25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Study Explores the Effectiveness of Insider Risk Management Programs
Feb26

Study Explores the Effectiveness of Insider Risk Management Programs

In 2024, the healthcare industry was rocked by a ransomware attack on Change Healthcare that caused massive disruption to healthcare operations across the country and resulted in the theft of the protected health information of more than 190 million individuals. According to Kroll, healthcare was the most attacked industry, overtaking finance, accounting for 23% of all data breaches last year. While hacking was the most common breach cause in 2024, many cybersecurity incidents were due to malicious and negligent insiders, and these incidents can be costly to resolve. A recent study by the Ponemon Institute on behalf of DTEX Systems sought to identify how prevalent insider breaches are, the financial impact of these incidents, and how organizations are addressing insider risk. The survey revealed that organizations are increasingly adopting insider risk management programs, with the percentage of companies that have an insider risk management program increasing from 77% in 2023 to 81% in 2024. The amount of the IT security budget devoted to insider risk management is also...

Read More
Healthcare Was the Most Breached Industry in 2024
Feb25

Healthcare Was the Most Breached Industry in 2024

A recent report from the financial and risk advisory firm Kroll has confirmed that healthcare is now the primary target for cybercriminals, having overtaken finance for data breaches in 2024. In 2024, healthcare accounted for almost one-quarter (23%) of all data breaches, overtaking finance (22%), albeit by the smallest of margins. In 2023, finance topped the list with 26% of data breaches with healthcare in second place with 18% of data breaches. Over the past few years, finance and healthcare have been vying for the top spot for data breaches, and there is no reason to suggest any change in 2025; however, the Kroll Data Breach Outlook 2025 report provides interesting insights into attacks on other sectors. Cyber actors are conducting fewer attacks on other often targeted sectors such as professional services, retail, technology, and education, with attacks on the technology sector falling by 46%, attacks on education falling by 38%, and retail attacks falling by 33%. Last year saw an increase in attacks on the industrial services, manufacturing, government, and insurance sectors,...

Read More
VectraRx Mail Pharmacy Services Notifies 109K Individuals About Data Breach
Feb25

VectraRx Mail Pharmacy Services Notifies 109K Individuals About Data Breach

Cyberattacks and data breaches have recently been announced by VectraRx Mail Pharmacy Services, St. Andrew’s Resources for Seniors System, Jewish Child Care Association of New York, and the Columbus Division of Fire. VectraRx Mail Pharmacy Services VectraRx Mail Pharmacy Services, a New York-based mail order pharmacy, has suffered a major data breach involving the protected health information of 109,383 individuals. On February 6, 2025, VetraRx disclosed details of the incident, stating that unusual activity was identified in its computer systems on December 13, 2025, and a third-party cybersecurity firm was engaged to investigate the cause of the activity. The investigation confirmed that an unauthorized actor had access to its network and may have viewed or acquired certain data. VetraRx did not disclose in the breach notice when its network was first breached or the duration of the unauthorized access. The review of the exposed data was completed on January 7, 2025, when it was confirmed that the exposed electronic protected health information (ePHI) included names, dates of...

Read More
Three Healthcare Providers Notify Patients About 2024 Data Breaches
Feb24

Three Healthcare Providers Notify Patients About 2024 Data Breaches

Data breaches have recently been announced by Consultants in Pain Medicine in Texas, Claris Vision Holdings in Massachusetts, and Precision Orthopedics and Sports Medicine in Maryland. Consultants in Pain Medicine Texas Consultants in Pain Medicine, a San Antonio, Texas-based pain management practice, has recently notified the Texas Attorney General about a security incident that saw unauthorized individuals access its network between June 26, 2024, and July 7, 2024. The forensic investigation confirmed that the attackers had access to patient data and exfiltrated files from the network. The file review concluded on January 17, 2025, and it was confirmed that full names, Social Security numbers, dates of birth, driver’s license numbers or state identification numbers, financial account information, passport numbers, medical information, and/or health insurance policy information had been stolen. Notification letters started to be mailed to the affected individuals on February 14, 2025. Individuals whose Social Security numbers were involved were offered complimentary credit...

Read More
Vulnerability Identified in Medixant RadiAnt DICOM Viewer
Feb24

Vulnerability Identified in Medixant RadiAnt DICOM Viewer

A vulnerability has been identified in the Medixant RadiAnt DICOM Viewer, a commonly used PACS DICOM viewer for medical images. The vulnerability is tracked as CVE-2025-1001 and is a medium-severity vulnerability with a CVSS v3.1 base score of 5.7 (v4 base score 5.7). The vulnerability affects RadiAnt DICOM Viewer version 2024.02 and is due to the update mechanism failing to verify the update server’s certificate. The vulnerability could be exploited in a machine-in-the-middle (MitM) attack, and successful exploitation could allow an attacker to modify the response from the server and deliver malicious updates to the user. Medixant has addressed the issue and recommends users update their software to version v2025.1 or a later version. If any users are unable to apply the update, steps should be taken to prevent the vulnerability from being exploited. The mitigations involve preventing any updates from being applied to the software. The display of available updates should be disabled via the command reg add “HKCU\Software\RadiAnt Viewer” /t REG_DWORD /v CheckUpdate /d 0...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist