NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam
Aug26

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails purporting to be legitimate communications sent via their MyChart patient portal. Many of the emails claim that the recipient is a winner of a MyChart Medicare Kit, although other healthcare benefits, Medicare packages, free gifts, or rewards may be offered. Texas Health Resources has warned patients that some email communications offered a “Senior Health Package.” Healthcare providers that use Epic Systems’ electronic health records and MyChart portals, including Methodist Health System, Premier Health, Sentara Health, Metro Health, and Texas Health Resources, have added scam warnings to their websites about the campaign. The scammer most likely seeks MyChart credentials, Medicare information, financial account information, or other sensitive data. The emails are not sent from legitimate healthcare provider email addresses or domains, and while they include a MyChart logo, they have not been sent by Epic Systems. The logo is used to make the messages...

Read More
Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit
Aug25

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2 million to settle a class action lawsuit stemming from a 2022 cyberattack that exposed patient data. Tift Regional Health, which operates as Southwell, Inc., which is also a defendant, identified suspicious activity within its computer network on or around August 16, 2022. The forensic investigation confirmed that its network was accessed by an unauthorized third party between August 11, 2022, and August 17, 2022. The compromised parts of the network contained documents that included patient names, birth dates, Social Security numbers, and a range of sensitive medical information. Tift Regional Health said those documents may have been accessed or copied in the attack. A ransomware group  – Hive – claimed responsibility for the attack. Hive claimed to have stolen 1 terabyte of data and proceeded to leak some of that data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health...

Read More
DAP Health Settles Data Breach Lawsuit for $1,300,000
Aug21

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health, a nonprofit community healthcare network based in Southern California, has agreed to settle a class action lawsuit that was filed in response to a cyberattack on its computer systems that exposed sensitive patient data. Suspicious activity was identified within certain computer systems on or around July 22, 2024. An investigation was launched, which confirmed that an unauthorized third party gained access to an email server and exfiltrated emails and files containing personally identifiable information and protected health information. Data stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, birth certificate numbers, vehicle license plate and VIN numbers, financial account numbers, Medicare/Medicaid numbers, health insurance information, and a range of medical information. Notification letters started to be sent to the affected individuals in December 2024, and the breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 129,048...

Read More
What is Information Blocking in Healthcare?
Aug20

What is Information Blocking in Healthcare?

Information blocking in healthcare is any practice by a healthcare provider, certified health IT developer, or Health Information Network (collectively “actors” ) that prevents or materially discourages access to, exchange of, or use of Electronic Health Information (EHI). Actors responsible for information blocking can face significant sanctions. In 2016, §4004 of the 21st Century Cures Act added a new section to the Public Health Service Act to prohibit the practice of information blocking in healthcare. The new section describes some of the most common information blocking practices, and instructs the Secretary of Health and Human Services (HHS) to identify exceptions when information blocking in healthcare is permissible. HHS did so through the 2020 Cures Act Final Rule, which codified the information blocking provisions — including the permitted exceptions — at 45 CFR Part 171. The new section also authorizes HHS’ Office of Inspector General (HHS OIG) and the Office of the National Coordinator for Health Information Technology (ONC) to sanction “actors” found responsible for...

Read More
Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs
Aug20

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims. When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Medusa had conducted more than 300 attacks on critical infrastructure entities between 2021 and February 2025. The Medusa ransomware operation emerged in June 2021 and initially operated as a closed ransomware group, with the developers conducting all aspects of the operation, including development, ransomware campaigns, and ransom negotiations. In early 2023, Medusa morphed into a RaaS operation, using affiliates to conduct attacks for a percentage of the ransom payments. The group also launched a data leak site in 2023 and adopted double extortion tactics, issuing threats to publish stolen data to pressure victims into paying to prevent data leaks as well as to obtain the keys to decrypt data. Since the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist