25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Thousands of Medical Devices and Data Systems Exposed Over the Public Internet
Oct18

Thousands of Medical Devices and Data Systems Exposed Over the Public Internet

Censys, a provider of an Internet intelligence platform for threat hunting and attack surface management, has identified thousands of IP addresses that expose medical devices and systems over the Internet, almost half of which (49%) are located in the United States. Censys security researcher Himaja Motheram explained that the research was focused on identifying publicly accessible interfaces and services from the perspective of an external threat actor looking to conduct an attack on a healthcare organization or gain access to healthcare data. The company identified 14,004 unique IPs that publicly exposed healthcare-related devices and applications on the Internet but suggests that their research likely only captured a portion of exposed devices, with many other systems likely exposed but not openly accessible. The findings of the study have been published in the Censys 2024 Global State of Internet of Healthcare Things (IoHT) Exposures on Public-Facing Networks report. The most commonly exposed medical assets were DICOM servers (5,100), which are used for viewing and transferring...

Read More
East River Medical Imaging $1.85 Million Settlement Due to Receive Final Approval
Oct18

East River Medical Imaging $1.85 Million Settlement Due to Receive Final Approval

A $1.85 million settlement to resolve a class action data breach lawsuit against the New York radiology group, East River Medical Imaging, is due to receive final approval on October 22, 2024. Individuals affected by the breach have until October 22, 2024, 2:30 PM EDT to submit a claim. A security breach was detected by East River Medical Imaging on September 20, 2023. A hacker was determined to have accessed its systems from August 31, 2023, to September 20, 2023, and during that time files were copied from its network. Patient and employee information was compromised including names, contact information, insurance information, exam and/or procedure information, referring physician names, imaging results, financial account information, driver’s license numbers, and Social Security numbers. Notification letters were sent to the affected individuals starting November 22, 2023, and the breach was reported to the HHS’ Office for Civil Rights on November 22, 2024, as affecting 605,809 individuals. The first lawsuit over the data breach was filed by the law firm Shub & Johns...

Read More
OCR Announces 50th HIPAA Right of Access Penalty
Oct18

OCR Announces 50th HIPAA Right of Access Penalty

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Rules. A civil monetary penalty of $70,000 has been imposed on the Silver Spring, MD, dental practice Gums Dental Care for failing to provide a patient with timely access to her and her children’s medical records. This is the 50th HIPAA Right of Access enforcement action to result in a financial penalty since OCR launched its HIPAA Right of Access enforcement initiative in the fall of 2019. The complainant sent a written request to Gums Dental Care on or around April 8, 2019, requesting copies of her protected health Information (PHI) and the PHI of her children. She requested the records be sent to her electronically via email and received a reply the same day confirming how many times each of them had visited the dental practice but was not provided with the requested records.  She filed a complaint with OCR on May 1, 2019, after no records had...

Read More
Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics
Oct17

Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics

Healthcare and public health (HPH) and other critical infrastructure sectors have been warned that Iranian cyber actors are using brute force tactics for initial access in targeted attacks on critical infrastructure entities in the United States. The cybersecurity advisory was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC). Since October 2023, the authoring agencies have observed Iranian cyber actors using brute force tactics such as password spraying and multifactor authentication (MFA) push bombing to obtain credentials and information that allows them to move deep into networks, obtain additional credentials, escalate privileges, and achieve persistence. Password spraying is the use of commonly used and default passwords to attempt access to accounts and in the case of the Iranian cyber actors, Microsoft 365, Azure, and Citrix...

Read More
Email Account Breaches Reported by 5 HIPAA-Regulated Entities
Oct17

Email Account Breaches Reported by 5 HIPAA-Regulated Entities

Email is the second most common location for breached healthcare information behind network servers. Over the past few days, five HIPAA-regulated entities have reported breaches of HIPAA email rules and the exposure of patient data. Hafetz and Associates, New Jersey Hafetz and Associates, a Linwood, NJ-based independent insurance agency, has confirmed that employee email accounts were compromised in a recent phishing attack. Immediate action was taken on October 12, 2024, to secure its email accounts when unauthorized activity was detected, and an investigation was launched to determine the extent of the security breach. Hafetz and Associates confirmed that several employee email accounts had been accessed by an unauthorized third party at various points between July 24, 2023, and October 12, 2023. The review of the accounts confirmed that they contained information such as names, dates of birth, Social Security numbers, and/or benefits election information. The data analysis involved checking all emails and attachments in the affected accounts, identifying exposed protected health...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist