25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS-OIG and Law Enforcement Partners Tackle $2.75 Billion Healthcare Fraud Schemes
Jun28

HHS-OIG and Law Enforcement Partners Tackle $2.75 Billion Healthcare Fraud Schemes

The Department of Health and Human Services Office of Inspector General (HHS-OIG) and its law enforcement partners have tackled nationwide healthcare fraud schemes involving around $2.75 billion in intended losses and $1.6 billion in actual losses. The 2024 National Health Care Fraud Enforcement Action has resulted in criminal charges being filed against 193 defendants, including 76 doctors, nurses, and other licensed medical professionals in 32 federal districts across the country. $231 million in cash, gold, luxury vehicles, and other assets has been seized. One of the actions announced by HHS-OIG Inspector General Christi A. Grimm involved five individuals at a start-up telehealth company that claimed they diagnosed and treated attention deficit hyperactivity disorder (ADHD). The company engaged in deceptive advertising on social media networks to target patients, who were prescribed addictive drugs such as Adderall and other stimulants when they were not medically necessary. Millions of pills were prescribed through the telehealth company, Done Global Inc. and its affiliated...

Read More
Health-ISAC Issues Warning Abuse of TeamViewer Remote Connectivity Software
Jun28

Health-ISAC Issues Warning Abuse of TeamViewer Remote Connectivity Software

The Health Information Sharing and Analysis Center (Health-ISAC) has issued a warning to the healthcare and public health sector about cyber threat actors exploiting TeamViewer remote connectivity software. TeamViewer provides remote access and remote control of devices and is commonly used for remote IT support and maintenance. Health-ISAC has received intelligence from a trusted source that a threat actor tracked as APT29, aka Cozy Bear/Midnight Blizzard, has compromised TeamViewer, and threat actors associated with APT29 are abusing TeamViewer. APT29 is a threat group that has been in operation since at least 2008 and is a Russian hacking group associated with Russia’s intelligence agencies, the Federal Security Service (FSB) and Foreign Intelligence Service (SVR). The United States believes APT29 is led by the SVR. On Thursday, TeamViewer issued a statement confirming it had detected an irregularity in its internal network on June 26, 2024. According to its security update, “A comprehensive taskforce consisting of TeamViewer’s security team together with globally leading cyber...

Read More
January 2024 Cyberattack on Lurie Children’s Hospital Affects 792K Individuals
Jun28

January 2024 Cyberattack on Lurie Children’s Hospital Affects 792K Individuals

On January 31, 2024, Ann & Robert H. Lurie Children’s Hospital of Chicago fell victim to a cyberattack that forced IT systems offline, including its Epic electronic health record systems and its MyChart patient portal. Staff were forced to work under downtime procedures and record patient information manually while its EHR was offline. It took until May 20, 2024, to restore access, and then the lengthy process of transferring all manually recorded data to the EHR commenced. Lurie Children’s said it has taken a considerable amount of time to investigate the incident and restore its systems due to the sophistication of the attack and the complexity of its IT infrastructure. The forensic investigation confirmed that an unauthorized, unnamed third party had access to its systems from January 26, 2024, to January 31, 2024. Lurie Children’s confirmed that the hackers were able to access patient data during those 5 days. “Through our ongoing investigation, Lurie Children’s has determined that certain individuals’ personally identifiable and/or protected health information was...

Read More
OSHA Offers $12.7M in Grants to Support Employee Safety, Health Training & Education
Jun28

OSHA Offers $12.7M in Grants to Support Employee Safety, Health Training & Education

The Occupational Safety and Health Administration (OSHA) is offering $12.7 million in training grants to help create safer workplaces. The grants are administered under OSHA’s Susan Harwood Training Grant Program to support employee safety, health training, and education. The grants are awarded to provide training and education programs for employers and workers on the recognition, avoidance, and prevention of safety and health hazards in their workplaces, and to ensure that workers are aware of their rights under the Occupational Safety and Health (OSH) Act and the responsibilities of their employers to create a safe workplace. The grants are intended to advance job quality by providing instructor-led training for workers, supervisors, and employers in small businesses, industries with high injury, illness, and fatality rates, and vulnerable, underserved workers, such as seasonal workers who often have limited English proficiency. There are three categories of grants available: Targeted Topic Training: To identify and prevent OSHA-designated workplace safety and health hazards....

Read More
Vulnerabilities Identified in Sensor Net Connect and Thermoscan IP Temperature Control Devices and Software
Jun27

Vulnerabilities Identified in Sensor Net Connect and Thermoscan IP Temperature Control Devices and Software

Multiple vulnerabilities have been identified in Proges Plus temperature monitoring devices and their associated software. The vulnerabilities affect the Sensor Net Connect temperature sensor device from the Pregres Plus-owned Plug&Track and the associated Thermoscan IP desktop application.  The devices are used by pharmaceutical companies and hospitals for drug storage, where temperature needs to be carefully controlled. The vulnerabilities were identified by researchers at Nozomi Network Labs, who tried to report the flaws to Proges Plus but never received a response. No patches have been released to fix the flaws at present and it is unclear when the vulnerabilities will be fixed. Nozomi Network Labs has disclosed limited details about the flaws to advise users of the devices and software about the risks, along with recommended mitigations to prevent exploitation of the flaws. In total, 7 vulnerabilities were identified, four of which are in Sensor Net Connect and three are in Thermoscan IP, some of which can be chained to maximize the impact. The Sensor Net Connect...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist