25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Feds Sound Alarm About RansomHub Ransomware Group
Aug30

Feds Sound Alarm About RansomHub Ransomware Group

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Department of Health and Human Services (HHS) have issued a joint cybersecurity advisory about the RansomHub ransomware group. RansomHub is a relatively new ransomware-as-a-service (RaaS) group that emerged in February 2024. While the group was not directly involved with the ransomware attack on Change Healthcare, the group allegedly acquired the stolen data and issued a ransomware demand to Change Healthcare to prevent the release of the stolen data. Since February, RansomHub has conducted at least 210 attacks, exfiltrating data and demanding ransom payments to prevent the stolen data from being uploaded to its data leak site. While the group’s primary goal is to exfiltrate sensitive data for extortion purposes, the group possesses ransomware and often encrypts files. RansomHub has attacked organizations in multiple sectors including water and wastewater, IT, government services and facilities, food and...

Read More
Healthcare Cybersecurity Act Introduced in House of Representatives
Aug30

Healthcare Cybersecurity Act Introduced in House of Representatives

The bipartisan Senate bill, the Healthcare Cybersecurity Act, which was introduced following the ransomware attack on Change Healthcare, now has a companion bill in the House of Representatives. The Senate Healthcare Cybersecurity Act was introduced by Senators Jacky Rosen (D-NV), Todd Young (R-IN), and Angus King (I-ME) in July 2024, and the companion bill was introduced in the House by Representatives Jason Crow (D-CO), Brian Fitzpatrick (R-PA), and Andy Kim (D-NJ). The healthcare industry is increasingly being attacked by malicious actors who attempt to steal sensitive patient data to sell to cybercriminals or hold to ransom. According to an HHS Office for Civil Rights (OCR) 2022 report, cyber healthcare data breaches increased by 93% from 2018 to 2022 and large data breaches increased by 107% over that period. The OCR data breach portal shows there were 744 healthcare data breaches of 500 or more records in 2023 and more than 160 million healthcare records were breached. From January 1, 2024, to July 31, 2024, 466 large healthcare data breaches have been reported to OCR...

Read More
Florida Department of Health Notifies Individuals Affected by June 2024 Cyberattack
Aug30

Florida Department of Health Notifies Individuals Affected by June 2024 Cyberattack

The Florida Department of Health has started notifying the individuals affected by its June 2024 cyberattack and has confirmed that the attack was detected on June 26, 2023, and involved the exfiltration of sensitive data from a limited number of its systems. A forensic investigation was launched into the attack which confirmed that the unauthorized activity occurred on June 26, 2024. The affected files have been reviewed and it has been confirmed that the stolen data included names, dates of birth, addresses, Social Security Numbers, banking information, credit card information, driver’s license numbers, passport numbers, military identification numbers, Nexus numbers, medical and dental histories, medication/prescription information, provider/doctor/care coordinator names, insurance claim information, insurance coverage information, and passwords. The types of data involved varied from individual to individual and the notifications state the exact types of information involved for each individual. The Department of Health said the affected networks were immediately shut down when...

Read More
Iranian Espionage Group Providing Network Access to Ransomware Groups
Aug29

Iranian Espionage Group Providing Network Access to Ransomware Groups

An Iranian hacking group has been collaborating with ransomware groups to extort organizations in the defense, education, finance, and healthcare sectors. The Pioneer Kitten group (aka Fox Kitten, Parisite, Rubidium, and Lemon Sandstorm) has been active since at least 2017 and is believed to be connected to the Iranian government. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Department of Defense Cyber Crime Center (DC3) have issued a joint cybersecurity advisory about the group that shares the tactics, techniques, and procedures (TTPs), Indicators of Compromise (IoCs), and recommended mitigations for hardening defenses. Pioneer Kitten has conducted a high number of computer network intrusions in the United States, with its most recent activity identified in August 2024. The group breaches defenses to gain access to organizations’ networks and then monetizes access, historically by selling domain admin credentials and full domain control privileges on cyber marketplaces and recently by working with affiliates of...

Read More
OCR Drops Appeal in AHA Tracking Technology Case
Aug29

OCR Drops Appeal in AHA Tracking Technology Case

Ten days after filing its notice to appeal a District Court ruling that vacated its tracking technology guidance, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) decided not to proceed and officially withdrew its notice of appeal. The decision by the HHS to voluntarily drop the appeal will provide HIPAA-regulated entities with clarity over the use of website tracking technologies, which can continue to be used on unauthenticated web pages without the risk of future penalties for HIPAA violations. “The American Hospital Association is pleased that the Office for Civil Rights has decided not to appeal the district court’s decision vacating the new rule adopted in its Online Tracking Technologies Bulletin,” said American Hospital Association (AHA) General Counsel, Chad Golder. “As the AHA repeatedly explained to OCR —both before and after OCR forced the AHA to file its lawsuit — this rule was a gross overreach by the federal government, imposed without any input from healthcare providers or the general public.” Golder went on to say,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist