25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Illinois Accountancy Firm Sued Over 217,000-Record Data Breach
Mar18

Illinois Accountancy Firm Sued Over 217,000-Record Data Breach

Legacy Professionals, an Illinois-based certified public accountancy firm, has notified almost 217,000 individuals about an April 2024 security incident involving data theft from its systems. Suspicious activity was identified within its computer network in late April, and a forensic investigation was launched to confirm the nature and scope of the activity. The investigation confirmed that there had been unauthorized access to its network, but client systems were unaffected. The investigation uncovered no evidence of data theft. In November 2024, Legacy Professionals learned that certain files had been exfiltrated from its network by an unauthorized actor. Legacy Professionals initiated a comprehensive review of the files and engaged data review specialists to assist with the time-intensive review. That process was completed in February 2025 and confirmed that the stolen data included employee benefit plan information such as names, Social Security numbers, driver’s license/state ID numbers, medical treatment information, and health insurance information. Legacy Professionals said...

Read More
Department of Labor Announces Senior OSHA Appointments
Mar17

Department of Labor Announces Senior OSHA Appointments

The U.S. Department of Labor has announced leadership changes at the Occupational Safety and Health Administration (OSHA), including Deputy Assistant Secretary Amanda Wood Laihow serving as the new acting Assistant Secretary of Labor for Occupational Safety and Health. Douglas L. Parker previously led the agency under President Biden and President Trump’s nomination to head OSHA, the former UPS and Amazon safety executive David Keeling, is currently with the Senate HELP Committee. Shortly after Lori Chavez-DeRemer was sworn in as Labor Secretary, OSHA updated its organizational chart confirming Amanda Wood Laihow is the new Acting Assistant Secretary of Labor for Occupational Safety and Health. Since February, Wood Laihow has served as Deputy Assistant Secretary alongside Scott Ketcham. Amanda Wood Laihow is a labor lawyer who previously served as a commissioner to the Occupational Safety and Health Review Commission from 2020 to 2023. She has also served as director of labor and employment policy for the National Association of Manufacturers, deputy general counsel on the...

Read More
High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)
Mar17

High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)

Two high-severity vulnerabilities have been identified in Philips Intellispace Cardiovascular (ISCV), a popular multi-modality image and information management solution for healthcare providers. The vulnerabilities are present in ISCV version 4.1 and prior versions and ISCV version 5.1 and prior versions. The vulnerabilities are due to improper authentication and the use of weak credentials. Both vulnerabilities have been assigned a CVSS v3.1 severity score of 7.7 and a CVSS v4 severity score of 8.5. An attacker can exploit the vulnerabilities to replay the session of a logged-in user and gain access to patient records. Vulnerability CVE-2025-2230 is due to improper authentication. The Windows login flow contains a flaw where an AuthContext token can be exploited for replay attacks and authentication bypass. Vulnerability CVE-2025-2229 is due to weak credentials, where a token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations. The vulnerabilities have been resolved in previous releases of ISCV; however,...

Read More

HIPAA Compliance Plan

A HIPAA compliance plan starts life as a framework for using and disclosing Protected Health Information as required or permitted by the HIPAA Privacy Rule, and as a set of safeguards for protecting the confidentiality, integrity, and availability of electronic Protected Health Information as required by the HIPAA Security Rule. In addition to complying with the Privacy and Security Rules, a HIPAA compliance plan must also take into account the Breach Notification Rule, any applicable General Rules (Part 160), and any applicable Transaction Rules (Part 162) – notwithstanding that some elements of HIPAA compliance may have to be integrated with other federal regulations (i.e. 42 CFR Part 2) or preempted by state regulation with greater privacy protections, increased patient rights, or shorter breach notification periods. Responsibility for Creating a HIPAA Compliance Plan The administrative requirements within the HIPAA Security Rule are quite clear about who has responsibility for creating a HIPAA compliance plan. Section §164.530 of the Security Rule states “A covered entity must...

Read More
Healthcare Staff Database with 86,000 Records Exposed Online
Mar14

Healthcare Staff Database with 86,000 Records Exposed Online

A database owned by a New Jersey health technology company has been exposed online, allowing sensitive data to be freely accessed by anyone without the need for any authentication. The non-password-protected database was linked to ESHYFT, which operates in 29 U.S. states and offers a mobile app platform that connects healthcare facilities with healthcare workers such as Licensed Practical Nurses (LPNs), Registered Nurses (RNs), and Certified Nursing Assistants (CNAs). The app is available in the Apple App Store and on Google Play, with the latter showing the app has been downloaded more than 50,000 times. The app can be used by nurses to find shifts that fit their schedules and by healthcare facilities to find vetted nursing staff to fill vacancies. The exposed 108.8 GB database was found by cybersecurity researcher Jeremiah Fowler, who shared his findings with Website Planet. Fowler identified 86,341 records in the database, a sample of which included profile/facial images, monthly work schedules, professional certificates, work assignment agreements, CVs, and resumes. A single...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist