25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Recent Equipment Thefts Bring Data Encryption Issue to the Forefront

Cybersecurity is a hot topic at board meetings; the healthcare industry is under attack and cybersecurity defenses must be improved. While boards may be preoccupied with the threat from hackers – it is often perceived to be the biggest cause of HIPAA breaches – it is important not to forget about lower-tech attacks. Hackers are breaking through healthcare providers defenses to obtain PHI, but there are easier ways for thieves to obtain data: A fact that has certainly not been overlooked by the criminal fraternity. Theft of equipment containing Protected Health Information is also a major cause of HIPAA breaches, in spite of affordable technology existing to prevent data disclosure. Healthcare Providers Must Tackle Device Loss and Theft   The spate of recent thefts reported by healthcare providers and health plans shows that while cybercriminal activity is on the rise, theft of devices containing unencrypted PHI is keeping pace. The risk of HIPAA breaches from the theft and loss of equipment simply cannot be ignored. It is an ever-present threat. Current figures may suggest...

Read More
Lua Joins App Configuration for Enterprise (ACE) Program
Jun20

Lua Joins App Configuration for Enterprise (ACE) Program

The secure mobile messaging platform provider Lua has announced it has joined the App Configuration for Enterprise (ACE) program. The ACE program was recently launched to create a standard approach to configuring and securing apps in the enterprise. ACE has developed an operating framework incorporating APIs from operating system platforms such as Android and Apple iOS. By using the framework, developers can create new, secure apps with minimal effort. Lua has joined founding members Cisco, Salesforce, Workday, Box, Xamarin, and AirWatch in the program. The Lua platform has also been made available on the AirWatch Marketplace. The new ACE integration allows all organizations running the EMM solution to easily administer Lua as a managed application. “As a member of ACE we are able to offer customers mobile messaging in a secure, easy-to-manage EMM environment,” said Brian Feller, Vice President of Corporate Development at Lua. “Executives across all industries are concerned with security and amplifying their employees’ productivity. Secure mobile messaging is the cornerstone of a...

Read More

HIPAA Breach for Handbags: Manhattan DA Indicts 8 in ID Theft Ring

Yesterday, the Manhattan District Attorney’s Office issued a press release announcing the indictment of 8 individuals involved in an ID Theft Ring. A former Montefiore Medical Center employee was named as the provider of the Protected Health Information (PHI) which enabled the thieves to obtain gift cards and store cards and run up tens of thousands of dollars of debt. Monique Walker, 32, was employed as an assistant clerk at Montefiore Medical Center, and was provided with access to patient records in order to complete her work duties. However, Walker allegedly started printing off pages of HIPAA-protected patient records to sell to a third party, Fernando Salazar, 28. The records contained patient names, addresses, dates of birth, health insurance information, next of kin contacts and Social Security numbers. The information was used by thieves to forge identities to obtain goods and gift cards from high-end stores. The offenses are alleged to have taken place between 2012 and 2013. Walker was paid $3 for each printed copy of the records, and during her time at the hospital she...

Read More

Akorn Database for the Highest Bidder: Hacker Holds Pharma Data Auction

A Lake Forest, IL, pharmaceutical company has discovered its cybersecurity defenses were not as impregnable as thought. A hacker has managed to infiltrate the customer database of Akorn Inc., and has stolen over 50,000 records. Those records have been offered online to the highest bidder or will be given back to Akorn if the price is right. In spite of outward appearances, the attack does not appear to be financially motivated; instead, the hacker has claimed that the cyberattack was staged to “teach them a lesson in security.” Hacker Claims Responsibility for the Attack Earlier this week a known hacker, operating under the name “Mufasa,” made an offer via the dark web to sell the data appropriated in the Akorn cyberattack. Along with that offer was a selection of the data confirming the authenticity of the offer. The hacker is the same person who claimed responsibility for the huge iiNet ISP data breach in Australia earlier this month. The hacker is known for using SQL Injection to exploit security vulnerabilities, and according to Salted Hash, the same technique was used to gain...

Read More

L.A. Medical Center Employee Causes 4,859-Record HIPAA Breach

A 4-year HIPAA data breach has been reported by The University of California Irvine Medical Center after the healthcare provider discovered an employee had accessed nearly 5,000 patient records without authorization. Shocking Discovery Could Prove Expensive   News of the discovery of a data breach is enough to bring out a cold sweat in many a CISO; news that the breach has been allowed to persist for 4 years unchecked is certain to cause sleepless nights. The length of time a breach is allowed to persist has major implications for the cost of remediation. Credit and identity theft protection may need to be extended to two years or more and breach fines could be considerable. The Department of Health and Human Services’ Office for Civil Rights can levy a fine of up to $1.5 million per violation category discovered. That figure is then multiplied by the number of years the violation was allowed to persist. Healthcare providers can implement a number of security measures to stop employees snooping on records and stealing customer data, but the risk is impossible to eliminate. The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist