25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

How Often Should Healthcare Employees Receive Security Awareness Training?
Aug01

How Often Should Healthcare Employees Receive Security Awareness Training?

Security awareness training is a requirement of HIPAA, but how often should healthcare employees receive security awareness training? Recent Phishing and Ransomware Attacks Highlight Need for Better Security Awareness Training Phishing is one of the biggest security threats for healthcare organizations. Cybercriminals are sending phishing emails in the millions in an attempt to get end users to reveal sensitive information such as login credentials or to install malware and ransomware. While attacks are often ransom, healthcare employees are also being targeted with spear phishing emails. In December last year, anti-phishing solution provider PhishMe released the results of a study showing 91% of cyberattacks start with a phishing email. Spear phishing campaigns rose 55% last year, ransomware attacks increased by 400% and business email compromise (BEC) losses were up by 1,300%. In recent weeks, there have been several phishing attacks reported to the Department of Health and Human Services’ Office for Civil Rights. Those attacks have resulted in email accounts being compromised....

Read More
Forcepoint Adds New Capabilities to CASB, Web, and Email Security Solutions
Aug01

Forcepoint Adds New Capabilities to CASB, Web, and Email Security Solutions

Forcepoint has announced its security solutions now incorporate new behavior-driven controls to help protect critical business data, intellectual property, and employee devices. Forcepoint CASB, Web Security and Email Security have all been updated and now have new capabilities. New CASB analytics have been incorporated to help organizations reduce the time it takes to identify data breaches. Forcepoint cites Gartner data, which shows the dwell time between an attack and discovery is an average of 99 days. The longer a breach continues before it is discovered and mitigated the higher the cost to the organization. By using data and analytics it is possible to greatly reduce the time between an attack and detection, and thus reduce the cost and damage caused. Forcepoint CASB helps organizations study the actions of users to identify risky behavior and vulnerabilities, allowing IT teams to take action to be taken before a breach occurs. The solution also helps IT teams identify anomalies which are indicative of a data breach and take rapid action to mitigate attacks. The new...

Read More
96% of SMBs Susceptible to External Cybersecurity Threats
Aug01

96% of SMBs Susceptible to External Cybersecurity Threats

Webroot has published the results of a new study that examined how well small to medium sized businesses are prepared to deal with cyber threats. The study revealed the majority of SMBs are not currently equipped to deal with external cybersecurity risks and believe they are susceptible to external cybersecurity threats. 600 IT decision makers in the UK, USA, and Australia were surveyed by Wakefield Research on behalf of Webroot. All respondents were employed by small to medium sized businesses with between 100 and 499 employees. 96% of respondents said they believe their organization will be susceptible to cyber threats this year and while their organization is aware of the current threat landscape and the growing number of threats, 71% of respondents said they are not well prepared to address them. The main concerns are malware infections, mobile attacks, and phishing incidents. 56% of respondents were most concerned about malware, 48% most concerned about threats to company-owned or BYOD mobile devices, and 47% were particularly concerned about phishing. The fallout from a...

Read More

47% of Healthcare Organizations Have Experienced A HIPAA Data Breach in the Past 2 Years

The KPMG 2017 Cyber Healthcare & Life Sciences Survey shows there has been a 10 percentage point increase in reported HIPAA data breaches in the past two years. The survey was conducted on 100 C-suite information security executives including CIOs, CSOs, CISOs and CTOs from healthcare providers and health plans generating more than $500 million in annual revenue. 47% of healthcare organizations have reported a HIPAA data breach in the past two years, whereas in 2015, when the survey was last conducted, 37% of healthcare organizations said they had experienced a security-related HIPAA breach in the past two years. Preparedness for data breaches has improved over the past two years. When asked whether they were ready to deal with a HIPAA data breach, only 16% of organizations said they were completely ready in 2015. This year, 35% of healthcare providers and health plans said they were completely ready to deal with a breach if one occurred. Ransomware has become a major threat since the survey was last conducted. 32% of all respondents said they had experienced a security breach...

Read More

10,000 Plastic Surgery Patients Informed of Ransomware-Related PHI Breach

10,200 patients of Plastic Surgery Associates of South Dakota are being notified that some of their protected health information was potentially compromised as a result of a ransomware attack in February this year. Plastic Surgery Associates of South Dakota discovered ransomware had been installed on some of its systems on February 12, 2017. Rapid action was taken to remove the ransomware and third-party forensics experts were brought in to investigate and determine the extent of the breach and which, if any, patients had been impacted. Fortunately, while data were encrypted, the majority of its patients were not impacted by the incident and did not have any of their data accessed or encrypted. However, the process of restoring data resulted in critical files being lost. Those files contained evidence that could have been used to confirm that some patients had not been impacted by the incident. On April 24, Plastic Surgery Associates of South Dakota decided that without access to that evidence it was not possible to rule out PHI access for 10,200 of its patients with a high degree...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist