NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Rhysida Ransomware Group Claims Responsibility for AXIS Health System Attack
Oct16

Rhysida Ransomware Group Claims Responsibility for AXIS Health System Attack

AXIS Health System, a Colorado-based network of behavioral health facilities, has confirmed via its website that it has experienced a cyber incident. Few details have been released about the nature of the attack other than its incident response protocol has been initiated and an investigation is underway to determine the nature and scope of the incident. “If it is determined that patient data was impacted, affected individuals will be notified directly by mail,” explained AXIS Health in its website notice. Patient data does appear to have been stolen in the attack, according to the Rhysida ransomware group. Rhysida is a ransomware-as-a-service group that is known to attack healthcare organizations. An H1 2024 analysis by Barracuda Networks indicates that Rhysida was behind 8% of known ransomware attacks, between August 2023 and July 2024, and 38% of the group’s victims were healthcare organizations.  Recent attacks include BayHealth Healthcare System in Delaware, Community Care Alliance in Rhode Island, Ann & Robert H. Lurie Children’s Hospital in Chicago, and Prospect Medical...

Read More
Gryphon Healthcare Notifies 400,000 Patients About Recent Cyberattack
Oct16

Gryphon Healthcare Notifies 400,000 Patients About Recent Cyberattack

Gryphon Healthcare has recently confirmed a security incident involving unauthorized access to files containing the protected health information (PHI) of almost 400,000 individuals. Gryphon Healthcare is a Houston, TX-based provider of revenue cycle, coding, compliance, consultancy, and management services to healthcare providers such as hospitals, EMS providers, emergency departments, independent labs, medical imaging centers, ambulatory surgery centers, and physician practices. The security incident occurred at a partner for whom Gryphon Healthcare provides medical billing services. Gryphon Healthcare learned about the third-party incident on August 13, 2024, and following a comprehensive review of the affected files determined that the PHI of 393,358 patients of its healthcare clients had been exposed and potentially obtained by an unauthorized individual. Further information on the nature of the attack, such as whether ransomware was involved, was not disclosed. It is also unclear how many of its healthcare provider clients were affected. The file review was completed on...

Read More
Threat Actors Actively Exploiting Critical Fortinet; Veeam Backup & Replication Vulnerabilities
Oct15

Threat Actors Actively Exploiting Critical Fortinet; Veeam Backup & Replication Vulnerabilities

Ransomware actors have been observed exploiting a critical vulnerability in Veeam Backup & Replication, a data protection and recovery solution for virtual, physical, network-attached storage, and cloud-native environments. The deserialization of untrusted data vulnerability – CVE-2024-40711 – can lead to remote code execution and has a CVSS severity score of 9.8. According to Sophos, ransomware groups have been observed using compromised VPN credentials to access VPN gateways without multifactor authentication enabled, and then exploiting CVE-2024-40711 to create new local administrator accounts to deploy Akira and Fog ransomware. Sophos has tracked several attacks in the past month that exploited the vulnerability. While ransomware deployment was not always successful, in one of the attacks the threat actor successfully dropped Frog ransomware on an unprotected Hyper-V server and used rclone to exfiltrate data. The vulnerability affects Veeam Backup & Replication version 12.1.2.172, and potentially also unsupported versions. Veeam released a patch to fix the...

Read More
CISA Warns F5 BIG-IP Users About Abuse of Unencrypted Cookies
Oct15

CISA Warns F5 BIG-IP Users About Abuse of Unencrypted Cookies

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to F5 BIG-IP users that threat actors are abusing unencrypted persistence F5 BIG-IP cookies to map internal servers and identify potentially vulnerable devices on the network that can be attacked. F5 BIG-IP is a widely used suite of hardware and software solutions for managing and securing network traffic. One of the core modules is the Local Traffic Manager (LTM), which is used to manage traffic and spread it across different servers to optimize load-balanced server resources and ensure high availability. To maintain session consistency, the LTM module uses persistence cookies to ensure traffic from specific clients is delivered to the same server each time. According to CISA, threat actors have been observed leveraging the unencrypted persistence cookies that are managed by the LTM module during the planning stage of a cyberattack to enumerate other non-internet-facing devices on the network. The information gathered from the cookies, which can include IP addresses, port numbers, and load...

Read More
New York Implements New Cybersecurity Regulations For General Hospitals
Oct15

New York Implements New Cybersecurity Regulations For General Hospitals

On October 2, 2024, New York implemented new legislation that requires “general hospitals” in the state of New York to implement a raft of cybersecurity measures. Prior to the implementation of the new law, there were no state cybersecurity regulations for hospitals regarding the safeguarding of patients’ protected health information (PHI) and personally identifying information (PII), only the minimum standards of the federal Health Insurance Portability and Accountability Act (HIPAA). Under state law, general hospitals are classed as healthcare institutions that “provide medical or medical and surgical services primarily to in-patients by or under the supervision of a physician on a twenty-four-hour basis with provisions for admission or treatment of people in need of emergency care.” Currently, there are more than 190 general hospitals in the state of New York that are required to comply with the new cybersecurity requirements. The new law does not apply to diagnostic centers, treatment centers, outpatient care facilities, nursing homes, public health centers, or...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist