25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS-OIG Audit Suggests 1 in 4 Nursing Homes Are Not Compliant with Infection Preventionist Requirements
Aug28

HHS-OIG Audit Suggests 1 in 4 Nursing Homes Are Not Compliant with Infection Preventionist Requirements

An audit by the HHS Office of Inspector General (HHS-OIG) indicates more than one-quarter of nursing homes either did not designate an infection preventionist (IP) or designated an IP who had not been completely trained for the position. Due to the high number of healthcare-associated infections in nursing homes, the significant exposure to infections, and the increased susceptibility of nursing home residents to infections, the HHS Centers for Medicare & Medicaid Services (CMS) issued a final rule in October 2016 stating that infection control is a critical issue. The final rule required nursing homes to establish and maintain an infection prevention and control program (ICIP) that ensures a safe, sanitary, and comfortable environment and to strictly adhere to federal requirements for proper infection prevention and control practices. Infection prevention and control regulations include the requirement to designate an infection preventionist (IP) and for that individual to meet federal requirements for that position. HHS-OIG has conducted previous audits of nursing homes and...

Read More
Ransomware Attack on Software Vendor Involved Medical Insurance Information of 954K Individuals
Aug28

Ransomware Attack on Software Vendor Involved Medical Insurance Information of 954K Individuals

Young Consulting (Connexure), an Atlanta, GA-based vendor that provides software solutions to the employer stop loss marketplace, has fallen victim to a BlackSuit ransomware attack that involved the medical insurance information of 954,177 individuals. The software provided by Young Consulting helps carriers, brokers, and third-party administrators market, underwrite, and administer stop-loss insurance. Stop-loss insurance protects against unexpected losses and is often purchased by businesses and organizations that self-fund their employee benefits plans but do not want to be 100% liable for any losses. Young Consulting started experiencing “technical difficulties” on April 13, 2024. A cybersecurity forensics firm was engaged to assist with the investigation and determine the nature and scope of the incident. The forensic investigation confirmed there had been unauthorized access to its network between April 10, 2024, and April 13, 2024, and during that time, certain files were downloaded from its network. The review of those files is ongoing; however, it has been confirmed that...

Read More
$460 Million Paid to Ransomware Groups in H1, 2024
Aug27

$460 Million Paid to Ransomware Groups in H1, 2024

Several ransomware reports have been released in the past few weeks that shed light on the extent to which ransomware is being used in cyberattacks, the profitability of the attacks, and the tactics involved. What these reports make clear is there is no sign of ransomware groups abandoning ransomware, even with significant law enforcement operations and arrests. Almost $460 Million Paid to Ransomware Groups in H1 2024 A recent report from the blockchain analysis firm Chainalysis has revealed ransomware victims have paid $459,800,000 to ransomware groups in the first half of 2024, a 2% increase from 2023’s record-breaking ransom payment total of $449,100,000 in H1, 2023. If payments continue in the second half of 2024 at the same level, last year’s record total of $1.1 billion in ransom payments will be broken. Chainalysis has identified a change in tactics at some ransomware groups, which appear to be targeting large organizations more frequently. Large organizations typically have more robust cybersecurity measures than smaller businesses as well as in-house security teams that...

Read More
Email Breach Reported by The Facial Pain Center
Aug27

Email Breach Reported by The Facial Pain Center

The Facial Pain Center in Minnesota has revealed several employee email accounts were accessed by an unauthorized individual in January 2024, exposing the protected health information of 1,894 individuals. Suspicious activity was identified in certain employee email accounts on January 23, 2024. Immediate action was taken to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. A third-party cybersecurity company assisted with the investigation and confirmed that the threat actor had access to emails and related file shares, although the extent to which patient data was accessed and/or copied is not known. Due to the amount of data and number of email accounts involved it has taken several months to complete the review. That process was completed on June 10, 2024. The types of data involved varied from individual to individual and may have included names along with one or more of the following: date of birth, demographic information, medical information, and/or health insurance information. The Facial Pain Center...

Read More
Data Breaches Reported by Medical Center Barbour; Monte Nido; Allergy Medical Group of the North Area
Aug26

Data Breaches Reported by Medical Center Barbour; Monte Nido; Allergy Medical Group of the North Area

Medical Center Barbour in Alabama, Allergy Medical Group of the North Area in California, and the nationwide eating disorder treatment provider Monte Nido have reported cyberattacks involving unauthorized access to patient data. Medical Center Barbour, Alabama Medical Center Barbour in Eufaula, AL, reported a breach of the personal information of 61,014 individuals to the Maine Attorney General and notified the affected individuals on August 22, 2024. Suspicious activity was identified within its network on October 29, 2023, and cybersecurity specialists were engaged to investigate the incident. The investigation concluded on December 8, 2023, and confirmed that an unauthorized third party had accessed files and data stored on its network and may have exfiltrated data. While the investigation was completed relatively quickly, it took until May 21, 2024, for the medical center to complete its internal review to determine the types of data involved, then a third-party data mining company was engaged to assist with the review of the data to allow notifications to be mailed. That...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist