25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New Jersey Oral & Maxillofacial Surgery Notifies 74,400 Patients About PHI Exposure
Jul26

New Jersey Oral & Maxillofacial Surgery Notifies 74,400 Patients About PHI Exposure

New Jersey Oral & Maxillofacial Surgery has confirmed that the PHI of 74,413 individuals has been exposed in a cyberattack. The Kansas Fire Department is investigating a security incident and has confirmed that sensitive data was exfiltrated from its network. New Jersey Oral & Maxillofacial Surgery Notifies Patients About April 2024 Cyberattack New Jersey Oral & Maxillofacial Surgery has notified 74,413 patients that some of their protected health information has been stolen in a cyberattack. A security incident was detected on May 14, 2024, and the investigation confirmed that there had been unauthorized access to its computer systems starting on or around April 19, 2024. The practice immediately initiated its incident response procedures and worked quickly to secure its systems to prevent further unauthorized access. The investigation confirmed that an unauthorized third party accessed the network and acquired certain files from its computer systems. The review of the exposed files confirmed that they contained patient information including names, addresses, dates of...

Read More
Survey Highlights Challenges in Healthcare with Managing Sensitive Content in Communications
Jul25

Survey Highlights Challenges in Healthcare with Managing Sensitive Content in Communications

Kiteworks (formerly Accellion, Inc.) has published the findings of a 2024 survey of professionals in the IT, security, and compliance sectors that has identified some of the challenges faced with managing sensitive content in communications. In healthcare, 53% of surveyed healthcare organizations said they used 5 or more communications tools for sharing sensitive content, comparable with other industry sectors, and while the same percentage of healthcare organizations believe they could track and control sensitive data when sent internally, only 44% shared that confidence about tracking and controlling sensitive data when sent externally. When asked about the most important privacy and compliance priorities regarding the communication of sensitive data, 61% of respondents said the prevention of leakage of confidential IP and corporate secrets. Interestingly, that ranked more important than the avoidance of regulatory violations, which was a top priority for 56% of healthcare respondents. Those figures were 56% and 48% across all industry sectors. There has been an increase in the...

Read More
Mandiant Warns of North Korean Threat Actors Targeting Healthcare
Jul25

Mandiant Warns of North Korean Threat Actors Targeting Healthcare

Mandiant has announced that the North Korean Threat group Andariel (UNC614) has been designated an Advanced Persistent Threat (APT) actor, now tracked as APT45. The threat actor is moderately sophisticated and has been operating since at least 2009, and is known to target businesses, government agencies, financial services infrastructure, private corporations, and the defense industry as part of North Korea’s cyber defensive operations, primarily targeting military and government personnel. The group is also known to engage in cybercrime to provide additional income to fund its operations, including attacks on hospitals using its own ransomware variant, MAUI. Mandiant has observed the group expanding its financially motivated activities, which they believe is to generate additional revenue to support broader cyber campaigns and potentially provide funds to the DPRK regime. The increase in attacks has led to Mandiant elevating the threat actor to an APT and warning about the significant and escalating threat posed by the group. Since the start of the pandemic, several hacking groups...

Read More
Ransomware Attacks Increased by 9% In Q2, 2024
Jul25

Ransomware Attacks Increased by 9% In Q2, 2024

New data released by Guidepoint Security shows there has been a 9% quarter-over-quarter increase in ransomware attacks, with H1, 2024 attacks up by 5% compared to H1, 2023. Ransomware attacks typically increase from Q1 to Q2, and while 2024 is no different in that respect, the percentage increase was far lower than the 37% increase in attacks between Q1 2023 and Q2 2023. The data analyzed by GuidePoint’s Research and Intelligence Team (GRIT) shows the number of active ransomware groups is growing, and those groups are attacking a much broader range of targets. The leading industries for ransomware attacks in Q2, 2024 were manufacturing, technology, and healthcare. Technology companies had the biggest increase in attacks, rising to 10% of attacks in the quarter, the highest placement for the sector since Q3, 2023. In Q2, 2024, the most active ransomware groups targeting the healthcare sector were LockBit, Bianlian, and Inc Ransom. While the increase in attacks was relatively modest, the GRIT team notes that in H1, 2024, there was an international law enforcement operation that...

Read More
Senators Respond to Overturning of the Chevron Doctrine
Jul25

Senators Respond to Overturning of the Chevron Doctrine

Senator Elizabeth Warren (D-MA) has introduced the Stop Corporate Capture Act (SCCA) in response to the recent decision of the Supreme Court to overturn the Chevron deference doctrine, which has stood for the past 40 years. Under the Chevron deference doctrine (Chevron U.S.A., Inc. v. Natural Resources Defense Council, 1984), federal courts must defer to agency interpretations of ambiguous statutes, provided their interpretation of those statutes is reasonable.  Chevron acknowledged that federal agency experts are in the best position to write rules and regulations and implement laws passed by Congress. On June 28, 2024, the U.S. Supreme Court issued a landmark decision in Loper Bright Enterprises v. Raimondo, overturning the Chevron deference doctrine in a 6-3 decision. Chief Justice John Roberts ruled that the judiciary has the sole prerogative to say what the law is, not federal agencies. The decision has implications for all regulated industries, including healthcare, and means federal agencies’ interpretation of federal laws can be challenged in court. The SCCA first was...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist