NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Feds Sound Alarm About Ghost Ransomware Group
Feb21

Feds Sound Alarm About Ghost Ransomware Group

U.S authorities have issued a warning about the China-based Ghost ransomware group, which has conducted ransomware attacks in around 70 countries on multiple industry sectors including healthcare, education, religious institutions, technology, manufacturing, and government networks. The group, also known as Cring, Crypt3r, Phantom, Strike, Hello, Wickrme, HsHarada, and Rapture, has been active since at least 2021, and its victims include many small- to medium-sized businesses. According to the joint cybersecurity alert from the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), the group conducts attacks indiscriminately, targeting low-hanging fruit – businesses with poorly secured Internet-facing servers. The group uses publicly available exploits for multiple vulnerabilities, some of which date back to 2009. The group has exploited vulnerabilities in Fortinet FortiOS appliances (CVE-2018-13379), Adobe ColdFusion servers (CVE2010-2861 and CVE-2009-3960), Microsoft...

Read More
TRICARE Administrator Pays $11.23M Penalty to Resolve Cybersecurity-related FCA Claims
Feb21

TRICARE Administrator Pays $11.23M Penalty to Resolve Cybersecurity-related FCA Claims

The U.S. Department of Justice has announced that Health Net Federal Services (HNFS) and its parent company, Centene Corporation, have agreed to pay a $11,253,400 penalty to settle allegations that HNFS falsely certified compliance with the cybersecurity requirements of its Defense Health Agency (DHA) contract to manage the TRICARE healthcare program. The military health benefits administrator was investigated by the Civil Division’s Commercial Litigation Branch (Fraud Section) and the U.S. Attorney’s Office for the Eastern District of California. The investigation revealed HNFS had not implemented certain cybersecurity controls that were required under its DHA contract between 2015 and 2018 yet certified in multiple annual reports that those controls were in place. The terms of the contract required HNFS to comply with 48 C.F.R. § 252.204-7012 cybersecurity standards and 51 security controls from NIST Special Publication 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations. HNFS failed to scan for known vulnerabilities and remediate...

Read More
Warby Parker to Pay $1.5 Million To Resolve HIPAA Violations
Feb21

Warby Parker to Pay $1.5 Million To Resolve HIPAA Violations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed its first financial penalty under the Trump administration for noncompliance with the HIPAA Rules. Warby Parker, Inc., a manufacturer and online retailer of prescription and non-prescription eyewear, must pay a $1.5 million civil monetary penalty to resolve alleged violations of the HIPAA Rules. OCR launched an investigation of Warby Parker to assess compliance with the HIPAA Rules after receiving a data breach report in December 2018. Hackers gained access to the accounts of customers between September 25, 2018, and November 30, 2018, via its website in a credential stuffing attack, where usernames and passwords obtained in a data breach at an unrelated entity are used to access accounts. These attacks are made possible by individuals using the same usernames and passwords on multiple platforms. Warby Parker filed an addendum with OCR on September 18, 2020, updating the initial breach report to 197,986 affected individuals. Data compromised in the incident included names, addresses,...

Read More
OCR Rescinds 2022 Guidance on Gender Affirming Care
Feb21

OCR Rescinds 2022 Guidance on Gender Affirming Care

Following President Trump’s Executive Order 14187 – Protecting Children from Chemical and Surgical Mutilation – the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has rescinded its previously issued guidance on gender affirming care – HHS Notice and Guidance on Gender Affirming Care, Civil Rights, and Patient Privacy. The Executive Order put an end to the United States funding, sponsoring, promoting, assisting, and supporting the transitioning of children from one sex to another, with President Trump committing to rigorously enforcing all laws that prohibit or limit gender transitioning procedures. President Trump also issued Executive Order 14168 – Defending Women from Gender Ideology Extremism and Restoring Biological Truth to the Federal Government – which made it the policy of the United States to only recognize two sexes – male and female. The rescinding of previous OCR guidance on gender affirming care aligns with both of those Executive Orders. The OCR guidance was issued in March 2022 under the Biden administration,...

Read More
U.S. Sanctions Russian Bulletproof Hosting Service for Supporting LockBit Ransomware Attacks
Feb20

U.S. Sanctions Russian Bulletproof Hosting Service for Supporting LockBit Ransomware Attacks

Last week, the United States, United Kingdom, and Australia announced further action in ongoing efforts to disrupt the LockBit ransomware-as-a-service operation, including jointly designating Zservers for its role in supporting LockBit ransomware attacks and sanctioning two Russian nationals. LockBit is one of the most deployed ransomware variants. The group that shares the name was targeted in an international law enforcement operation, Operation Cronos, involving law enforcement agencies in 10 countries. Announced in February 2024, the operation caused significant disruption to the group’s operations at all levels. Infrastructure was seized, including the data leak site and 34 servers in multiple countries, along with cryptocurrency accounts linked to the group. International arrest warrants were issued, and arrests were made. The group recovered but has been operating in a limited capacity ever since. Efforts to disrupt the group are continuing. Almost a year after Operation Cronos was announced, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC),...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist