25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative
Nov01

OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative

The HHS Office for Civil Rights (OCR) has confirmed that another settlement has been agreed to resolve a ransomware-related HIPAA violation, its second settlement in as many days. The latest HIPAA enforcement action is the first under OCR’s new risk analysis enforcement initiative and involved a $90,000 financial penalty and the adoption of a corrective action plan for Bryan County Ambulance Authority in Oklahoma. A risk analysis is a required provision of the HIPAA Security Rule – 45 C.F.R. § 164.308(a)(1)(ii)(A) – and one of the most important for security. If a risk analysis is not conducted, it is highly likely that risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) will remain unknown and could be exploited by malicious actors to gain access to networks and ePHI. When risks are identified, they must be managed and reduced to a low and acceptable level. OCR’s investigations of large data breaches have shown that a risk analysis is something many HIPAA-regulated entities get wrong. They either...

Read More
$500,000 HIPAA Penalty for South Dakota Plastic Surgery Practice
Nov01

$500,000 HIPAA Penalty for South Dakota Plastic Surgery Practice

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle an investigation of a ransomware attack at a South Dakota plastic surgery practice, its 6th ransomware investigation to result in a financial penalty. OCR has seen a 264% increase in ransomware-related large data breaches since 2018, as ransomware groups have extensively targeted healthcare providers. OCR investigates all large data breaches and has closed investigations of several ransomware-related breaches without pursuing civil monetary penalties. Financial penalties are pursued if OCR identifies a failure to comply with the HIPAA Rules. In multiple guidance documents and video presentations, OCR has explained that HIPAA Security Rule compliance improves defenses against ransomware attacks, helps covered entities detect attacks in progress, and limits the severity of attacks. “Ransomware attacks often reveal a provider’s underlying failures to comply with the HIPAA Security Rule requirements such as conducting a risk analysis or managing identified risks and vulnerabilities to...

Read More
Data Breaches Reported by Mystic Valley Elder Services & St. Anthony Regional Hospital
Oct31

Data Breaches Reported by Mystic Valley Elder Services & St. Anthony Regional Hospital

Mystic Valley Elder Services, a Malden, Massachusetts-based non-profit agency providing home and community-based care to elders and adults living with disabilities, has started issuing individual notifications about a cyberattack and data breach that was identified on April 5, 2024. A digital forensics company was engaged to investigate the unauthorized activity and confirmed that there had been unauthorized access to its internal systems on April 5, 2024, during which time files may have been acquired. A review was conducted of all affected files which confirmed on July 11, 2024, that protected health information had been exposed. The data involved varied from individual to individual and may have included names, dates of birth, passport numbers, financial account numbers, payment card numbers, online credentials, taxpayer identification numbers, Social Security numbers, driver’s license numbers, health insurance information, and medical information. Notification letters are now being mailed to the affected individuals and complimentary credit monitoring and identity theft...

Read More
HPH Sector Warned About Exploitation of Miracle Exploit Vulnerabilities in Oracle Systems
Oct31

HPH Sector Warned About Exploitation of Miracle Exploit Vulnerabilities in Oracle Systems

A critical vulnerability affecting multiple Oracle products is being exploited in the wild. The vulnerability was dubbed The Miracle Exploit by the security researchers who discovered it, due to its severity and the number of products they affected – all products based on Oracle Fusion Middleware and Oracle online systems. The vulnerability is one of a pair of related vulnerabilities that were discovered two years apart. The vulnerabilities can be chained, and both can lead to remote code execution. The Oracle Fusion Middleware products are used to build web interfaces for Java EE applications and any website developed by ADF Faces framework is affected. The vulnerabilities also affect Oracle Business Intelligence, Enterprise Manager, Identity Management, SOA Suite, WebCenter Portal, Application Testing Suite, and Transportation Management. The vulnerabilities are tracked as CVE-2022-21445 (CVSS 9.8) and CVE-2022-21497 (CVSS 8.1) and can be exploited easily by an unauthenticated attacker with network access via HTTP for an application takeover. Successful exploitation can lead to a...

Read More
Albany ENT & Allergy Services Pays $500K Penalty and Commits to $2.25M Cybersecurity Investment
Oct30

Albany ENT & Allergy Services Pays $500K Penalty and Commits to $2.25M Cybersecurity Investment

The New York multi-site medical practice, Albany ENT & Allergy Services, has agreed to pay a $500,000 financial penalty to the state of New York and will invest $2.25 million to strengthen its information security practices after suffering two ransomware attacks that saw threat actors gain access to the medical records of more than 213,000 New York patients. Under the agreement, a further $500,000 in penalties must be paid if Albany ENT & Allergy Services fails to invest the required $2.25 million in upgrades and maintenance of its information security program over the next 5 years. An investigation was launched by the Office of the New York Attorney General (OAG) following an intrusion of Albany ENT & Allergy Services’ network by two different threat actors between March 23, 2023, and April 4, 2023. The first intrusion involved ransomware and was discovered on March 27, 2023, when files were encrypted. Systems and data were restored by the healthcare provider’s IT vendor; however, the source of the intrusion was not identified before the restoration of external network...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist