25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

East River Medical Imaging $1.85 Million Settlement Due to Receive Final Approval
Oct18

East River Medical Imaging $1.85 Million Settlement Due to Receive Final Approval

A $1.85 million settlement to resolve a class action data breach lawsuit against the New York radiology group, East River Medical Imaging, is due to receive final approval on October 22, 2024. Individuals affected by the breach have until October 22, 2024, 2:30 PM EDT to submit a claim. A security breach was detected by East River Medical Imaging on September 20, 2023. A hacker was determined to have accessed its systems from August 31, 2023, to September 20, 2023, and during that time files were copied from its network. Patient and employee information was compromised including names, contact information, insurance information, exam and/or procedure information, referring physician names, imaging results, financial account information, driver’s license numbers, and Social Security numbers. Notification letters were sent to the affected individuals starting November 22, 2023, and the breach was reported to the HHS’ Office for Civil Rights on November 22, 2024, as affecting 605,809 individuals. The first lawsuit over the data breach was filed by the law firm Shub & Johns...

Read More
OCR Announces 50th HIPAA Right of Access Penalty
Oct18

OCR Announces 50th HIPAA Right of Access Penalty

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Rules. A civil monetary penalty of $70,000 has been imposed on the Silver Spring, MD, dental practice Gums Dental Care for failing to provide a patient with timely access to her and her children’s medical records. This is the 50th HIPAA Right of Access enforcement action to result in a financial penalty since OCR launched its HIPAA Right of Access enforcement initiative in the fall of 2019. The complainant sent a written request to Gums Dental Care on or around April 8, 2019, requesting copies of her protected health Information (PHI) and the PHI of her children. She requested the records be sent to her electronically via email and received a reply the same day confirming how many times each of them had visited the dental practice but was not provided with the requested records.  She filed a complaint with OCR on May 1, 2019, after no records had...

Read More
Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics
Oct17

Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics

Healthcare and public health (HPH) and other critical infrastructure sectors have been warned that Iranian cyber actors are using brute force tactics for initial access in targeted attacks on critical infrastructure entities in the United States. The cybersecurity advisory was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC). Since October 2023, the authoring agencies have observed Iranian cyber actors using brute force tactics such as password spraying and multifactor authentication (MFA) push bombing to obtain credentials and information that allows them to move deep into networks, obtain additional credentials, escalate privileges, and achieve persistence. Password spraying is the use of commonly used and default passwords to attempt access to accounts and in the case of the Iranian cyber actors, Microsoft 365, Azure, and Citrix...

Read More
Email Account Breaches Reported by 5 HIPAA-Regulated Entities
Oct17

Email Account Breaches Reported by 5 HIPAA-Regulated Entities

Email is the second most common location for breached healthcare information behind network servers. Over the past few days, five HIPAA-regulated entities have reported breaches of HIPAA email rules and the exposure of patient data. Hafetz and Associates, New Jersey Hafetz and Associates, a Linwood, NJ-based independent insurance agency, has confirmed that employee email accounts were compromised in a recent phishing attack. Immediate action was taken on October 12, 2024, to secure its email accounts when unauthorized activity was detected, and an investigation was launched to determine the extent of the security breach. Hafetz and Associates confirmed that several employee email accounts had been accessed by an unauthorized third party at various points between July 24, 2023, and October 12, 2023. The review of the accounts confirmed that they contained information such as names, dates of birth, Social Security numbers, and/or benefits election information. The data analysis involved checking all emails and attachments in the affected accounts, identifying exposed protected health...

Read More
Is GoDaddy HIPAA Compliant?
Oct16

Is GoDaddy HIPAA Compliant?

GoDaddy is not HIPAA compliant for its web hosting services, however organizations that subscribe to a Business Professional or a Premium Security Microsoft 365 account through GoDaddy can take advantage of a HIPAA compliant email service that allows them to send and receive emails containing Protected Health Information using their domain name. GoDaddy is a domain name registrar and web hosting company that provides tools to help build and promote websites, host marketplaces, and collect payments. The company also offers advanced security features to protect websites from malicious bots, brute force hacks, and DDoS attacks. Other add-ons perform updates for plugins, backups, and search engine optimization. Despite its advanced security features, and the option to host websites on dedicated servers, GoDaddy does not support HIPAA compliance for its web hosting services. This is because GoDaddy leases most of its data centers and is not responsible for their physical security. Therefore, GoDaddy is unable to comply with the physical safeguards of the HIPAA Security Rule. What this...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist