25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Artemis Healthcare Falls Victim to Ransomware Attack
Dec30

Artemis Healthcare Falls Victim to Ransomware Attack

Tennessee-based Artemis Healthcare has experienced a ransomware attack involving data theft, and email account breaches have been announced by Greater St. Louis Oral & Maxillofacial Surgery in Missouri and St. John’s Riverside Hospital in New York. Artemis Healthcare, Tennessee Artemis Healthcare in Nashville, Tennessee, has recently announced a data security incident that was identified on May 31, 2025. According to the notification sent to the Vermont Attorney General, Artemis Healthcare confirmed that it was the target of a ransomware group, which accessed its network from May 5, 2025, to May 31, 2025. The investigation confirmed on September 12, 2025, that the ransomware group accessed personally identifiable and protected health information, including names, addresses, dates of birth, Social Security numbers, and health information. The Crypto24 ransomware group took responsibility for the attack and claimed on its dark web data leak site to have exfiltrated 1 terabyte of data, including image files for millions of patients. The stolen data has been leaked, indicating the...

Read More
New HIPAA Regulations in 2026
Dec30

New HIPAA Regulations in 2026

New HIPAA regulations may be implemented in 2026, such as the proposed update to the HIPAA Privacy Rule,  a final rule for which is long overdue. An update to the HIPAA Security Rule was proposed in January 2025,  although it is unclear when or if OCR will publish a final rule. New HIPAA regulations were implemented in 2024 when a final rule was published updating the HIPAA Privacy Rule to strengthen reproductive health care privacy, and a final rule was published aligning the Part 2 regulations more closely with HIPAA, although in June 2025, the HIPAA Privacy Rule to strengthen reproductive health care privacy was vacated nationally by a Texas judge. This article explains the implemented and proposed new HIPAA regulations and can be used in conjunction with our HIPAA compliance checklist to help better understand how the HIPAA updates for 2026 may impact HIPAA compliance. Please use the form on this page to request your free copy of the checklist Summary Of Article Contents New Part 2 Rulemaking New Regulations in 2024 and 2025 Compliance Challenges Transaction Code Set Updates...

Read More
New Liberty Hospital; New York Blood Center; Memorial Blood Centers Settle Data Breach Lawsuits
Dec30

New Liberty Hospital; New York Blood Center; Memorial Blood Centers Settle Data Breach Lawsuits

New Liberty Hospital in Missouri, Memorial Blood Centers in Minnesota, and the New York Blood Center have settled class action lawsuits over cyberattacks that exposed patient data. New Liberty Hospital Corporation A $1,500,000 settlement has received preliminary approval from the court to resolve a class action lawsuit against Liberty Hospital in Missouri over a 2023 data breach involving the protected health information of 264,541 individuals. Liberty Hospital experienced a cyberattack on or around December 19, 2023. While it is unclear if data was encrypted in the attack, a ransom note was received, and the attacker claimed to have downloaded sensitive data from its network. The investigation confirmed that protected health information had been accessed and potentially obtained in the attack, including names, addresses, email addresses, telephone numbers, dates of birth, medical records, medical treatment information, diagnoses, Social Security numbers, and health insurance information. The affected individuals were notified on or around February 8, 2024. The first class action...

Read More
80 Hospitals May Have Been Affected by the Oracle Health Data Breach
Dec30

80 Hospitals May Have Been Affected by the Oracle Health Data Breach

The number of individuals affected by the hacking incident at Oracle Health has yet to be confirmed; however, the data breach is known to have affected up to 80 hospitals. Oracle Health has been notifying the affected healthcare provider clients, some of whom have only recently learned that they have been affected. Lake Regional Health System in Missouri, OSF Saint Clare Medical Center in Illinois, Aultman Health System in Ohio, and NKC Health in North Kansas City have all recently confirmed that they were affected by the hacking incident and had patient data stolen. Each of those healthcare providers has started issuing notifications to the affected patients and has offered complimentary credit monitoring services. The data compromised in the hacking incident varies from provider to provider and generally includes information typically stored in medical records, such as names, dates of birth, Social Security numbers, medical record numbers, diagnoses, medications, test results, and medical images. While data was compromised in the incident, there have been no known instances of...

Read More
Murfreesboro Medical Clinic Settles Lawsuit Over 559K-record Data Breach
Dec29

Murfreesboro Medical Clinic Settles Lawsuit Over 559K-record Data Breach

Murfreesboro Medical Clinic & SurgiCenter in Tennessee has agreed to settle class action litigation over a major data breach in April 2023 that involved unauthorized access to the protected health information of 559,000 patients. Murfreesboro Medical Clinic determined that “a well-known cyber extortion operation” gained access to its network on or around April 22, 2023, and exfiltrated patient and employee data. Data compromised in the incident included names, dates of birth, home addresses, phone numbers, copies of driver’s licenses, full or partial social security numbers, dependent information, dates of service, medical and diagnostic information related to those dates of service, test results, procedure notes, prescription information, medical record numbers, and insurance and enrolment information. The affected individuals were notified about the attack in May 2023. The BianLian ransomware group claimed responsibility for the attack. Six class action lawsuits were filed in response to the data breach, which were consolidated on September 7, 2023, into a single action...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist