25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2023
May12

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2023

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted a pair of reports to Congress on the state of compliance with the Health Insurance Portability and Accountability (HIPAA) Privacy, Security, and Breach Notification Rules, and breaches of unsecured protected health information for calendar year 2023, as required by Section 13424(a) of the Health Information Technology for Economic and Clinical Health (HITECH) Act. OCR maintains a data breach portal, through which HIPAA-regulated entities must submit their reports of breaches of unsecured protected health information, and a web page through which individuals may submit a health information privacy complaint. There has been a general trend of increasing data breaches and complaints, which is placing greater pressure on OCR’s limited resources; however, OCR made progress in decreasing the backlog of complaint and data breach investigations in 2023. The reports show data breaches affecting fewer than 500 individuals increased by 7% year-over-year, data breaches affecting 500 or more...

Read More
Missouri Regulators Claim Conduent is Stonewalling State’s Data Breach Investigation
May12

Missouri Regulators Claim Conduent is Stonewalling State’s Data Breach Investigation

An investigation by regulators in Missouri into the 2024 hacking incident at Conduent Business Services has stalled. The Missouri Department of Commerce claims it is being stonewalled by Conduent, which has not provided the information it requires about the data breach. Conduent, a provider of printing, mailroom, document processing, payment integrity, and other back-office support services, discovered in January 2025 that hackers accessed parts of its network between October 21, 2024, and January 13, 2025, and potentially exfiltrated files containing electronic protected health information. Data potentially compromised in the incident included names, addresses, social security numbers, and medical records. Conduent has taken steps to notify insurers, members, and law enforcement about the cybersecurity breach and has offered the affected individuals 12 months of complimentary credit monitoring services. The breach was significant, affecting tens of millions of individuals. In a February 2025 filing with the Wisconsin Department of Agriculture, Trade, and Consumer Protection,...

Read More
March 2026 Healthcare Data Breach Report
May11

March 2026 Healthcare Data Breach Report

In March 2026, 66 healthcare data breaches affecting 500 or more individuals were reported to the HHS’ Office for Civil Rights (OCR). More than 8.7 million individuals had their personal and protected health information exposed, stolen, or otherwise impermissibly disclosed. Under the HITECH Act of 2009, OCR is required to publish a summary of large healthcare data breaches – incidents involving the exposure, theft, or impermissible disclosure of the electronic protected health information of 500 or more individuals. OCR checks all breach reports submitted through its data breach portal, then adds the data breaches to the public-facing section of the portal. Typically, there is a delay of up to 2 weeks from the receipt of a breach report to its addition to the breach portal. During the month of March, no data breaches were added to the portal for March. March data breaches started to be added to the portal in mid-April, hence the delay in publication of this breach report. Since this breach report was first published on May 11, 2026, a further 22 data breaches were added to the...

Read More
5 HIPAA Compliance Tips for Medical Office Managers
May11

5 HIPAA Compliance Tips for Medical Office Managers

Medical office managers sit at the center of every operational workflow in a small or mid‑sized practice. They are the people who translate HIPAA’s legal requirements into the daily routines that keep patient information protected, staff aligned with the practice’s workflows, and the practice out of regulatory trouble. Unlike large health systems with compliance departments, privacy teams, and dedicated security personnel, medical practices often rely on a single individual to oversee both the structural elements of a HIPAA compliance program and the practical application of HIPAA in daily operations across reception, billing, clinical support, and administrative functions. That dual responsibility is demanding even for experienced managers, and it becomes especially challenging when policies, training, and documentation have not kept pace with the way the practice actually operates. This is why practical, operationally grounded tips matter. Office managers need guidance that helps them run a compliant practice in real time, with real staff, real patients, and real constraints....

Read More
OpenLoop Health Data Breach Affects 716,000 Individuals
May11

OpenLoop Health Data Breach Affects 716,000 Individuals

On March 24, 2026, The HIPAA Journal reported on a data breach at the telehealth platform provider Open Loop Health (see below). The data breach had been reported to regulators, but it can take weeks for the incident to be added to the HHS Office for Civil Rights breach portal and for the scale of the breach to become clear. While the data breach was reported to OCR on March 17, 2026, it has only recently been added to the breach portal. That listing shows that the protected health information of up to 716,000 individuals was compromised in the incident. March 24, 2026: Telehealth Platform Provider OpenLoop Health Discloses Data Breach A major data breach has been reported by the telehealth platform provider OpenLoop Health Inc. While the total number of affected individuals has yet to be publicly disclosed, it could well be one of the largest healthcare data breaches of the year to date. According to the breach notice provided to the California Attorney General, OpenLoop Health learned on January 7, 2026, that an unauthorized third party had gained access to some of its systems...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist