NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Six New Healthcare Data Breaches Announced
Mar27

Six New Healthcare Data Breaches Announced

Data breaches have been announced by Coastal Carolina Health Care in North Carolina, New Horizons Behavioral Health in Georgia, CWA Local 1180 in New York, West Texas Health, and Nephrology Associates Medical Group and Stockton Cardiology Medical Group in California. Coastal Carolina Health Care, North Carolina Coastal Carolina Health Care (CCHC), a provider of primary and specialty care services in Craven, Pamlico, and Carteret Counties in North Carolina, has recently notified the New Hampshire Attorney General about a data breach. Unauthorized network activity was first identified on March 25, 2025, and after securing its network and investigating the incident, the healthcare provider determined that there had been unauthorized network access between March 21, 2025, and March 27, 2025. A third-party vendor was engaged to review the affected data, and almost a year later, the types of data involved have been confirmed. Coastal Carolina Health Care said it was determined on February 26, 2026, that names and Social Security numbers were compromised in the incident, and sufficient...

Read More
Data Breaches Reported by New York & Texas Plastic Surgery Practices
Mar27

Data Breaches Reported by New York & Texas Plastic Surgery Practices

Data breaches have recently been reported by Vantage Plastic Surgery in New York City and Austin Plastic and Reconstructive Surgery in Texas. Vantage Plastic Surgery, New York Vantage Plastic Surgery, a plastic surgery practice in New York City, has recently disclosed a security incident involving unauthorized access to the protected health information of 4,600 current and former patients. The plastic surgery practice said it first learned about the cyberattack on January 15, 2026, and immediate action was taken to secure its computer environment. Third-party cybersecurity specialists were engaged to assist with the investigation, and on January 22, 2026, the practice confirmed that patient data had been exposed and may have been obtained by an unauthorized third party. The file review determined that names, addresses, phone numbers, email addresses, dates of birth, and medical record information had been exposed in the incident. The practice announced the data breach on February 14, 2026, and is now notifying the affected patients. Complimentary credit monitoring and identity...

Read More
Excelsior Orthopaedics; Buffalo Surgery Center Pay $2.4 Million to Settle Data Breach Lawsuit
Mar27

Excelsior Orthopaedics; Buffalo Surgery Center Pay $2.4 Million to Settle Data Breach Lawsuit

A settlement has been reached to resolve class action data breach litigation against Excelsior Orthopaedics and Buffalo Surgery Center. The lawsuit was filed in response to a 2024 data breach that affected hundreds of thousands of patients. On or around June 23, 2024, Amherst, New York-based Excelsior Orthopaedics identified suspicious network activity, and its forensic investigation confirmed that an unauthorized third party accessed and copied data from its network. The data breach also affected Northtowns Orthopaedics in Buffalo and Buffalo Surgery Center. Excelsior Orthopaedics reported the data breach to the HHS’ Office for Civil Rights as affecting 394,752 individuals, and Buffalo Surgery Center reported the breach as affecting 64,000 of its patients. The hackers obtained names, demographic information, driver’s license numbers, Social Security numbers, medical information, health insurance information, and financial information. The affected individuals were notified on December 31, 2024. Multiple class action lawsuits were filed against Excelsior Orthopaedics and Buffalo...

Read More
Take the Guesswork out of Small Practice HIPAA Compliance
Mar27

Take the Guesswork out of Small Practice HIPAA Compliance

Small practices reduce HIPAA risk by replacing assumption-based compliance with a documented, current program that can be produced on demand. Many practices believe they are compliant because staff completed a training session or a policy binder sits on a shelf. That belief is often wrong, and the gap between what a practice has done and what HIPAA requires typically surfaces during an OCR investigation, a breach, or a patient complaint, not before. Why Guesswork Persists in Small Practices Independent practices rarely have a dedicated compliance department. An office manager or physician is usually responsible for HIPAA alongside patient care, billing, and staffing. Without a structured process, compliance tasks get handled inconsistently: a HIPAA Security Risk Analysis is run once and never repeated, training dates vary by employee, and policies are copied from a generic template without being matched to the practice’s own systems and workflows. The result is a program built on assumption rather than evidence. Guesswork also comes from outdated beliefs about enforcement....

Read More
BakerHostetler: Healthcare Remains Most Targeted Sector with Extortion-Only Attacks on the Rise
Mar26

BakerHostetler: Healthcare Remains Most Targeted Sector with Extortion-Only Attacks on the Rise

Healthcare has retained its position as the industry most targeted by cyber actors, an unwanted accolade that the sector has held for more than a decade, and in 2025, healthcare had the highest average ransom payments, averaging $1,154,245, according to the recently published BakerHostetler 2026 Data Security Incident Response Report. The report is based on more than 1,250 data security incidents that the law firm was engaged in last year. BakerHostetler has been publishing annual breach reports for 12 years, and in each of those years, healthcare accounted for more cyber incidents than any other industry. In 2025, healthcare – which includes biotech and pharma – accounted for 27%, with finance/insurance in second spot, accounting for 18% of incidents. While healthcare data breaches remain high – more than 700 last year – 2025 was the second consecutive year where breaches impacting 500 or more individuals declined, albeit only slightly. Last year saw some threat actors issue astronomical ransom demands, the highest of which was $98 million, more than double the highest...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist