NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics
Oct17

Iranian Threat Actors Targeting Critical Infrastructure Entities Using Brute Force Tactics

Healthcare and public health (HPH) and other critical infrastructure sectors have been warned that Iranian cyber actors are using brute force tactics for initial access in targeted attacks on critical infrastructure entities in the United States. The cybersecurity advisory was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Communications Security Establishment Canada (CSE), the Australian Federal Police (AFP), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC). Since October 2023, the authoring agencies have observed Iranian cyber actors using brute force tactics such as password spraying and multifactor authentication (MFA) push bombing to obtain credentials and information that allows them to move deep into networks, obtain additional credentials, escalate privileges, and achieve persistence. Password spraying is the use of commonly used and default passwords to attempt access to accounts and in the case of the Iranian cyber actors, Microsoft 365, Azure, and Citrix...

Read More
Email Account Breaches Reported by 5 HIPAA-Regulated Entities
Oct17

Email Account Breaches Reported by 5 HIPAA-Regulated Entities

Email is the second most common location for breached healthcare information behind network servers. Over the past few days, five HIPAA-regulated entities have reported breaches of HIPAA email rules and the exposure of patient data. Hafetz and Associates, New Jersey Hafetz and Associates, a Linwood, NJ-based independent insurance agency, has confirmed that employee email accounts were compromised in a recent phishing attack. Immediate action was taken on October 12, 2024, to secure its email accounts when unauthorized activity was detected, and an investigation was launched to determine the extent of the security breach. Hafetz and Associates confirmed that several employee email accounts had been accessed by an unauthorized third party at various points between July 24, 2023, and October 12, 2023. The review of the accounts confirmed that they contained information such as names, dates of birth, Social Security numbers, and/or benefits election information. The data analysis involved checking all emails and attachments in the affected accounts, identifying exposed protected health...

Read More
Is GoDaddy HIPAA Compliant?
Oct16

Is GoDaddy HIPAA Compliant?

GoDaddy is not HIPAA compliant for its web hosting services, however organizations that subscribe to a Business Professional or a Premium Security Microsoft 365 account through GoDaddy can take advantage of a HIPAA compliant email service that allows them to send and receive emails containing Protected Health Information using their domain name. GoDaddy is a domain name registrar and web hosting company that provides tools to help build and promote websites, host marketplaces, and collect payments. The company also offers advanced security features to protect websites from malicious bots, brute force hacks, and DDoS attacks. Other add-ons perform updates for plugins, backups, and search engine optimization. Despite its advanced security features, and the option to host websites on dedicated servers, GoDaddy does not support HIPAA compliance for its web hosting services. This is because GoDaddy leases most of its data centers and is not responsible for their physical security. Therefore, GoDaddy is unable to comply with the physical safeguards of the HIPAA Security Rule. What this...

Read More
Q3 Sees 8% Fall in Data Compromises; 77% Reduction in Victims
Oct16

Q3 Sees 8% Fall in Data Compromises; 77% Reduction in Victims

This year was on track to set a new record for data compromise incidents; however, there has been some good news – data compromises are down 8% from Q2, 2024, according to the latest data from the Identity Theft Resource Center (ITRC). In Q3, 2024, there were 672 publicly reported data compromises, which bring the running total for the year to 2,242 data compromise incidents – 70% of the total for all of 2023. That makes it unlikely that 2024 will set a new record for data compromises, although ITRC predicts that the annual compromise rate will be only slightly below last year’s record. The number of individuals affected by data compromise incidents in Q3, 2024 fell by 77% from the previous quarter, with 241,889,316 individuals confirmed as having their personal data compromised. Out of the 672 known compromises, 615 were data breaches affecting a total of 141,022,573 individuals and 6 were data exposure incidents involving the data of more than 100 million individuals. The latter includes a misconfiguration at the data broker MC2 Data, which primarily supplies data for...

Read More
Data Breaches Confirmed by Tri-City Healthcare District; TheraCom
Oct16

Data Breaches Confirmed by Tri-City Healthcare District; TheraCom

Tri-City Healthcare District, which includes Tri-City Medical Center in Oceanside, California, has recently informed the Maine Attorney General about a data breach affecting 108,149 individuals, including 14 Maine residents. Individual notifications were mailed to the affected individuals on October 11, 2024, informing them that unauthorized access to its computer network was identified on November 9, 2023. The forensic investigation confirmed that an unknown third party accessed files on its network on November 8, 2023, and retained access to its network until the following day when the intrusion was detected and blocked. The review of the affected files was completed on September 27, 2024, and confirmed that the files contained information such as names, addresses, dates of birth, Social Security numbers, medical treatment/diagnosis information, dates of service, health insurance provider names, health insurance claim information, and/or treatment costs. No evidence has been found to indicate any misuse of patient data; however, as a precaution, the affected individuals have been...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist