25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Center for Vein Restoration Data Breach Affects Almost 450,000 Individuals
Dec11

Center for Vein Restoration Data Breach Affects Almost 450,000 Individuals

The Center for Vein Restoration, a Greenbelt, MD-based provider of treatments for varicose and spider veins, has experienced a major data breach affecting current and former patients and employees. Unusual system activity was detected on October 6, 2024, and action was taken to isolate the affected systems and law enforcement was notified. The investigation confirmed unauthorized access to its network and files containing patient and employee data may have been viewed or exfiltrated in the attack. The file review confirmed that the types of patient data involved varied from individual to individual and may have included names combined with one or more of the following: address, date of birth, Social Security number, driver’s license number, medical record number, diagnoses, lab results, medications, treatment information, health insurance information, provider names, dates of treatment, and/or financial information. Current and former employees had data exposed related to their employment. The Center for Vein Restoration has implemented additional safeguards and technical security...

Read More
Kaye-Smith Settles Class Action Data Breach Lawsuit for $2 Million
Dec11

Kaye-Smith Settles Class Action Data Breach Lawsuit for $2 Million

The marketing company and mailing vendor, Kaye-Smith Enterprises, has agreed to settle a class action lawsuit filed in response to a 2022 cyberattack and data breach. Hackers gained access to its systems, used ransomware to encrypt files, and potentially exfiltrated sensitive data. Several healthcare providers were affected by the incident, including MultiCare Health System, St. Luke’s Health System, UW Medicine, Delta Dental of Washington, Geisinger Health System and Seattle Children’s Hospital. Several class action lawsuits were filed in response to the breach, which were consolidated into a single action – Smith, et al. v. Kaye-Smith Enterprises Inc.- in the U.S. District Court of Oregon. The plaintiffs asserted a variety of claims related to the failure to protect sensitive data. Kaye-Smith maintains there was no wrongdoing; however, the decision was taken to settle the lawsuit to avoid further legal costs and the uncertainty of trial. The $2 million settlement includes benefits for consumers whose personal and protected health information was compromised in the attack...

Read More
Critical Cleo File-Transfer Flaw Under Active Exploitation; Cl0p Claims Responsibility
Dec11

Critical Cleo File-Transfer Flaw Under Active Exploitation; Cl0p Claims Responsibility

A critical flaw in Cleo file-transfer software is being actively exploited by threat actors. The vulnerability is believed to be a previously patched flaw, CVE-2024-50623, which allows unrestricted file uploads and downloads, including dangerous file types. Successful exploitation of the vulnerability can lead to remote code execution. The vulnerability affects the following Celo products: Cleo Harmony before 5.8.0.21 Cleo VLTrader before 5.8.0.21 Cleo LexiCom before 5.8.0.21 Cleo issued a patch to fix the vulnerability in October; however, the patch does not provide full protection against exploitation. Researchers at Huntress have observed mass exploitation and post-exploitation activity in patched and unpatched versions of the affected products since December 3, 2024. An analysis of the attacks allowed Huntress to develop a proof-of-concept exploit for the flaw, and while they believe threat actor activity uses the same method to exploit the flaw, they do not have full details of the vulnerability so they could not confirm whether that was the case. It is possible that threat...

Read More
OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse
Dec11

OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse

The U.S. Department of  Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged HIPAA Privacy and Security Rule violations with the Puerto Rican healthcare clearinghouse, Inmediata Health Group. The alleged HIPAA violations were discovered during an investigation of the exposure of individuals’ electronic protected health information (ePHI) via the Internet. OCR received a complaint on November 16, 2018, alleging patients’  ePHI held by Inmediata was accessible over the Internet. OCR’s investigation substantiated the allegations and determined that between May 16, 2016, and January 23, 2019, the ePHI of 1,565,338 individuals was publicly available on the Internet and had been indexed and cached by search engines. Inmediata analyzed the exposed data and determined that names, dates of birth, home addresses, Social Security numbers, claims information, diagnosis/conditions, and other treatment information had been exposed online. OCR determined that the exposure of ePHI violated the HIPAA Privacy Rule, and HIPAA Security Rule violations were...

Read More
HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability
Dec10

HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability

A New York healthcare provider that experienced a breach of the personal and protected health information of 242,641 New Yorkers has been ordered to pay a financial penalty of $550,000 and take steps to strengthen its data security practices. HealthAlliance serves patients in Ulster and Delaware counties in New York State and operates HealthAlliance Hospital in Kingston, Margaretville Hospital in Margaretville, and Mountainside Residential Care Center in Margaretville. In July 2023, HealthAlliance was notified by its vendor, Citrix, that three vulnerabilities had been identified in its NetScaler networking products, including the critical zero-day vulnerability CVE-2023-3519 that affected two of the NetScaler products deployed on the HealthAlliance network. The cybersecurity advisory explained that threat actors were actively exploiting the vulnerability to deploy a web shell, that gave them remote access to victims’ networks. HealthAlliance attempted to patch the vulnerabilities but was unable to install the patch for the CVE-2023-3519 due to technical issues. HealthAllinace...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist