25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Advocate Aurora Health and WakeMed Sued Over Meta Pixel Privacy Breaches

Two class action lawsuits have been filed on behalf of patients whose protected health information (PHI) was impermissibly disclosed to Meta/Facebook as a result of the use of the Meta Pixel JavaScript code snippet on the websites and web applications of Advocate Aurora Health and WakeMed Health and Hospitals. Advocate Aurora Health said the PHI of up to 3 million patients had potentially been disclosed to Meta/Facebook, and WakeMed said around 495,000 patients were affected due to the inclusion of the code on the MyChart patient portal and its appointment scheduling page. Both healthcare providers have admitted to an impermissible disclosure of PHI but said at the time of issuing notifications that they were unaware of any cases of misuse of patient information and that there are no indications that employees of Meta or Facebook viewed the transmitted data. The lawsuit against Advocate Aurora Health, which also names Meta as a defendant, was filed in the U.S. District Court for the Northern District of Illinois and names Alistair Stewart, of Illinois, as the lead plaintiff. The...

Read More
Georgia Home Health Company Settles Phishing Investigation and Pays $425,000 Penalty
Nov04

Georgia Home Health Company Settles Phishing Investigation and Pays $425,000 Penalty

Aveanna Healthcare has agreed to pay a $425,000 financial penalty to the Office of the Attorney General of Massachusetts for failing to implement appropriate safeguards to prevent phishing attacks, in violation of state and federal laws. Aveanna Healthcare operates in 33 states and is the nation’s largest provider of pediatric home care. In the summer of 2019, Aveanna Healthcare was targeted in a phishing campaign that saw more than 600 phishing emails sent to its employees. The phishing emails attempted to trick the recipients into providing credentials, money, or other sensitive information. The first email account was breached in July 2019, with the attacks continuing throughout the summer. Aveanna Healthcare discovered the breach on August 24, 2019. The forensic investigation revealed multiple employees had been tricked into disclosing their account credentials, which provided the attackers with access to parts of the network that contained the protected health information (PHI) of 166,000 patients, including the PHI of approximately 4,000 Massachusetts residents. The patient...

Read More
OSHA was Created in What Year?
Nov03

OSHA was Created in What Year?

There are two answers to the question OSHA was created in what year because the acronym OSHA has two meanings – the Occupational Safety and Health Act and the Occupational Safety and Health Administration – and each were “created” in different years. Strictly speaking, both the Occupational Safety and Health Act and the Occupational Safety and Health Administration evolved in different years – rather than were created. This is because although Congress passed the Act in 1970, and the Administration started enforcing the Act the following year, the regulation of occupational safety and health started almost 200 years earlier. The History of Safety and Health Legislation The earliest recorded safety and health legislation was passed by the First Congress of the United States in 1790. The legislation gave a ship´s crew the authority to order a vessel into the nearest port if the majority of the crew and the first mate believed the ship was unseaworthy. Although the legislation was unenforceable, it demonstrated some federal responsibility towards workers´ safety. Further...

Read More

Anesthesia, Eye Care, and Telehealth Providers Announce Third-Party Data Breaches

Several more providers of anesthesia services have confirmed they have been affected by a data breach at their management services organization (MSO). Last month, HIPAA Journal reported that 13 providers of anesthesia services to hospitals had been affected by the breach. At least nine more healthcare providers are now known to have been affected, bringing the total to at least 22. The latest announcements bring the breach total up to 433,826 records. Somnia Pain Mgt of Kentucky – 10,849 individuals Primary Anesthesia Services – 9,517 individuals Saddlebrook Anesthesia Services PC – 8,861 individuals Resource Anesthesiology Associates Of KY PSC – 8,980 individuals Resource Anesthesiology Associates of NM Inc – 7,054 individuals Resource Anesthesiology Associates of VA LLC – 3,305 individuals Resource Anesthesiology Associates of CT PC – 3,123 individuals Somnia, Inc. – 1,326 individuals Mid-Westchester Anesthesia Services – 707 individuals The breach was detected by the MSO on July 11, 2022, with the forensic investigation determining information...

Read More

President Biden Declares November as Critical Infrastructure Security and Resilience Month

The White House has issued a proclamation from President Biden declaring November as Critical Infrastructure Security and Resilience Month – A month dedicated to raising awareness of the need to improve critical infrastructure and strengthening the resilience of critical infrastructure against physical and cyber threats. President Biden has recommitted to improving and fortifying critical infrastructure, “by building better roads, bridges, and ports; fortifying our information technology and cybersecurity across sectors, including election systems; safeguarding our food and water sources; moving to clean energy; and strengthening all other critical infrastructure sectors,” and by doing so will lay the foundation for long-term security and prosperity. One of the main focus areas is improving defenses and shielding critical infrastructure against malicious cyber activity. President Biden has confirmed his administration will be establishing clear international rules of the road as they relate to cyberspace. In the United States, most critical infrastructure is owned and operated by...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist