25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cybersecurity Firms Report Record-Breaking Quarter for Ransomware Attacks
Apr10

Cybersecurity Firms Report Record-Breaking Quarter for Ransomware Attacks

Several cybersecurity companies have released Q1, 2025 reports on the current state of ransomware, and while the figures vary across the different reports due to different methodologies for tracking ransomware activity, there is consensus that the year so far has been a record-breaker with a historic high in terms of new victims. There has also been a significant increase in active ransomware groups due to the fragmentation of the ransomware landscape, with many more smaller groups emerging as seasoned affiliates of previously dominant ransomware-as-a-service (RaaS) choose their own paths. The BlackFog State of Ransomware 2025 report shows a record-breaking number of ransomware attacks disclosed by victims in Q1, 2025. BlackFog tracked 278 disclosed incidents in Q1, 2025, up 45% from Q1, 2024. BlackFog said March set a new record with 107 disclosed attacks, following on from new records set in January and February, which were up 22% and 36% respectively from Q1, 2024. Healthcare Continues to be Top Target for Ransomware Groups As has been the case in previous quarters, healthcare...

Read More
Free HIPAA Training
Apr10

Free HIPAA Training

Free HIPAA training can be a steppingstone to a better understanding of HIPAA, an enhanced level of compliance with workplace policies and procedures, and improved patient outcomes in healthcare environments. For these reasons, free HIPAA training can be beneficial to both healthcare organizations and workforce members. Table of Contents Why Sufficient Understanding of HIPAA is Important How Best to Support HIPAA Compliance Training HIPAA Overview HIPAA Definitions The HITECH Act The Main HIPAA Regulatory Rules HIPAA Omnibus Final Rule HIPAA Privacy Rule Basics HIPAA Security Rule Basics HIPAA Patient Rights HIPAA Disclosure Rules HIPAA Violation Consequences Preventing HIPAA Violations Being a HIPAA Compliant Employee Voluntary Foundation Courses for Individuals What is Free HIPAA Training? What is Free HIPAA Certification? Free HIPAA Training FAQs   HIPAA Training for Individuals Our HIPAA Certification training gives learners clear, practical guidance on what to do and why in real-world HIPAA scenarios. View Training The Gold Standard in HIPAA Training by The HIPAA Journal...

Read More
Windows CLFS Flaw Being Actively Exploited by Ransomware Group
Apr10

Windows CLFS Flaw Being Actively Exploited by Ransomware Group

Microsoft has patched a vulnerability in the Windows Common Log File System (CLFS) that is being actively exploited by a threat actor tracked as Storm-2460 after first deploying PipeMagic malware. The malware is used to exploit the flaw to elevate privileges to facilitate the widespread deployment of ransomware on victims’ systems. Windows CLFS is a logging system used for managing transactional records.  The vulnerability is tracked as CVE-2025-29824 and is a use-after-free vulnerability affecting the CLFS kernel driver. The vulnerability has been assigned a CVSS base score of 7.8 (high severity), as it cannot be remotely exploited without first compromising a vulnerable system. PipeMagic malware was first identified in 2022 and provides a backdoor into compromised systems and serves as a gateway. The malware has previously been used to facilitate the exploitation of other vulnerabilities and has been observed being delivered via a fake ChatGPT application, although the initial access vector used in the latest attacks has yet to be determined.  Microsoft has observed the...

Read More
Lawsuit Filed Against Teaching Hospital Over Pharmacist’s Decade-long Cyber-Spying Campaign
Apr09

Lawsuit Filed Against Teaching Hospital Over Pharmacist’s Decade-long Cyber-Spying Campaign

A class action lawsuit has been filed against University of Maryland Medical System Corporation and University of Maryland Medical Center (UMMC) by six current and former employees who claim they were victims of cyber-voyeurism and cyber stalking by a former UMMC pharmacist. The lawsuit names six Jane Doe plaintiffs, and was filed individually and on behalf of similarly situated individuals. According to the lawsuit, the former UMMC pharmacist Matthew Bathula installed keylogging software on approximately 400 laptops and workstations in clinics, treatment rooms, laboratories, and other locations at UMMC over the course of a decade. The spyware granted him access to the devices without requiring his credentials and allowed him to obtain the credentials of at least 80 staff members. The keylogger recorded keystrokes on devices as they were entered and allowed him to obtain credentials for personal accounts, including email accounts, financial accounts, dating apps, home surveillance systems, and more. The lawsuit claims he learned username and password patterns from the spyware,...

Read More
Fortinet Advises Immediate Upgrade to Fix Critical FortiSwitch Vulnerability
Apr09

Fortinet Advises Immediate Upgrade to Fix Critical FortiSwitch Vulnerability

Fortinet is advising FortiSwitch users to urgently update their firmware to fix a critical vulnerability that could be exploited by a remote attacker to modify administrative passwords. The vulnerability is tracked as CVE-2024-4887, has a CVSS base score of 9.3, and was discovered internally by Daniel Rozeboom of the FortiSwitch web UI development team. The vulnerability is present in FortiSwitch GUI and can be exploited remotely by sending a specially crafted request. Users have been advised to upgrade to a patched version as soon as possible to prevent exploitation. Vulnerabilities in Fortinet products are regularly targeted by threat actors, although at the time of issuing the security alert, Fortinet was unaware of any instances of attempted exploitation in the wild. If immediate patching is not possible, Fortinet recommends disabling HTTP/HTTPS Access from administrative interfaces and configuring trusted hosts to limit the hosts that can connect to the system. Affected Versions Fixed versions FortiSwitch 7.6.0 FortiSwitch 7.6.1 and above FortiSwitch 7.4.0 to 7.4.4 FortiSwitch...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist