25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Judge Approves $7 Million Brightline Data Breach Settlement
Feb13

Judge Approves $7 Million Brightline Data Breach Settlement

A $7 million settlement has been agreed to resolve a lawsuit filed against the virtual mental health provider Brightline over a hacking incident by the Clop threat group in 2023 that resulted in the theft of the protected health information of up to 1 million individuals. Brightline was one of 130 companies to have data stolen by the Clop threat group in January 2023, after the mass exploitation of a critical remote code execution vulnerability in Fortra’s GoAnywhere MFT file transfer solution. The vulnerability was exploited between January 18, 2023, and January 30, 2023. The Clop actors created unauthorized user accounts after exploiting the vulnerability and leveraged those accounts to download files from victims’ hosted MFTaaS environments. Brightline said the information of 964,300 individuals was potentially stolen in the attack including names, addresses, dates of birth, member identification numbers, health plan coverage start and end dates, employer names, and Social Security numbers. Notifications were issued in May 2023. Four lawsuits were filed against Brightline...

Read More
Insights into the Current Healthcare Threat Landscape
Feb12

Insights into the Current Healthcare Threat Landscape

Two recent reports provide insights into the current threat landscape and the evolving tactics, techniques, and procedures of the growing number of ransomware groups and other threat actors targeting healthcare and other critical infrastructure entities in the United States. According to the Information Technology – Information Sharing and Analysis Center (IT-ISAC), 57% of ransomware attacks tracked by IT-ISAC in 2024 were conducted on entities in the United States, with the UK the next most targeted country, accounting for just 4.6% of attacks. The IT-ISAC report – Exploring the Depths: Analysis of the 2024 Ransomware Landscape and Insights for 2025 – is based on threat intelligence gathered from approximately 3,500 ransomware attacks in 2024, a significant increase from the 3,000 ransomware attacks identified in 2023. The increase is due to an improved ability to track ransomware attacks and threat actors conducting attacks in increasing volume, in part due to the increased reluctance of victims to pay ransom demands. A report by Chainalysis earlier this month shows a 35%...

Read More
41% of 2024 Third Party Breaches Affected Healthcare Organizations
Feb12

41% of 2024 Third Party Breaches Affected Healthcare Organizations

New research has confirmed that healthcare is the industry most impacted by third-party breaches, accounting for 41.2% of all third-party breaches tracked by the cyber risk intelligence and third-party risk management software provider Black Kite. Increasing digital connectedness in healthcare drives progress but also heightens risk, and threat actors are increasingly taking advantage of systemic vulnerabilities to gain access to healthcare networks, including turning trusted vendor relationships into gateways for disruption and data theft. Black Kite explained that the healthcare industry is particularly vulnerable due to the high value of patient data, the need for constant access to that data, the reliance on third-party vendors, and inherent security challenges within the healthcare ecosystem. Organizations are increasingly reliant on software platforms and third-party tools, but vulnerabilities in those tools can be exploited by threat actors to attack all organizations that rely on those tools, as was demonstrated by the mass exploitation of a zero-day vulnerability in...

Read More
Watchdog Organization Calls for Investigations of Crisis Pregnancy Centers Over Potential Privacy Violations
Feb12

Watchdog Organization Calls for Investigations of Crisis Pregnancy Centers Over Potential Privacy Violations

The non-profit civil liberties organization, Electronic Frontier Foundation (EFF), has written to Attorneys General in Arkansas, Florida, Missouri, and Texas, requesting they open investigations of crisis pregnancy centers (CPCs) in their respective states over potential privacy violations and deceptive business practices. There are currently an estimated 2,750 CPCs in the United States, the majority of which are affiliated with one or more of three organizations: Care Net, Heartbeat International, and the National Institute of Family and Life Advocates. CPCs generally offer pregnancy testing services, counseling, and information, with some also providing limited medical services; however, many CPCs are not licensed medical clinics. CPCs are often connected to religious organizations and have a strong anti-abortion stance and therefore do not offer reproductive healthcare such as abortions or, in some cases, contraception. According to EFF, in 2022, CPCs received $1.4 billion in revenue, including substantial federal and state funds. The letters from EFF follow complaints filed...

Read More
HIPAA Training for Physicians
Feb12

HIPAA Training for Physicians

Physicians must receive documented HIPAA training that covers the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule, is provided during onboarding and repeated annually as an industry best practice, and is supported by ongoing security awareness training so that uses and disclosures of protected health information, HIPAA safeguards, and breach response requirements are consistently followed in clinical and operational workflows. HIPAA Training Obligations for Physicians Under the HIPAA Privacy Rule, a HIPAA Covered Entity must train all members of its workforce on the organization’s policies and procedures related to protected health information, as necessary and appropriate for them to carry out their functions. Physicians are workforce members when they are employed by, under contract with, or otherwise operate under the direct control of a HIPAA Covered Entity, whether or not they are paid. Under the HIPAA Security Rule, HIPAA Covered Entities and Business Associates must implement a security awareness and training program for all workforce members,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist