25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Does HIPAA Apply to Minors?
Dec25

Does HIPAA Apply to Minors?

The privacy standards of HIPAA apply to minors inasmuch as a minor’s health information is subject to the same Privacy Rule protections as an adult’s health information and must be secured in the same way against threats to its confidentiality, integrity, and availability. However, there are differences in the application of HIPAA rights when an individual is an unemancipated minor. A common cause of confusion about how the standards of HIPAA apply to minors relates to consent for health care. The reason for the confusion is that clause (3)(i) of the privacy standard relating to personal representatives (§164.502(g)) states: “If under applicable law a parent, guardian, or other person acting in loco parentis has authority to act on behalf of an individual who is an unemancipated minor in making decisions related to health care, a covered entity must treat such person as a personal representative under this subchapter with respect to Protected Health Information.” Some sources interpret this clause of §164.502(g) to mean that parents, guardians, and others who can represent an...

Read More
Second NetWalker Ransomware Affiliate Sentenced to 20 Years in Jail
Dec25

Second NetWalker Ransomware Affiliate Sentenced to 20 Years in Jail

A Romanian man has been sentenced to 20 years in prison for conducting ransomware attacks on healthcare providers and educational institutions during the pandemic. Daniel Christian Hulea, 30, was an affiliate of the NetWalker ransomware-as-a-service (RaaS) operation. In January 2021, the U.S. Department of Justice reported that more than $450,000 in cryptocurrency had been seized in a coordinated International law enforcement operation against the NetWalker ransomware group. That operation involved the seizure of NetWalker servers in Bulgaria, the analysis of which suggested NetWalker had a network of around 100 affiliates in Eastern Europe. The group is believed to have conducted more than 1,500 ransomware attacks since the Fall of 2019 and is thought to have been responsible for more than $146 million in extortion payments (1,500 BTC). That operation led to charges being filed against a Canadian Netwalker ransomware affiliate, Sebastian Vachon-Desjardins. Vachon-Desjardins was alleged to have obtained more than $27.6 million in ransom payments from attacks in the United States...

Read More
Russian-Israeli National Faces 41-Count Indictment for LockBit Development
Dec24

Russian-Israeli National Faces 41-Count Indictment for LockBit Development

A dual Russian and Israeli national alleged to have been a developer for the infamous LockBit ransomware group has been charged by the U.S. Department of Justice in a 41-count indictment. Rostislav Panev, 51, a resident of Haifa in Israel, was arrested by Israeli authorities in August 2024. An analysis of Penev’s computer revealed he had credentials for a dark web repository containing the source code of several different versions of the LockBit builder, used by affiliates of the Ransomware-a-s-a-Service (RaaS) operation to create custom versions of the LockBit encryptor. The repository also contained leaked Conti ransomware source code and tools used by LockBit affiliates, including StealBit, a tool for exfiltrating data from victims’ networks. The computer also contained credentials for the LockBit control panel. The U.S. Department of Justice alleges Panev was a developer of LockBit ransomware since the group emerged in 2019 and maintained the ransomware group’s infrastructure, including tools used by affiliates to disable anti-virus software, deploy malware across victims’...

Read More
November 2024 Healthcare Data Breach Report
Dec23

November 2024 Healthcare Data Breach Report

There has been a 15.3% month-over-month increase in healthcare data breaches, with 68 data breaches of 500 or more healthcare records reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) in November. November was the worst month of H2 2024 in terms of reported data breaches, and the 4th worst month of the year; however, data breaches were down 8% from November 2024. November’s healthcare data breaches bring the 2024 total up to 667 data breaches, one short of the total for the year to November 30, 2023. While there was an increase in data breaches there was a reduction in breached records, which were down 36.1% month-over-month to 3,437,256 breached records. In 2024, an average of 16,395,000 records were breached each month; however, that number is skewed by the massive data breach at Change Healthcare which affected an estimated 100 million individuals. The median number of breached records each month in 2024 is 6,496,306 records. As the bar chart below shows, there was a massive decrease in breached records compared to the 31 million...

Read More
Illinois Department of Human Services Phishing Attack Impacts 1.1 Million Customers
Dec23

Illinois Department of Human Services Phishing Attack Impacts 1.1 Million Customers

Earlier this year, an email phishing attack on the Illinois Department of Human Services (IDHS) saw multiple employees tricked into disclosing their credentials. The threat actor was able to access email accounts that contained the public assistance account information of more than 1.1 million customers, including the Social Security numbers of 4,701 customers. According to an IDHS media notice on December 20, 2024, the email accounts were compromised on April 25, 2024. Assisted by the Illinois Department of Innovation and Technology (DoIT), IDHS investigated the incident to determine the extent of the data breach and the individuals who had sensitive data exposed. On May 3, 2024, IDHS determined the incident was a reportable data breach under the Illinois Personal Information Protection Act (PIPA); however, it took several months to analyze the email accounts and associated files. The analysis revealed 1,118,993 customers had public assistance account information compromised, including their name and public assistance account number in combination with some or all of the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist