25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

$17.5 Million Settlement Resolves Infosys McCamish Systems Data Breach Lawsuit
Mar18

$17.5 Million Settlement Resolves Infosys McCamish Systems Data Breach Lawsuit

A settlement has been agreed to resolve multiple Infosys McCamish Systems class action lawsuits that were filed in response to a 2023 ransomware attack and data breach that involved unauthorized access to the personal data of more than 6 million individuals. Infosys is India’s second-largest IT services provider, and Infosys McCamish Systems is a U.S. subsidiary that provides life insurance and retirement software and services. In November 2023, Infosys McCamish Systems discovered its systems had been breached in a ransomware attack. The forensic investigation confirmed that an unauthorized cyber actor had access to its systems between October 29 and November 2, 2023, exfiltrated sensitive data, and used ransomware to encrypt files. The LockBit ransomware group claimed responsibility for the attack and demanded a ransom, payment of which was required to obtain the keys to decrypt data and prevent the stolen data from being made public. A LockBit representative claimed that Infosys McCamish offered to pay $50,000 to prevent the release of the stolen data but the lowball offer was...

Read More
New HIPAA Exemption Added to Kentucky Consumer Data Protection Act
Mar18

New HIPAA Exemption Added to Kentucky Consumer Data Protection Act

In April 2024, Kentucky joined the growing number of states that have adopted comprehensive consumer privacy and data protection laws. The Kentucky Consumer Data Protection Act was signed into law on April 4, 2024, and is due to take effect on January 1, 2026. The Kentucky Consumer Data Protection Act applies to individuals and legal entities that control or process the personal data of at least 100,000 Kentucky consumers or control or process the personal data of 25,000 Kentucky consumers and derive over 50% of gross revenue from the sale of personal data. An amendment to the law has been signed by state governor Andy Beshear that narrows the scope of the law, exempting information collected by healthcare providers covered under HIPAA that maintain protected health information in compliance with the HIPAA Rules and other related regulations. The amendment also expands the excluded information to include information collected in a limited data set, as defined in 45 C.F.R. 8 164.514(e) to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. 8...

Read More
Illinois Accountancy Firm Sued Over 217,000-Record Data Breach
Mar18

Illinois Accountancy Firm Sued Over 217,000-Record Data Breach

Legacy Professionals, an Illinois-based certified public accountancy firm, has notified almost 217,000 individuals about an April 2024 security incident involving data theft from its systems. Suspicious activity was identified within its computer network in late April, and a forensic investigation was launched to confirm the nature and scope of the activity. The investigation confirmed that there had been unauthorized access to its network, but client systems were unaffected. The investigation uncovered no evidence of data theft. In November 2024, Legacy Professionals learned that certain files had been exfiltrated from its network by an unauthorized actor. Legacy Professionals initiated a comprehensive review of the files and engaged data review specialists to assist with the time-intensive review. That process was completed in February 2025 and confirmed that the stolen data included employee benefit plan information such as names, Social Security numbers, driver’s license/state ID numbers, medical treatment information, and health insurance information. Legacy Professionals said...

Read More
Department of Labor Announces Senior OSHA Appointments
Mar17

Department of Labor Announces Senior OSHA Appointments

The U.S. Department of Labor has announced leadership changes at the Occupational Safety and Health Administration (OSHA), including Deputy Assistant Secretary Amanda Wood Laihow serving as the new acting Assistant Secretary of Labor for Occupational Safety and Health. Douglas L. Parker previously led the agency under President Biden and President Trump’s nomination to head OSHA, the former UPS and Amazon safety executive David Keeling, is currently with the Senate HELP Committee. Shortly after Lori Chavez-DeRemer was sworn in as Labor Secretary, OSHA updated its organizational chart confirming Amanda Wood Laihow is the new Acting Assistant Secretary of Labor for Occupational Safety and Health. Since February, Wood Laihow has served as Deputy Assistant Secretary alongside Scott Ketcham. Amanda Wood Laihow is a labor lawyer who previously served as a commissioner to the Occupational Safety and Health Review Commission from 2020 to 2023. She has also served as director of labor and employment policy for the National Association of Manufacturers, deputy general counsel on the...

Read More
High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)
Mar17

High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)

Two high-severity vulnerabilities have been identified in Philips Intellispace Cardiovascular (ISCV), a popular multi-modality image and information management solution for healthcare providers. The vulnerabilities are present in ISCV version 4.1 and prior versions and ISCV version 5.1 and prior versions. The vulnerabilities are due to improper authentication and the use of weak credentials. Both vulnerabilities have been assigned a CVSS v3.1 severity score of 7.7 and a CVSS v4 severity score of 8.5. An attacker can exploit the vulnerabilities to replay the session of a logged-in user and gain access to patient records. Vulnerability CVE-2025-2230 is due to improper authentication. The Windows login flow contains a flaw where an AuthContext token can be exploited for replay attacks and authentication bypass. Vulnerability CVE-2025-2229 is due to weak credentials, where a token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations. The vulnerabilities have been resolved in previous releases of ISCV; however,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist