NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Proliance Surgeons Settles Data Breach Litigation for $4,450,000
Mar12

Proliance Surgeons Settles Data Breach Litigation for $4,450,000

The Seattle, Washington-based surgical group, Proliance Surgeons, has agreed to a settlement to resolve class action litigation over a February 2023 cyberattack and data breach. Hackers gained access to the surgical group’s network on February 11, 2023, and exfiltrated files containing patient information. Notification letters were mailed to the 437,392 affected individuals in November 2023. Shortly thereafter, class action lawsuits started to be filed. The HIPAA Journal reported on one of those lawsuits in December 2023 (see below). That lawsuit was one of eleven class action complaints filed by victims of the data breach. Due to overlapping claims, and to conserve resources, the lawsuits were consolidated into a single complaint – In re: Proliance Surgeons Data Breach Litigation – in the Superior Court of the State of Washington in and for King County. The consolidated lawsuit alleged that Proliance Surgeons failed to implement the necessary safeguards to protect private personal and protected health information on its network and as a direct consequence of that failure,...

Read More
Paubox Research on Email Security Identifies Top Security Risks in 2026
Mar12

Paubox Research on Email Security Identifies Top Security Risks in 2026

New research from Paubox has highlighted the top email security risks for healthcare organizations in 2026. The greatest risk lies not with novel and increasingly sophisticated threats, but the foundational weaknesses in email security that have existed and been exploited by threat actors for years. The latest data show that cyber threat actors are relying less on vulnerabilities and are focused on compromised credentials for initial access to networks. Email is the leading entry point for cybercriminals and the root cause of many data breaches, especially in healthcare. Cybercriminals are using email to obtain credentials that provide them with the foothold they need for an extensive compromise, including data theft, extortion, and file encryption with ransomware. The extent to which email is used, and the weaknesses in email security that facilitate attacks, have been explored by the leading HIPAA-compliance email firm Paubox in its 2026 Healthcare Email Security Report. Based on data reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), at...

Read More
HIPAA Privacy Officer’s Guide for Small Medical Practices
Mar12

HIPAA Privacy Officer’s Guide for Small Medical Practices

Article Contents Privacy Officers require a documented designation. The Notice of Privacy Practices should reflect current operations. Patient rights requests include access, amendments, and restrictions. Privacy Officers manage key patient rights. The minimum necessary standard limits access and disclosures. Authorization management includes breach assessments and vendor oversight. Privacy Rule training covers staff privacy responsibilities. Privacy complaints require documented investigation and follow-up. A HIPAA Privacy Officer in a small medical practice manages the Notice of Privacy Practices, responds to patient requests to access, amend, or restrict their protected health information, applies the minimum necessary standard to daily disclosure decisions, oversees authorization requirements for uses outside routine treatment and payment purposes, and trains staff on Privacy Rule obligations specific to their roles. The HIPAA Privacy Rule requires every covered entity to designate a Privacy Officer, and in a small practice this individual typically manages these duties...

Read More
ID Care & CommuniCare Announce Data Breaches
Mar12

ID Care & CommuniCare Announce Data Breaches

ID Care in New Jersey and Barrio Comprehensive Family Health Care Center (CommuniCare) in Texas have confirmed that patients’ personal and protected health information have been compromised in recent data security incidents. ID Care ID Care, a New Jersey-based network of board-certified infectious disease specialists, has recently disclosed a data security incident that involved unauthorized access to the personal and protected health information of current and former patients. Suspicious activity was identified within certain systems on November 5, 2025. Industry-leading cybersecurity specialists were engaged to investigate the activity and confirmed that an unknown actor gained access to its network and accessed or downloaded files without authorization. ID Care is currently reviewing the affected files, and while that process has not yet been completed, ID Care has confirmed that the affected files contained full names, dates of birth, Social Security numbers, health insurance information, and medical information, including diagnoses, treatment information, and prescription...

Read More
Data Breaches Reported by Centerwell & Lakeside Pediatrics & Adolescent Medicine
Mar11

Data Breaches Reported by Centerwell & Lakeside Pediatrics & Adolescent Medicine

Centerwell, a provider of senior healthcare services in 30 U.S. states, has experienced a cyberattack and data breach. Lakeside Pediatric & Adolescent Medicine has recently notified individuals affected by an October 2024 data breach. Centerwell Centerwell, a Louisville, Kentucky-based provider of healthcare services to seniors, has recently reported a data breach to the Texas Attorney General that involved unauthorized access to patient information. The scale of the breach is currently unclear, other than the personal and protected health information of 4,618 Texas residents was compromised in the incident. The breach could be substantially larger, as Centerwell provides senior healthcare services in 30 U.S. states. The Texas Attorney General was informed on March 6, 2026, that data compromised in the incident includes names, addresses, dates of birth, and medical information. At the time of writing, the affected individuals have not been informed by mail, and no known threat group has publicly claimed responsibility for the incident. While there is currently no substitute...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist