25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Active Ransomware Groups Increase by 57% as Ransomware Landscape Fragments
Sep04

Active Ransomware Groups Increase by 57% as Ransomware Landscape Fragments

There has been a significant increase in the number of ransomware groups conducting attacks, according to Searchlight Cyber. In H1, 2023, Searchlight Cyber identified 46 active ransomware groups from posts to dark web data leak sites, with the number of active groups increasing by 57% in H1, 2024 to 72 active groups. In the first half of 2024, 2,879 organizations have been added to ransomware groups’ data leak sites, which is a 50% increase from H1, 2023, although a 16% decrease from H2, 2023. It is important to note that there was an increase in attacks in the second half of 2023 when the number of victims added to ransomware groups’ data leak sites was at the highest level since ransomware groups started adopting data theft and leak tactics in addition to file encryption. There has been some fluctuation in the most prolific ransomware groups in the first half of the year. LockBit has retained its position as the most active ransomware group, despite efforts by law enforcement to disrupt its operation. At least 434 victims were added to the LockBit data leak site in H1, 2024,...

Read More
Data Breaches Reported by Three Californian Healthcare Providers
Sep04

Data Breaches Reported by Three Californian Healthcare Providers

Data breaches have recently been reported by Californian healthcare providers Vasinda’s Around the Clock Care, Baker Places, Turning Point of Central California, and Watson Clinic in Florida. Vasinda’s Around the Clock Care / ATC Home Care, California Vasinda’s Around the Clock Care Inc., doing business as ATC Home Care in California, has notified 3,785 individuals about a computer intrusion detected on June 18, 2024. The forensic investigation revealed an unauthorized individual had access to its network for almost 5 months. Its network was first compromised on January 30, 2024, and access remained possible until June 18, 2024. During that time, files were copied from its systems that contained sensitive patient information. The file review confirmed names had been compromised along with addresses, Social Security numbers, health insurance information, billing and claims information, and medical information such as diagnoses, lab results, medications, and other treatment information. The affected individuals were patients or clients of ATC or clients of the payee...

Read More
Security Camera Vendor Fined $2.95 Million for Alleged Violations of FTC Act and CAN-SPAM Act
Sep03

Security Camera Vendor Fined $2.95 Million for Alleged Violations of FTC Act and CAN-SPAM Act

The Federal Trade Commission (FTC) has proposed a $2.95 million financial penalty for the Californian security camera vendor Verkada to resolve allegations the company violated the FTC Act by failing to implement appropriate information security practices and violated the CAN-SPAM Act by bombarding customers with emails without providing a way to unsubscribe. Verkada’s IP-enabled security cameras provide live video feeds and record and store video footage in Amazon Web Services (AWS) storage. The cameras are used in many sensitive locations, including psychiatric hospitals, women’s health clinics, prisons, and schools. Verkada claimed it takes data security and customer privacy seriously and said the company uses best-in-class security tools and best practices to ensure that customer data is kept safe and is prevented from unauthorized access. The FTC alleged that appropriate security measures had not been implemented. For example, the company did not require unique and complex passwords, had not implemented secure network controls, and did not adequately encrypt customer data....

Read More
What is the Administrative Simplification Compliance Act?
Sep03

What is the Administrative Simplification Compliance Act?

The Administrative Simplification Compliance Act is an Act passed in 2001 that requires healthcare providers and medical equipment suppliers to submit claims for payment to Medicare electronically. Noncompliance with the requirement will result in nonpayment and possible exclusion from Medicare unless an exemption applies or the requirement is waived. When Congress passed HIPAA in 1996, one of the changes the Act made to the Public Health and Welfare Code was the “General Requirements for the Adoption of Standards”. The General Requirements led to the publication of the Administrative Simplification Regulations which include the HIPAA Transaction Standards (Part 162), the HIPAA Privacy Rule, and the HIPAA Security Rule. When the first HIPAA Transaction Standards were published in October 2000, the implication was that healthcare providers and medical equipment suppliers only had to apply the standards when submitting electronic claims to Medicare. Indeed, in the preamble to the Part 162 Final Rule, HHS denies any intention to introduce a rumored $1 user fee for each claim submitted...

Read More
CISA Launches New Cyber Incident Reporting Portal
Sep02

CISA Launches New Cyber Incident Reporting Portal

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new portal to make it easier for organizations to report cyber incidents and data breaches. Use of the portal is voluntary but strongly recommended, as the reporting of cyber incidents benefits the reporting entity as well as the broader community. Cyberattacks can be hugely disruptive for the breached entity; however, CISA and its government partners may be able to offer assistance, as they have unique resources and tools available to help with response and recovery. Prompt reporting will ensure that those resources can be made available when they are needed. “An organization experiencing a cyberattack or incident should report it — for its own benefit, and to help the broader community,” said Jeff Greene, executive assistant director for cybersecurity, CISA. “CISA and our government partners have unique resources and tools to aid with response and recovery, but we can’t help if we don’t know about an incident.” When a threat actor conducts a successful attack, the tactics, techniques, and procedures...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist