NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

California Sues Catholic Hospital for Denying an Emergency Abortion
Oct07

California Sues Catholic Hospital for Denying an Emergency Abortion

California Attorney General Rob Bonta is suing the owners of Providence St. Joseph Hospital in Eureka, CA, for denying a patient an emergency abortion, in violation of multiple state laws, including California’s Emergency Services Law, the state equivalent of the federal Emergency Medical Treatment & Labor Act (EMTALA). The lawsuit concerns the denial of emergency care to a patient whose waters broke when she was 15 weeks pregnant with twins on February 23, 2024. According to AG Bonta, the patient, Anna Nusslock, presented at the hospital and despite there being an immediate threat to her life and health, she was denied an emergency abortion even though she was severely bleeding and the pregnancy was no longer viable. A doctor at Providence St. Joseph Hospital diagnosed Nusslock with previable premature pre-labor rupture of membranes (Previable-PPROM) and confirmed that the twins would not survive. The patient was at an increased risk of permanent harm or death, and while abortion is a standard treatment for Previable-PPROM at such an early stage of the pregnancy, that...

Read More
Weiser Memorial Hospital Investigating Cyberattack
Oct07

Weiser Memorial Hospital Investigating Cyberattack

Weiser Memorial Hospital in Idaho recently experienced a cyber incident and is investigating claims that a cybercriminal group stole data in the attack. It is unclear exactly when the attack occurred. The notice about the cyberattack was added to the hospital’s Facebook page on September 5, 2024, and the post was updated on September 17, 2024, confirming that the hospital is still working on restoring full functionality to its systems. Weiser Memorial Hospital did not name the group behind the attack, but this appears to have been an attack by the Embargo ransomware group. Embargo is a relatively new ransomware-as-a-service group that emerged earlier this year. The group is known to engage in double extortion, stealing data from victims before encrypting files with ransomware. At this stage of the investigation, it is unclear to what extent patient data was involved. Weiser Memorial Hospital said it is currently researching to determine if the group’s claims are factual. If data has been stolen, notification letters will be mailed to the affected individuals. In the meantime,...

Read More
Critical Zimbra Flaw Being Mass Exploited
Oct04

Critical Zimbra Flaw Being Mass Exploited

Hackers are mass exploiting a critical command injection vulnerability to gain access to vulnerable Zimbra email servers. Successful exploitation of the flaw allows malicious code to be remotely executed on the Zimbra email server. Threat actors have been exploiting the flaw to drop and execute a webshell on the Zimbra server. Once installed, the webshell provides full access to the Zimbra server, allows the downloading and execution of additional files, and provides the required access for a more extensive network compromise. The vulnerability is tracked as CVE-2024-45519 (CVSS base score: 9.8) and affects Zimbra’s postjournal service, which parses inbound emails over SMTP. The vulnerability can be exploited by sending a specially crafted email with malicious code in the CC field. A vulnerable Zimbra server will execute the code in the CC field when the postjournal service processes the email. Exploitation of the flaw was first detected by HarfangLab researcher Ivan Kwiatkowski and has also been confirmed by Proofpoint. Proofpoint confirmed it detected exploitation of the flaw in...

Read More
Harvard Pilgrim Health Care Ransomware Attack Affected at Least 2,967,000 Individuals
Oct04

Harvard Pilgrim Health Care Ransomware Attack Affected at Least 2,967,000 Individuals

Harvard Pilgrim Health Care has issued an updated notification to the Maine Attorney General about its April 2023 ransomware attack, increasing the total number of affected individuals by 106,601 to 2,967,396 individuals. In the notification, Harvard Pilgrim Health Care said the investigation into the data breach is still ongoing, so that may not be the final total. Harvard Pilgrim Health Care said the investigation uncovered evidence that a significant amount of data was copied from its systems between March 28, 2023, and April 17, 2023, which included personal and protected health information. The data stolen in the attack is known to have included names, physical addresses, phone numbers, dates of birth, health insurance account information, Social Security numbers, and clinical information such as medical histories, diagnoses, treatment information, dates of service, and provider names. A limited number of the affected individuals also had their financial account information stolen. Harvard Pilgrim Health Care has been issuing notifications on a rolling basis to individuals...

Read More
OCR Imposes $240,000 HIPAA Fine on Californian Healthcare Provider
Oct04

OCR Imposes $240,000 HIPAA Fine on Californian Healthcare Provider

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $240,000 civil monetary penalty on Providence Medical Institute to resolve potential violations of two provisions of the HIPAA Security Rule. This is the fifth investigation of a ransomware attack to result in a penalty for noncompliance with the HIPAA Rules. Providence Medical Institute (PMI) is a Californian healthcare provider that acquired a full-scope orthopedic medical service provider – Center for Orthopaedic Specialists (COS) – in July 2016. PMI planned to fully integrate COS as a PMI unit within 2 years, although the integration was delayed until May 2019. On February 18, 2018, a ransomware group encrypted files on COS systems. The threat actor gained a foothold in the network after an employee responded to a phishing email and disclosed their credentials. Within a few days of the encryption event, systems were restored from backup tapes; however, on February 25, 2018, COS systems were encrypted a second time. Within a few days, files were restored from backup tapes for a second...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist