NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Republicans Form Working Group to Develop Federal Data Privacy Law
Feb13

Republicans Form Working Group to Develop Federal Data Privacy Law

House Republicans have formed a working group to draft privacy legislation that will set federal privacy standards to replace the current patchwork of state laws. All previous efforts to introduce comprehensive federal privacy legislation have failed, and the absence of a federal privacy law has led to around 20 states introducing their own comprehensive data privacy laws. In 2022, the American Data Privacy and Protection Act (ADPPA) was billed as the best opportunity so far to set federal data privacy standards. While the ADPPA had strong bipartisan support, several elements of the bill proved problematic, including the preemption of state laws. The failure of ADPPA to get sufficient support led to the introduction of the American Privacy Rights Act of 2024, which eliminated some of the more problematic requirements of its predecessor. While both of these bills would have seen privacy protections greatly improved in many states, states such as California would have seen their privacy protections watered down. Neither bill made it to a House vote. Last month, more than three dozen...

Read More
Hackers Breach Systems of HIPAA-Regulated Entities in Missouri, Nevada, Texas & Wisconsin
Feb13

Hackers Breach Systems of HIPAA-Regulated Entities in Missouri, Nevada, Texas & Wisconsin

Kansas City Hospice & Palliative Care in Missouri, Apex Custom Software in Texas, ARC Community Services in Wisconsin, and REMSA Health in Nevada have experienced hacking incidents that potentially involved unauthorized access to patient data. Kansas City Hospice Falls Victim to Black Suit Ransomware Attack Kansas City Hospice & Palliative Care in Missouri is notifying 3,621 individuals about a 2024 ransomware attack. Kansas City Hospice confirmed that third-party digital forensics experts were engaged to investigate the incident and determine the extent and scope of the unauthorized activity. While the attack disrupted certain IT systems, services continued to be provided to patients throughout the attack and recovery. The recovery process has now been completed, and steps are being taken to improve security. It is unclear exactly when the attack occurred, when it was detected, or the exact types of data compromised in the incident. On October 19, 2024, the Black Suit ransomware group added Kansas City Hospice to its data leak site, claiming 600+GB of data was stolen in...

Read More
Judge Approves $7 Million Brightline Data Breach Settlement
Feb13

Judge Approves $7 Million Brightline Data Breach Settlement

A $7 million settlement has been agreed to resolve a lawsuit filed against the virtual mental health provider Brightline over a hacking incident by the Clop threat group in 2023 that resulted in the theft of the protected health information of up to 1 million individuals. Brightline was one of 130 companies to have data stolen by the Clop threat group in January 2023, after the mass exploitation of a critical remote code execution vulnerability in Fortra’s GoAnywhere MFT file transfer solution. The vulnerability was exploited between January 18, 2023, and January 30, 2023. The Clop actors created unauthorized user accounts after exploiting the vulnerability and leveraged those accounts to download files from victims’ hosted MFTaaS environments. Brightline said the information of 964,300 individuals was potentially stolen in the attack including names, addresses, dates of birth, member identification numbers, health plan coverage start and end dates, employer names, and Social Security numbers. Notifications were issued in May 2023. Four lawsuits were filed against Brightline...

Read More
Insights into the Current Healthcare Threat Landscape
Feb12

Insights into the Current Healthcare Threat Landscape

Two recent reports provide insights into the current threat landscape and the evolving tactics, techniques, and procedures of the growing number of ransomware groups and other threat actors targeting healthcare and other critical infrastructure entities in the United States. According to the Information Technology – Information Sharing and Analysis Center (IT-ISAC), 57% of ransomware attacks tracked by IT-ISAC in 2024 were conducted on entities in the United States, with the UK the next most targeted country, accounting for just 4.6% of attacks. The IT-ISAC report – Exploring the Depths: Analysis of the 2024 Ransomware Landscape and Insights for 2025 – is based on threat intelligence gathered from approximately 3,500 ransomware attacks in 2024, a significant increase from the 3,000 ransomware attacks identified in 2023. The increase is due to an improved ability to track ransomware attacks and threat actors conducting attacks in increasing volume, in part due to the increased reluctance of victims to pay ransom demands. A report by Chainalysis earlier this month shows a 35%...

Read More
41% of 2024 Third Party Breaches Affected Healthcare Organizations
Feb12

41% of 2024 Third Party Breaches Affected Healthcare Organizations

New research has confirmed that healthcare is the industry most impacted by third-party breaches, accounting for 41.2% of all third-party breaches tracked by the cyber risk intelligence and third-party risk management software provider Black Kite. Increasing digital connectedness in healthcare drives progress but also heightens risk, and threat actors are increasingly taking advantage of systemic vulnerabilities to gain access to healthcare networks, including turning trusted vendor relationships into gateways for disruption and data theft. Black Kite explained that the healthcare industry is particularly vulnerable due to the high value of patient data, the need for constant access to that data, the reliance on third-party vendors, and inherent security challenges within the healthcare ecosystem. Organizations are increasingly reliant on software platforms and third-party tools, but vulnerabilities in those tools can be exploited by threat actors to attack all organizations that rely on those tools, as was demonstrated by the mass exploitation of a zero-day vulnerability in...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist