25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

RRCA Accounts Management Falls Victim to Play Ransomware Attack
Nov22

RRCA Accounts Management Falls Victim to Play Ransomware Attack

RRCA Accounts Management and Aspen Healthcare Services have confirmed they experienced ransomware attacks that involved unauthorized access to patient data. Pinnacle Claims Management has recently announced that it was affected by a MOVEit hack in May 2023. RRCA Accounts Management Last month, the Sterling IL-based collection agency, RRCA Accounts Management, announced that it had fallen victim to a ransomware attack by the Play ransomware group. The attack occurred on June 6, 2024, and was detected and blocked on June 7, 2024. The forensic investigation confirmed that the majority of files accessed by the Play ransomware group did not include any personal information; however, some personal information provided by its healthcare clients had been stolen. RRCA confirmed in its breach notice that there was a full release of the stolen data by the Play threat group on August 20, 2024. The personal information stolen in the attack varied from individual to individual and may have included full names, addresses, phone numbers, dates of birth, and email addresses with one or more of the...

Read More
HHS Information Security Program Rated Not Effective for FY24
Nov22

HHS Information Security Program Rated Not Effective for FY24

A review of the U.S. Department of Health and Human Services (HHS) to assess compliance with the Federal Information Security Modernization Act of 2014 (FISMA) for Financial Year 2024 has revealed the HHS information security program is not effective, as was the case with last year’s HHS Office of Inspector General (HHS-OIG) review. The review assessed maturity levels across the five functions of the Cybersecurity Framework – Identify, Protect, Detect, Respond, and Recover, with the level of maturity given one of 5 scores: Level 1 (Ad hoc); Level 2 (Defined); level 3 (Consistently Implemented); level 4 (Managed and Measurable); and Level 5 (Optimized). To receive an effective rating, the HHS must achieve a level 4 rating of Managed and Measurable across all five of the functions of the Cybersecurity Framework. The HHS was assessed on core metrics and supplemental metrics across 10 IG FISMA Domains, but only achieved the Managed and Measurable level in two of those Domains – Risk Management and Information Security Continuous Monitoring, with an overall maturity rating for the...

Read More
October 2024 Healthcare Data Breach Report
Nov22

October 2024 Healthcare Data Breach Report

In October, 57 healthcare data breaches of 500 or more records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, slightly fewer than the 2024 average of 62 data breaches per month. While data breaches were below average, there was a 62.9% month-over-month increase in reported data breaches, following a particularly low number in September (35 breaches) – the lowest total since May 2020. As of October 31, 2024, 594 large data breaches have been reported to OCR, almost 100 fewer than this time last year (593 data breaches). Unless there is a sharp uptick in data breaches in November and December, this year will be one of the exceptionally rare years where there is a year-over-year decline in healthcare data breaches. Across the 57 data breaches, the protected health information of 5,232,507 individuals was exposed, stolen, or impermissibly disclosed, with 35% of that total coming from a single data breach. The number of breached records increased by 2.98% from September, although the total is considerably lower than the median of...

Read More

HIPAA Compliant Hosting

HIPAA compliant hosting is a service most often provided by cloud service providers that enables covered entities and business associates to take advantage of a hosting environment that complies with the HIPAA Security Rule standards. Most often, a HIPAA compliant hosting service includes access controls, data encryption, operating system security, and segregated servers. The Health Insurance Portability and Accountability Act (HIPAA) was signed into law in 1996 at a time when the Internet was still in its infancy and when most healthcare organizations were recording patient information on paper. It could not have been predicted how technology would progress and how IT practices would change over the next two decades, so the legislation has been kept technology neutral. Web hosting and other cloud services are not mentioned in the HIPAA text, but it is covered by the HIPAA Privacy and Security Rules and there are restrictions placed on the use of cloud services in connection with protected health information (PHI ). HIPAA does not prohibit healthcare organizations from moving...

Read More
Ransomware Groups Increasingly Targeting Poorly Secured and Outdated VPNs for Initial Access
Nov21

Ransomware Groups Increasingly Targeting Poorly Secured and Outdated VPNs for Initial Access

Ransomware attacks continue to be conducted at elevated levels, with the number of new victims added to data leak sites increasing slightly (0.72%) in Q3, 2024 from the previous quarter, according to the 2024 Q3 Cyber Threat Report from Corvus. In Q3, 2024 Corvus tracked 1,257 new additions to data leak sites, down 1.64% from Q3, 2023. There has been a marked change in the ransomware landscape, which is far more distributed than last year when a few highly prolific threat groups conducted the majority of attacks. Successful law enforcement operations against LockBit and ALPHV saw affiliates of both groups jump ship, and following the ransomware attack on Change Healthcare, the ALPHV operation was shut down pushing the remaining affiliates into joining other groups or starting up their own operations. In Q3, 2024, there were 59 active ransomware groups, many of which were small-scale ransomware groups, although some highly active ransomware groups remain. The most active group in the quarter was RansomHub, which increased its activity by 160% with at least 195 successful attacks....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist