25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Over 200,000 Individuals Potentially Affected by ClearBalance Phishing Attack

San Diego, CA-based ClearBalance, a loan provider that helps patients spread the cost of their hospital bills, was the victim of a phishing attack on March 8, 2021 where employees were tricked into disclosing their login credentials. ClearBalance identified the email security breach on April 26, 2021 when the attacker attempted to make a fraudulent wire transfer. Steps were immediately taken to secure the email environment and prevent further unauthorized access, and the attempted wire transfer failed. No funds were transferred to the attacker’s account. A third-party computer forensic investigator was engaged to investigate the breach and to determine whether the attacker accessed or obtained any sensitive data. The investigator confirmed that the breach was limited to the email environment and no other systems were affected and that the unauthorized individual had been ejected from email accounts the day the breach was detected. The attacker was not able to gain access to the database that hosts the medical record systems of any healthcare providers; however, some sensitive data...

Read More
Colorado Privacy Act Passed and Signed into Law
Jul14

Colorado Privacy Act Passed and Signed into Law

The Colorado Privacy Act gives consumers in Colorado more control over how personal data is collected, used, and shared, and requires qualifying entities in Colorado to adopt data protection policies and procedures similar to those required by the EU’s General Data Protection Regulations. While HIPAA covered entities and business associates are exempted from the Act, the exemption only applies to data protected by the HIPAA Privacy Rule. Any other data collected, used, or shared by a HIPAA covered entity or business associate may be subject to the requirements of the Colorado Privacy Act. Colorado has joined California and Virginia in passing a comprehensive data privacy law to protect state residents. It has taken several amendments to get the Colorado Privacy Act over the line, but the Act was finally passed unanimously by the state Senate on June 8, 2021. On July 7, 2021, Colorado Governor Jared Polis signed the bill, which will take effect on July 1, 2023. The Colorado Privacy Act applies to all data controllers that conduct business in Colorado that control or process the...

Read More

Radiology Specialists Facing Class Action Lawsuit Over PACS Data Breach

A class action lawsuit has been filed in the New York District Court for the Southern District of New York against a radiology company and its vendor. The radiology specialists are alleged to have failed to secure their Picture Archiving Communication System (PACS), which contained the protected health information and medical images of patients. In 2019, security researchers identified vulnerabilities in the PACS used by hospitals, clinics, and radiology companies to share medical images and data. The researchers analyzed more than 2,300 medical images, which were found to contain sensitive patient data. Northeast Radiology and its vendor, Alliance HealthCare Services, were among the companies affected and were notified about the exposed data by the researchers in December 2019. Both radiology firms used medical imaging archiving software that permitted unauthorized individuals to gain access to medical images and protected health information. The researchers identified 61 million X-rays, CT scans, and MRIs that had been exposed, which included protected health information such as...

Read More

Texas Man Sentenced to 48 Months for Fraud Scheme Involving Theft of Electronic Health Records

A Texas man has been sentenced to 48 months in prison after pleading guilty to one count of conspiracy to obtain information from a protected computer. Demetrius Cervantes of McKinney, TX, was one of three defendants indicted over the theft and misuse of protected health information. Prosecutors alleged the defendants unlawfully gained access to an unnamed healthcare provider’s EHR system, stole information, then repackaged that data to create false and fraudulent physician orders, which were sold to durable medical equipment providers and contractors. The defendants are alleged to have obtained $1.4 million from the sale of the data, which they subsequently used to purchase high value items such as vehicles and jet skis. “Today’s sentence sends the message that the theft of protected health information, the fabrication of physicians’ orders, and the sale of prescriptions will not be tolerated in the Eastern District of Texas,” said Acting U.S. Attorney Nicholas J. Ganjei. “This office will continue to pursue those who place profits over patients and...

Read More

Wisconsin Dermatology Practice Reports Data Breach Affecting 2.41 Million Individuals

Manitowoc, WI-based Forefront Management, LLC and Forefront Dermatology, S.C. discovered on June 4, 2021 that unauthorized individuals had gained access to its network and potentially viewed private and confidential employee and patient information. The affected systems were immediately taken offline to prevent further unauthorized access and an investigation was launched to determine the nature and scope of the attack. On June 24, 2021, Forefront determined that certain files stored on its network had been accessed and potentially obtained which contained the personal information of a limited number of Forefront employees, including their names and Social Security numbers. The investigation revealed its network was first breached on May 28, 2021 and access remained possible until June 4, 2021. During the course of the investigation, Forefront determined the unauthorized individual also accessed files that included the personal and protected health information of a limited number of current and former Forefront patients. Patient information potentially compromised in the attack...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist