healthcare providers’ websites revealed 33 of the top 100 hospitals in the United States had included Meta Pixel code on their websites, and 7 of those hospitals had added the code to their password-protected patient portals. The 7 hospitals discovered by The Markup to have installed Meta Pixel on their patient portals were Community Health Network, FastMed, Edward-Elmhurst Health, Piedmont, Renown Health, WakeMed, and Novant Health. Meta Pixel is a snippet of JavaScript code that is used to track website visitors, and the information gathered is sent to Meta (Facebook), which may be used to serve targeted ads. Meta claims that organizations that use Meta Pixel are not supposed to send sensitive data. If Meta discovers it has been sent sensitive data by...

Read More
How the FIDO Alliance Aims to Make Logging In More Secure
Aug16

How the FIDO Alliance Aims to Make Logging In More Secure

The Fido Alliance is an association of businesses from many different industries with a shared vision – to make logging in to online services more secure. The Alliance aims to achieve its vision by developing standards for user authentication and device attestation that will – it is hoped – replace the world´s “over-reliance on passwords”. The failure to use strong, unique passwords for each account – and the failure to keep the passwords secure – is the leading cause of data breaches; and while technologies exist that can prevent password-related data breaches, they are not as widely adopted as they should be because end users would rather sacrifice security for convenience. Acknowledging that poor online security is an issue that´s not going to go away, the FIDO Alliance evolved from an idea initiated by PayPal and Validity Sensors to replace passwords with biometric logins. The idea gained traction, and the Alliance was  launched in 2013 with the support of companies such as Google, Lenovo, Samsung, and Yubico. Since its launch, the FIDO Alliance has published three sets of...

Read More
Is Cloud Computing HIPAA Compliant?
Aug15

Is Cloud Computing HIPAA Compliant?

Cloud computing has revolutionized the way healthcare organizations operate, but ensuring cloud computing is HIPAA compliant can be a challenge. Many healthcare organizations have already embraced cloud technologies, but as with any technology, care must be taken as there is considerable potential for HIPAA violations in the cloud. Here we consider how healthcare organizations can use cloud computing in a HIPAA-compliant manner. There is an extensive range of Cloud Service Providers (CSPs) and their products differ in terms of storage limits, accessibility, and security configurations, Covered Entities are advised to research CSPs and ensure that a product supports HIPAA compliance. They should establish how they will use the cloud computing technologies, conduct a risk assessment, and ensure all staff members are trained on how to use a CSP’s products and services. All CEs are required to obtain a signed business associate agreement (BAA) from their chosen CSP prior to using that service in connection with any protected health information (PHI). BAAs outline the responsibilities...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist