25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Arietis Health Settles MOVEit Data Breach Lawsuit for $2.8 Million
Feb26

Arietis Health Settles MOVEit Data Breach Lawsuit for $2.8 Million

A $2.8 million settlement has been agreed to resolve a class action lawsuit against Arietis Health over a 2023 hacking incident that involved the protected health information of 1,975,066 individuals. Arietis Health, a provider of billing services to NorthStar Anesthesia, was one of more than 2,300 organizations to be affected by the mass exploitation of zero day vulnerability in Progress Software’s MOVEit Transfer solution in late May 2023. Arietis Health used the file transfer solution to transfer large files containing patient information. The Clop threat group exploited the vulnerability, gained access to the Arietis Health MOVEit environment between May 28 and May 31, 2024, and copied data from that environment. The Arietis Health data breach involved patient data from at least 54 healthcare organizations linked to NorthStar Anesthesia, with the compromised data including patient names, dates of birth, driver’s license or other state identification card numbers, addresses, Social Security numbers, medical record numbers, patient account numbers, health insurance information,...

Read More
Cyberattack on Arizona Business Associates Affects 78,000 Individuals
Feb26

Cyberattack on Arizona Business Associates Affects 78,000 Individuals

Data breaches have been announced by Ottawa Family Physicians in Kansas, CPS Solutions in Ohio, Turning Point of Central California, The Phoenix Rehabilitation and Nursing Center in New York, and Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP in Arizona. Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP A data breach has recently been reported that has affected the HIPAA business associates Primary Health-SMMPP and U.S. HEALTHWORKS-SMMPP. Both business associates are based in Arizona and provide healthcare-related services, including the distribution of rapid COVID test kits to schools and organizations in Arizona and other states. On or around December 13, 2024, unusual activity was identified in a server operated by Primary Health-SMMPP. A third-party digital forensics company was engaged to investigate the unauthorized activity and confirmed that an unauthorized third party had breached its defenses and may have viewed or copied data stored on the server. The server was reviewed to identify the individuals affected and the types of data involved, and that process was...

Read More
China-Based Threat Group Targets Healthcare with Malicious DICOM Installers
Feb26

China-Based Threat Group Targets Healthcare with Malicious DICOM Installers

Ransomware groups are targeting healthcare organizations for financial gain, infiltrating networks, stealing data, then using ransomware to encrypt files. Cyber threat actors are also infiltrating healthcare networks and stealing data in much quieter attacks, where compromised healthcare organizations are not extorted and hackers remain in their networks indefinitely. Researchers at the cybersecurity firm Forescout have identified a new China-based threat group that is engaged in these quiet attacks, with one campaign involving weaponized installers for DICOM viewers. The installers are used to deliver a remote access trojan to create a backdoor and gain control of victims’ computers. Silver Fox (aka Void Arachne, The Great Thief of the Valley) is a relatively new threat group first identified in June 2024. Initially, the group was focused on Chinese victims, deploying ValleyRAT malware via SEO poisoning, social media, and text message-based attacks, often under the guise of VPN software and AI applications. The group has been highly active since it emerged and its tactics have...

Read More
Study Explores the Effectiveness of Insider Risk Management Programs
Feb26

Study Explores the Effectiveness of Insider Risk Management Programs

In 2024, the healthcare industry was rocked by a ransomware attack on Change Healthcare that caused massive disruption to healthcare operations across the country and resulted in the theft of the protected health information of more than 190 million individuals. According to Kroll, healthcare was the most attacked industry, overtaking finance, accounting for 23% of all data breaches last year. While hacking was the most common breach cause in 2024, many cybersecurity incidents were due to malicious and negligent insiders, and these incidents can be costly to resolve. A recent study by the Ponemon Institute on behalf of DTEX Systems sought to identify how prevalent insider breaches are, the financial impact of these incidents, and how organizations are addressing insider risk. The survey revealed that organizations are increasingly adopting insider risk management programs, with the percentage of companies that have an insider risk management program increasing from 77% in 2023 to 81% in 2024. The amount of the IT security budget devoted to insider risk management is also...

Read More
Healthcare Was the Most Breached Industry in 2024
Feb25

Healthcare Was the Most Breached Industry in 2024

A recent report from the financial and risk advisory firm Kroll has confirmed that healthcare is now the primary target for cybercriminals, having overtaken finance for data breaches in 2024. In 2024, healthcare accounted for almost one-quarter (23%) of all data breaches, overtaking finance (22%), albeit by the smallest of margins. In 2023, finance topped the list with 26% of data breaches with healthcare in second place with 18% of data breaches. Over the past few years, finance and healthcare have been vying for the top spot for data breaches, and there is no reason to suggest any change in 2025; however, the Kroll Data Breach Outlook 2025 report provides interesting insights into attacks on other sectors. Cyber actors are conducting fewer attacks on other often targeted sectors such as professional services, retail, technology, and education, with attacks on the technology sector falling by 46%, attacks on education falling by 38%, and retail attacks falling by 33%. Last year saw an increase in attacks on the industrial services, manufacturing, government, and insurance sectors,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist