25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Luxottica Agrees $250,000 Settlement to Resolve Data Breach Litigation
Dec19

Luxottica Agrees $250,000 Settlement to Resolve Data Breach Litigation

Luxottica, the world’s largest eyewear company, has agreed to settle class action data breach litigation related to a 2020 hacking incident that involved unauthorized access to an appointment scheduling application that contained the personal and protected health information of more than 829,000 patients of its eye care partners. The unauthorized access occurred between August 5 and August 9, 2020, and the affected individuals were notified in November of that year. The breached data included names, health information, financial information, and Social Security numbers. Several individuals affected by the data breach took legal action seeking damages and restitution. The lawsuits were consolidated into a single action – In re: Luxottica of America Inc. Data Security Breach Litigation – in the District Court for the Southern District of Ohio. The lawsuits alleged Luxottica failed to implement reasonable and appropriate safeguards, and had those measures been implemented, the data breach could have been prevented. Luxottica maintains there was no wrongdoing but chose to settle...

Read More
Health Sector Warned About Ongoing Credential Harvesting Campaigns
Dec19

Health Sector Warned About Ongoing Credential Harvesting Campaigns

The Health Sector Cybersecurity Coordination Center (HC3) has issued an updated Analyst Note about credential harvesting, which includes a warning about an active credential harvesting campaign targeting grantees in the health sector. The cybersecurity Cofense has also issued an alert about a credential harvesting campaign spoofing the email security companies Proofpoint, Mimecast, and Virtru. Credential harvesting is a term covering the collection of login credentials – usernames and passwords – by malicious actors, either for use in future cyberattacks or to sell on or trade with other threat actors. The theft of the credentials of a single user can have far-reaching consequences. One only needs to look at the February 2024 ransomware attack on Change Healthcare to see the huge harm that can be caused. The ransomware attack on Change Healthcare saw an affiliate of the BlackCat ransomware group steal an estimated 100 million healthcare records. The credentials of a low-level customer support employee were obtained by a ransomware affiliate. The credentials had been posted on...

Read More
Texas Attorney General Sues New York Doctor for Providing Abortion Pills to Texas Resident
Dec18

Texas Attorney General Sues New York Doctor for Providing Abortion Pills to Texas Resident

Texas Attorney General Ken Paxton has filed a lawsuit in the District Court of Collin County, Texas, against a New York doctor accused of mailing abortion pills to a Texas telemedicine patient, in violation of multiple state laws. Dr. Margaret Daley Carpenter, co-founder of the Abortion Coalition for Telemedicine, is alleged to have prescribed abortion medications to a 20-year-old patient in Collin County Texas, knowing the woman lived in Texas, which prohibits physicians and medical suppliers from providing abortion-inducing medications via the mail service or courier delivery. The State of Texas Health & Safety Code requires any physician performing or inducing an abortion to be licensed to practice medicine in the state of Texas and they must hold admitting privileges at a hospital no further than 30 miles from the location where the abortion procedure takes place. The Texas Admin Code requires physicians who treat patients or prescribe medications to Texas residents through telehealth services to hold a valid Texas medical license. Dr. Carpenter does not have a license to...

Read More
CISA Seeks Comment on National Cyber Incident Response Plan Update
Dec18

CISA Seeks Comment on National Cyber Incident Response Plan Update

The Cybersecurity and Infrastructure Security Agency (CISA) is seeking comment on the draft National Cyber Incident Response Plan (NCIRP) Update, published in the Federal Register on December 16, 2024. Comments will be accepted on the draft update until January 15, 2025. The NCIRP is a national strategic framework for coordinated response to cyber incidents and was first published in 2016. The update was issued in response to the changing cyber threat landscape, and addresses significant changes in policy and federal law, and the new organizational capabilities since the NCIRP was released 8 years ago. The NCIRP concerns cyber incidents of severity Level 2 or above per the Cyber Incident Severity Scheme, which means the incidents may impact public health or safety, national security, economic security, foreign relations, civil liberties, or public confidence. The NCIRP covers four main areas of effort: Asset Response, Threat Response, Intelligence Support, and Affected Entity Response, and includes coordination mechanisms, key decision points, and priority activities. The NCIRP...

Read More
BD Identifies High Severity Vulnerability in its Diagnostic Solutions Products
Dec18

BD Identifies High Severity Vulnerability in its Diagnostic Solutions Products

Becton, Dickinson, and Company (BD) has discovered a high-severity vulnerability affecting several of its BD Diagnostic Solutions Products. The vulnerability, tracked as CVE-2024-10476 (CVSS v3, 8.0), is due to the use of default credentials, which were intended for use only by BD technical support teams within the clinical setting. Exploitation of the vulnerability could potentially allow a threat actor to access, modify, or delete data, including personally identifiable information (PII) and protected health information (PHI). The vulnerability could be exploited in a low-complexity attack, which could cause a system shutdown or impact the availability of the system. The vulnerability affects all versions of the following products: BD BACTEC Blood Culture System BD COR System BD EpiCenter Microbiology Data Management System BD MAX System BD Phoenix M50 Automated Microbiology System BD Synapsys Informatics Solution Exploitation of the vulnerability would require a threat actor to have direct access (logical or physical) to the affected product, so a threat actor would need to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist