25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Critical SolarWinds Web Help Desk Vulnerability Under Active Exploitation
Aug18

Critical SolarWinds Web Help Desk Vulnerability Under Active Exploitation

A critical vulnerability in SolarWinds Web Help Desk is being actively exploited by threat actors. Web Health Desk is a widely used application to help with IT management and help desk ticketing, and is extensively used by businesses of all sizes, including healthcare organizations. The vulnerability affects Web Help Desk versions 12.8.3 and earlier, and is tracked as CVE-2024-28986. SolarWinds said the issue is a Java deserialization vulnerability that can potentially be exploited by an unauthenticated remote attacker to execute arbitrary commands on a host machine. The vulnerability has been assigned a CVSS severity score of 9.8 out of 10. While the vulnerability was reported as an unauthenticated flaw, SolarWinds has conducted extensive testing and has not been able to exploit the flaw without prior authentication. SolarWinds issued a hotfix on Wednesday, and users are strongly advised to apply the hotfix to prevent exploitation, especially now that the vulnerability is being targeted by threat actors. SolarWinds has released instructions for applying the hotfix, which includes...

Read More
What is Patient Compliance in Healthcare?
Aug16

What is Patient Compliance in Healthcare?

Patient compliance in healthcare is generally considered to be the degree to which patients follow the instructions of their healthcare providers with regards to medical advice, prescribed treatments, and recommended lifestyle changes. However, when discussing patient compliance in healthcare, it is important to distinguish between compliance, adherence, and concordance. To best understand what patient compliance in healthcare is, it is necessary to understand the distinction between “compliance” (how well a patient passively follows their healthcare provider’s instructions), “adherence” (how well a patient actively follows their healthcare provider’s instructions), and “concordance” (how much the patient is involved in the decision-making progress). This distinction is important because patients that are more involved in the decision-making process are more likely to comply with the decisions made about their health. Conversely, patients that passively follow instructions without understanding why, are more likely to stop taking medications and abandon attempted lifestyle changes...

Read More
NIST Releases Finalized Post-Quantum Encryption Standards
Aug16

NIST Releases Finalized Post-Quantum Encryption Standards

The National Institute of Standards and Technology has released three new encryption standards that have been developed to resist decryption via quantum computing. Current public-key encryption systems render data unintelligible and are widely used to secure communications and transactions to prevent unauthorized access to data. These encryption methods rely on math problems that even today’s most powerful supercomputers cannot defeat. That could all change, however, with quantum computers. Data encrypted today using the most powerful encryption algorithms could be stolen and decrypted at a later date when quantum computers become readily available. Quantum computers are still in the early stages of development; however, researchers have created a processor comprised of fast, high-fidelity quantum logic gates, which in benchmark testing, performed a computation in 200 seconds that it would currently take the world’s fastest supercomputer 10,000 years to product a similar output. Quantum computers pose a significant threat to encryption systems, hence the need for new...

Read More
Acadian Ambulance Facing Multiple Class Action Lawsuits Over Data Breach
Aug16

Acadian Ambulance Facing Multiple Class Action Lawsuits Over Data Breach

Several class action lawsuits have been filed against Acadian Ambulance over a recent ransomware attack and data breach that may have affected up to 10 million individuals. At the time of publication, the breach has yet to be reported to the HHS’ Office for Civil Rights, so it is unclear exactly how many individuals have been affected. The threat group behind the attack, Daixin Team, claimed to have stolen 11 million lines of data, including 10 million unique records. The group said the stolen data includes names, dates of birth, phone numbers, medical histories, case histories, employment information, symptoms, suspected drug use, as well as employee information. Acadian Ambulance has confirmed the attack, and while the total number of affected individuals has yet to be determined, Acadian Ambulance says it is much lower than the attackers allege. Acadian Ambulance is a Lafayette, LA-based private ambulance service that operates in Louisiana, Texas, Tennessee, and Mississippi. At least six lawsuits have now been filed in the U.S. District Court for the Western District of...

Read More
Alabama Cardiovascular Group Cyberattack Affects 280,500 Individuals
Aug16

Alabama Cardiovascular Group Cyberattack Affects 280,500 Individuals

Alabama Cardiovascular Group, Gastrointestinal Medicine Associates & United Urology Group have recently reported data breaches involving the protected health information of at least 323,573 individuals. RansomHub claims to have stolen data from the Neurological Spine Institute of Savannah in Georgia. Alabama Cardiovascular Group Alabama Cardiovascular Group (ACG) has discovered unauthorized individuals accessed its computer network over the space of a month between June 6, 2024, and July 2, 2024, and during that time, exfiltrated files containing sensitive data. The intrusion was detected on July 2, 2024, and immediate steps were taken to prevent further unauthorized access to the network. The cyberattack has been reported to law enforcement and the HHS’ Office for Civil Rights (OCR). The OCR breach portal indicates up to 280,534 individuals have been affected, including current and former patients, guarantors, employees, and physicians. Those individuals have been notified by mail and offered 24 months of complimentary access to Experian’s IdentityWorks identity theft...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist