25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Hacker Facing Extradition to US and Up to 50 Years in Jail
Jun30

Healthcare Hacker Facing Extradition to US and Up to 50 Years in Jail

A notorious and prolific hacker alleged to have conducted cyberattacks on more than 40 victims in the United States has been charged in a four-count indictment and is facing extradition to face the charges. Kai West, 25, a British national, is alleged to have operated under the online monikers of IntelBroker and Kyle Northern, and under the name IntelBroker, is alleged to have hacked the networks of a telecommunications company, municipal healthcare provider, an Internet service provider, and more than 40 other U.S. victims. Victims included HPE, Cisco, Nokia, Ford, AMD, Zscaler, and Europol. According to the indictment, recently unsealed by United States Attorney for the Southern District of New York, Jay Clayton, and the Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (FBI), Christopher G. Raia, West’s attacks caused more than $25 million in damages to victims. Over several years, West conducted a hacking campaign for financial gain, mostly attacking companies, stealing their data, and selling the stolen data for profit. According...

Read More
FBI; CMS Issue Warning About Fraud and Phishing Attempts on Healthcare Orgs
Jun30

FBI; CMS Issue Warning About Fraud and Phishing Attempts on Healthcare Orgs

The Federal Bureau of Investigation (FBI), its Internet Crime Complaint Center (IC3), and the HHS Centers for Medicare & Medicaid Services (CMS) have issued warnings to the healthcare and public health (HPH) sector about ongoing fraud schemes. On Thursday last week, the CMS warned Medicare providers and their suppliers that scammers are impersonating the CMS in phishing requests by fax, requesting copies of medical records and documentation. The phishing attempts claim that medical records and documentation must be provided for a Medicare audit. In the fraud alert, the CMS reminded Medicare providers and their suppliers that the CMS never initiates audits with a request for medical records via fax. If in any doubt about the authenticity of any request claiming to be from the CMS, providers should contact their Medicare Review Coordinator for confirmation that the request is genuine. Any Medicare provider that outsources medical record requests to a third-party vendor should warn their vendor about the fraud scheme. On Friday last week, the FBI and IC3 issued a warning to the...

Read More
FDA Urges Medical Device Manufacturers to Improve OT Security
Jun27

FDA Urges Medical Device Manufacturers to Improve OT Security

The U.S. Food and Drug Administration (FDA) is urging medical device manufacturers to ensure the security of connected operational technologies due to the increasing threat to manufacturing supply chains. Financially motivated threat actors and nation-state hacking groups are targeting supply chains, and ransomware attacks on hospitals, medical clinics, and critical infrastructure have become more pervasive in recent years. Attacks on manufacturers and supply chains pose a significant threat and could result in harm to patients, medical advancement, and public health security. The FDA has previously focused on the cybersecurity of medical devices and now considers cybersecurity in premarket submissions for medical devices to ensure the devices can be secured for the entire product lifecycle. Now the FDA is warning medical device manufacturers that their manufacturing infrastructure can be particularly vulnerable to cyberattacks, especially due to the proliferation of connected devices, Industrial Internet of Things (IIoT) and smart technologies. Operational technologies have...

Read More
Patient Death Linked to Ransomware Attack on Pathology Services Provider
Jun27

Patient Death Linked to Ransomware Attack on Pathology Services Provider

An investigation of the unexpected death of a patient during the ransomware attack on Synnovis, a provider of pathology services to the National Health Service (NHS) in the United Kingdom, has confirmed that the attack contributed to the patient’s death. This is one of the first times that a patient’s death has been directly linked to a cyberattack. Synnovis provides diagnostics, testing, and digital pathology services to hospitals, doctors, and other NHS healthcare providers across southeast London. On June 3, 2024, Synnovis fell victim to a ransomware attack. The attack was conducted by the Qilin ransomware group and caused major disruption to healthcare services at a large number of hospitals and healthcare providers across southeast London. More than 10,000 appointments were cancelled due to the attack, and the disruption has continued for months. The attack led to a blood shortage locally and reduced blood stocks across the country as healthcare providers were forced to use O-negative blood due to limitations placed on blood matching due to the attack. A year on...

Read More
Mainline Health Systems Reports 101,000-Record Data Breach
Jun27

Mainline Health Systems Reports 101,000-Record Data Breach

Data breaches have been confirmed by Mainline Health Systems, Tallahassee Memorial Healthcare, Rural Health Services, Marquette County Medical Care Facility, Cardiology Associates of Fredericksburg, and AltaMed Health Services Corporation. Mainline Health Systems, Arkansas Mainline Health Systems, a Monticello-based medical and dental care provider serving communities in Southeast Arkansas, has recently notified the Maine Attorney General about an April 2024 security incident that involved unauthorized access to systems containing the personal and protected health information of 101,104 individuals. The network intrusion was detected on April 10, 2024; however, it has taken 14 months for individual notification letters to be sent to the affected individuals. Mainline Health Systems started sending consumer notifications on June 20, 2025. According to the notification letters, law enforcement was notified about the intrusion soon after it was discovered, and third-party cybersecurity experts were engaged to investigate the incident and determine the extent of the compromise. A file...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist