25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Horizon Behavioral Health Falls Victim to Ransomware Attack
May06

Horizon Behavioral Health Falls Victim to Ransomware Attack

Data breaches have been announced by Horizon Behavioral Health, BayMark Health Services, Carlton County Public Health and Human Services, the City of Bristol in Tennessee, and Schewitz Psychological Services (Couples Learn). Horizon Behavioral Health Horizon Behavioral Health, a Lynchburg, VA-based provider of mental health, substance use, and intellectual disability services in Central Virginia, has fallen victim to a ransomware attack. The attack was detected on March 16, 2025, when computer systems were disrupted. Immediate action was taken to try to contain the attack and prevent further unauthorized access, and a forensic investigation was launched to determine the extent of the compromise. Horizon Behavioral Health determined that a ransomware group had access to its network between March 13, 2025, and March 16, 2025, during which time sensitive data may have been viewed or acquired by the ransomware group. The file review confirmed that the affected data included names, Social Security numbers, addresses, ZIP codes, driver’s license numbers, dates of birth,...

Read More
Federal Judge Vacates FDA’s Final Rule Reclassifying Laboratory-Developed Tests as Medical Devices
May06

Federal Judge Vacates FDA’s Final Rule Reclassifying Laboratory-Developed Tests as Medical Devices

A Federal judge recently vacated a Final Rule proposed by the U.S. Food and Drug Administration (FDA) that sought to reclassify laboratory-developed tests (LDTs) as medical devices, thus regulating the LDTs under the Federal Food, Drug, and Cosmetic Act (FDCA). The rule was first proposed by the FDA on October 3, 2024, and a final rule was added to the Federal Register on May 6, 2024. Prior to the Final Rule, the FDA exercised general enforcement discretion for LDTs, with action only taken against an LDT if it was thought to have resulted in inaccurate diagnoses. LDTs are generally not sold to other laboratories and are used internally to help provide diagnoses from samples sent to the laboratory by a healthcare provider. LDTs are subjected to robust testing to ensure they are accurate and reliable before they are used for diagnostic purposes, and laboratories were already regulated by the Centers for Medicare and Medicaid Services (CMS) under the Clinical Laboratory Improvement Amendments of 1988 (CLIA). The Final Rule reclassified LDTs as medical devices, which means that they...

Read More
Is JotForm HIPAA Compliant?
May05

Is JotForm HIPAA Compliant?

JotForm is HIPAA compliant and can be used to collect, store, and share Protected Health Information (PHI) provided businesses subscribe to a Gold or Enterprise plan and agree to the terms of JotForm’s Business Associate Agreement. Existing subscribers with a Starter, Bronze, or Silver plan must upgrade their plan to use JotForm in compliance with HIPAA. JotForm is a software solution for creating online forms that can be used in the healthcare industry to simplify the collection and documentation of PHI. Use cases include collecting PHI during the patient intake process, documenting patient consent and authorizations, soliciting patient feedback, and scheduling appointments via forms embedded into a web page or patient portal. JotForm integrates with multiple HIPAA compliant productivity and collaboration tools (i.e., OneDrive, Google Workspace, Salesforce, etc.) to streamline workflows and increase efficiency. Through these integrations, it is also possible to transmit PHI to EHRs or other systems to improve the patient experience. However, in order to use the software solution...

Read More
SonicWall SMA Vulnerabilities Actively Exploited in Attacks
May05

SonicWall SMA Vulnerabilities Actively Exploited in Attacks

Users of SonicWall Secure Mobile Access (SMA) appliances have been warned about three vulnerabilities that are potentially being targeted by threat actors in attacks. The vulnerabilities are not zero-days, having been previously disclosed and patched by SonicWall in December 2023 and April 2025. Evidence has emerged that threat actors are actively targeting the flaws to attack unpatched SMA appliances. The vulnerabilities are tracked as CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475, and all three have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability (KEV) Catalog. SonicWall issued a warning about exploitation of the CVE-2021-20035 vulnerability in mid-April, with a further announcement made about potential exploitation of the other two vulnerabilities at the end of last month. CVE-2021-20035 is a high-severity flaw from 2021 that affects SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices running versions 9.0.0.10-28sv and earlier, 10.2.0.7-34sv and earlier, and 10.2.1.0-17sv and earlier. The vulnerability is thought...

Read More
Two High-Severity Vulnerabilities Identified in MicroDicom DICOM Viewer
May05

Two High-Severity Vulnerabilities Identified in MicroDicom DICOM Viewer

Two high-severity remotely exploitable vulnerabilities have been identified in MicroDicom DICOM Viewer that can be exploited in a low-complexity attack. Successful exploitation of the vulnerabilities could result in memory corruption, code execution, and unauthorized access to patient data. MicroDicom DICOM Viewer is free-to-use software for viewing and manipulating DICOM medical images. The software can also be used to burn DICOM images onto CDs and DVDs that can be viewed without having to install the software. The out-of-bounds read and write vulnerabilities require user interaction to exploit. A user would need to be convinced to open a malicious DCM file that had been specially crafted by a threat actor, such as in a social engineering or phishing attack. The vulnerabilities were identified by security researcher Michael Heinzl, who reported them to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). At present, there are no indications that the vulnerabilities have been exploited in attacks; however, users are advised to update to the latest version of the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist