25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Critical SonicWall Firewall Vulnerability Actively Exploited by Ransomware Actors
Sep10

Critical SonicWall Firewall Vulnerability Actively Exploited by Ransomware Actors

A critical vulnerability in SonicWall firewalls is being exploited by ransomware actors to gain initial access to victims’ networks. The vulnerability was first disclosed by SonicWall on August 22, 2024, and a patch was issued to fix the vulnerability. SonicWall issued an update to its advisory on September 6, 2024, urging customers to upgrade to the latest firmware version and warning them of potential exploitation of the flaw. The improper access control vulnerability was assigned a CVSS severity score of 9.3 and affects the SonicOS management access and SSLVPN. If successfully exploited, a remote attacker can gain unauthorized resource access under specific conditions, causing the firewall to crash. According to SonicWall, the vulnerability affects SonicWall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. In the September 6, 2024, update, SonicWall confirmed that the SSLVPN feature of its firewalls was also affected. On September 6, 2024, the same day that SonicWall issued its update, Arctic Wolf’s senior threat intelligence...

Read More
Maximum Severity Vulnerability Identified in Baxter Connex Health Portal
Sep10

Maximum Severity Vulnerability Identified in Baxter Connex Health Portal

Two vulnerabilities have been identified in the Baxter Connex Health Portal that, if exploited, could lead to the remote injection of malicious code, the shutdown of the database services, and unauthorized access, modification, and deletion of data from the database. The most serious flaw is an SQL injection vulnerability due to the improper sanitization of values of certain parameters. The vulnerability is tracked as CVE-2024-6795 and has been assigned a maximum CVSS (v3.1) severity score of 10. The vulnerability can be exploited remotely in a low-complexity attack allowing an attacker to run arbitrary SQL queries, access, modify, and delete sensitive data, and/or perform administrative operations including shutting down the database. The second issue is a high-severity improper access control vulnerability – CVE-2024-6796 – that can be exploited to access sensitive patient and clinician information and could also allow the modification or deletion of clinic details. The vulnerability has been assigned a CVSS score of 8.2. Both vulnerabilities were reported to the U.S....

Read More
St. Croix Regional Medical Center Settles Lawsuit Alleging Overcharging for Medical Records
Sep09

St. Croix Regional Medical Center Settles Lawsuit Alleging Overcharging for Medical Records

Wisconsin-based St. Croix Regional Medical Center has proposed a $225,000 settlement to resolve a lawsuit filed by individuals who alleged the medical center charged them excessive fees for exercising their right to obtain a copy of their health records, above what is permitted under Wisconsin law. According to the lawsuit – Stadler v. St. Croix Regional Medical Center Inc. – patients and persons authorized by patients to obtain a copy of their health records (e.g. attorneys) were overcharged for the requested records. St. Croix Regional Medical Center denied any wrongdoing or liability; however, counsel for the plaintiff and defendant determined that there was a significant risk of continuing the litigation, so the decision was taken to settle the lawsuit. Under the terms of the settlement, any patient who directly or indirectly paid a request, basic, retrieval, certification, or other fee in violation of Wis. Stat. §146.83(3f)(b)(4)-(5) is permitted to submit a claim for compensation of up to 1.5 times the amount of the disputed fees. A person authorized by a patient...

Read More
Researcher Identifies Exposed Database Containing Mental Health and Substance Abuse Treatment Information
Sep06

Researcher Identifies Exposed Database Containing Mental Health and Substance Abuse Treatment Information

A cybersecurity researcher has found an exposed healthcare database containing mental health and substance abuse treatment records that could be accessed via the Internet without a password. Researcher Jeremiah Fowler traced the database to Confidant Health, an Austin, TX-based company that has an AI-powered platform that connects individuals with therapists, psychiatrists, and providers of addiction treatment services. The company serves individuals in the states of Connecticut, Florida, New Hampshire, Texas, and Virginia. Fowler identified around 126,000 files and 1.7 million logging records, which included sensitive personally identifiable information of patients, therapists, and healthcare professionals. The exposed information included names, addresses, driver’s license information, state IDs, Medicaid cards, prescription medications, medical record requests, drug test results, and other health information. Audio recordings of sessions and text transcripts had also been exposed. Fowler notified Confidant Health about the exposed data, was told that the incident would be...

Read More
HHS-OIG Audit South Carolina Identifies Failure to Invoice $14.2 Million for Drug Rebates
Sep06

HHS-OIG Audit South Carolina Identifies Failure to Invoice $14.2 Million for Drug Rebates

The HHS Office of Inspector General (HHS-OIG) audited the South Carolina Department of Health and Human Services, South Carolina’s Medicaid agency, to assess compliance with the Medicaid requirements for invoicing manufacturers for rebates for physician-administered drugs dispensed to MCO enrollees. For a covered outpatient drug to be eligible for federal reimbursement under the Medicaid program’s drug rebate requirements, manufacturers must pay rebates to the states for the drugs. HHS-OIG has conducted previous audits that indicate states do not always invoice and collect rebates for MCO’s enrollees. This was the latest in a series of audits to assess compliance with the Medicaid drug rebate program, which took effect in 1991. HHS-OIG reviewed physician-administered drug claims paid by the MCOs between January 1, 2016, and December 31, 2019, which totaled $168,590,761. After removing claims for drugs that were not eligible for rebates or where invoices for rebates were sent, HHS-OIG identified physician-administered drug claims totaling $45,244,489 and then worked with the state...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist