25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

MSP HIPAA Compliance for Managed IT Service Providers
Feb01

MSP HIPAA Compliance for Managed IT Service Providers

MSP HIPAA compliance for managed IT service providers often consists of not only understanding the compliance capabilities of the services being provided, but also understanding the compliance obligations of clients that services are being provided to. Due to the many different types of HIPAA entity, understanding each client’s compliance obligations can be one of their biggest challenges. Regardless of the type of IT service(s) being provided, managed IT service providers have multiple challenges to overcome. Common challenges include integrating MSP services with clients’ legacy systems, resolving expertise gaps between providers and users, establishing levels of client control, and securing clients’ networks, systems, and devices to ensure the MSP security stack works effectively. When providing managed IT services to a HIPAA covered entity or business associate (collectively “HIPAA entities” for the purpose of this article), MSPs have a potentially bigger challenge to overcome – MSP HIPAA compliance. In many cases, there are three areas of MSP HIPAA compliance that can be...

Read More
Backdoor Identified in Contec CMS8000 Patient Monitors That Transmits Patient Data
Jan31

Backdoor Identified in Contec CMS8000 Patient Monitors That Transmits Patient Data

A remote code execution vulnerability and a hidden backdoor have been identified in the firmware of widely used patient monitors from Contec Health – Contec CMS8000 patient monitors and Epsimed MN-120 patient monitors. Testing by the Cybersecurity and Infrastructure Security Agency (CISA) determined the backdoor allows patient data to be sent to a hard-coded IP address. Contec Health is a Chinese healthcare technology company that provides patient monitoring systems, diagnostic equipment, and laboratory instruments. Its products are extensively used by healthcare organizations in the United States and Europe. After being alerted to firmware vulnerabilities by an anonymous researcher, CISA investigated and confirmed the presence of three vulnerabilities in multiple firmware versions, including a backdoor that silently transfers patient data in plain text to an external hard-coded IP address. The backdoor was present in all versions of the Contec Health CMS8000 Patient Monitor and Epsimed MN-120 Patient Monitor. In their default configuration, the products transmit patient data in...

Read More
NorthBay Healthcare Notifies 569K Individuals About February 2024 Data Breach
Jan31

NorthBay Healthcare Notifies 569K Individuals About February 2024 Data Breach

NorthBay Healthcare Corporation, a nonprofit healthcare system that operates two hospitals – NorthBay Medical Center & NorthBay VacaValley Hospital – and multiple primary care locations in California, has recently announced a data breach involving the personal and protected health information of 569,012 individuals. According to the notification sent to the Maine Attorney General, suspicious activity was identified within its network on February 23, 2024. An internal investigation was launched, law enforcement was notified, and third-party cybersecurity experts were engaged to assist with the investigation. The notification letter confirms that a threat actor gained access to its network on January 11, 2024, and the unauthorized access continued until April 1, 2024, more than 6 weeks after the security incident was detected. The notification letter does not explain why it took so long to eject the unauthorized third party from its network. The investigation confirmed that the threat actor had access to files containing patient data. The file review confirmed that...

Read More
2024 Healthcare Data Breach Report
Jan30

2024 Healthcare Data Breach Report

Large healthcare data breaches continue to be reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in high numbers. As of January 28, 2025, the OCR data breach portal shows 725 data breaches of 500 or more records in 2024, the third consecutive year that more than 700 large data breaches have been reported to OCR. That total could well change, as there is usually a delay in adding data breaches to the breach portal, as OCR conducts checks of all breach reports before adding them to the breach portal. The current figures indicate a slight (2.95%) year-over-year reduction in healthcare data breaches, 22 fewer data breaches than 2023’s record-breaking number of data breaches. As the above bar chart shows, healthcare data breaches have historically increased each year, with the biggest annual increases between 2018 and 2021, when large data breaches increased by 93.7%, primarily due to a sharp increase in hacking and ransomware incidents. Between January 1, 2028, and September 30, 2023, OCR reported a 278% increase in ransomware attacks, and...

Read More
Study Reveals 88% of Companies Experienced a Ransomware Attack Last Year
Jan30

Study Reveals 88% of Companies Experienced a Ransomware Attack Last Year

A recent survey conducted by the Ponemon Institute on behalf of Illumio, a zero-trust segmentation platform provider, revealed 88% of surveyed organizations had experienced one or more ransomware attacks in the past 12 months, highlighting the extent to which ransomware groups are running riot and the difficulty organizations have defending against attacks. The survey was conducted on 2,547 IT and cybersecurity professionals in the United States, United Kingdom, Germany, France, Australia, and Japan, including 7% of respondents from the healthcare and pharmaceutical sectors. The findings of the survey were published in Illumio’s Global Cost of Ransomware Report. On average, organizations spent almost one-third of their IT budget on ransomware defense, yet 88% still experienced a ransomware attack, showing it is not how much money is devoted to ransomware defense but how that information is spent that is important. Multifactor authentication, automated patching, intrusion prevention/detection systems, email security, and segmentation/micro-segmentation were the most common...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist