NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is a HIPAA Course?
Oct04

What is a HIPAA Course?

A HIPAA course is a training course that is either provided by an employer to members of the workforce, or that is taken independently by an individual in order to obtain a qualification that demonstrates an understanding of HIPAA. The first type of HIPAA course is most often a regulatory requirement. The second type of HIPAA course  is optional, but is recommended for students, jobseekers, and employees in the healthcare industry. The HIPAA training requirements in §164.530(b) of the HIPAA Privacy Rule require covered entities to provide training on HIPAA policies and procedures to all new members of the workforce when they join the covered entity’s workforce. A HIPAA training course must also be provided for all members of the workforce when their functions are affected by a material change to policies and procedures. Business associates must also comply with these requirements “where provided”. In addition, covered entities and business associates are required by §164.308(a) of the Security Rule to provide security and awareness training to all members of the workforce...

Read More
Four Individuals Connected to LockBit Ransomware Attacks Arrested; Evil Corp Members Sanctioned
Oct03

Four Individuals Connected to LockBit Ransomware Attacks Arrested; Evil Corp Members Sanctioned

An international law enforcement operation has resulted in the arrests of four individuals suspected of involvement in LockBit ransomware attacks and the takedown of nine servers linked to LockBit ransomware operations. Operation Cronos The latest actions are part of phase three of Operation Cronos, an international law enforcement operation led by the UK’s National Crime Agency (NCA) that successfully took down the online infrastructure of the LockBit ransomware operation in February this year. The February operation caused significant disruption to the group’s operations, and while the group claimed to have restored its infrastructure within a week, it was clear that Operation Chronos caused significant disruption that lasted longer than the group was willing to acknowledge. The NCA obtained around 7,000 decryption keys, which allowed victims to recover their data. The operation uncovered the leader of the group, Russian national Dmitry Khoroshev aka LockBitSupp, who has since been sanctioned by the Foreign, Commonwealth & Development Office (FCDO), US Department of the...

Read More
Email Account Breaches Reported by Four HIPAA Covered Entities
Oct03

Email Account Breaches Reported by Four HIPAA Covered Entities

Four HIPAA-covered entities have recently reported breaches of their email environments: Southern Bone & Joint Specialists in Mississippi, Connally Memorial Medical Center in Texas, Rim Country Health and Rehabilitation in Arizona, and Michigan Masonic Home. Southern Bone & Joint Specialists Southern Bone & Joint Specialists in southern Mississippi have reported a breach of their email environment. Unauthorized activity was identified in certain employee email accounts on May 7, 2024, and after the accounts were secured, a specialized cybersecurity firm was engaged to investigate the breach. The investigation confirmed there had been unauthorized access to the accounts and that certain files and data stored in the email environment had been accessed. The file review was completed on August 6, 2024, and confirmed that the protected health information of 7,162 patients had been exposed. The types of information involved varied from individual to individual and may have included names, addresses, phone numbers, dates of birth, diagnosis codes, insurance policy numbers, and...

Read More
HHS Finalizes Health IT Strategic Plan for 2024-2030
Oct02

HHS Finalizes Health IT Strategic Plan for 2024-2030

The Department of Health and Human Services (HHS), through the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (ASTP), has announced its final 2024-2030 Federal Health IT Strategic Plan. The Health IT Strategic Plan, a requirement of the HITECH Act, outlines the federal health information technology (health IT) goals and objectives to use healthIT and electronic health information (EHI) to promote health and wellness, enhance the delivery and experience of care, accelerate research and innovation, and connect the health system with health data. “The release of our latest health IT strategy is a culmination of partnership across the federal government to examine the forces shaping the health care ecosystem today and to craft a set of strategies to guide how to prioritize resources, align and coordinate federal health IT initiatives and activities, signal priorities to industry, and benchmark and assess progress over time,” said Micky Tripathi, Ph.D., assistant secretary for technology policy and national coordinator for...

Read More
Report Provides Insights into the Financial Impact of Cyberattacks
Oct02

Report Provides Insights into the Financial Impact of Cyberattacks

A new report from the cyber-physical systems (CPS) protection company, Claroty, provides insights into the financial impact of cyberattacks and reveals one in four CPS-enabled organizations lost more than $1 million due to cyberattacks in the past 12 months. For the report, Claroty conducted a survey of 1,110 cybersecurity professionals who had responsibilities for CPS, including operational technology (OT), Internet of Things (IoT), connected medical devices (IoMT), and building management systems (BMS). 45% of surveyed cybersecurity professionals said they suffered losses of $500,000 or more in the past 12 months due to cyberattacks, with 27% suffering losses of $1 million or more. Many costs have to be covered following a cyberattack. Aside from the ransom payment, the main factors that contributed to the losses were loss of revenue, reported by 39% of organizations, followed by recovery costs (35%), employee overtime (33%), legal costs (31%), and the loss of customers/partners (30%). Almost half of organizations (49%) that suffered a cyberattack said it resulted in operational...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist