NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

UMC Health System Responding to Ransomware Attack
Sep27

UMC Health System Responding to Ransomware Attack

UMC Health System, which operates University Medical Center in Lubbock, Texas, has been forced to divert emergency and non-emergency patients to ensure patient safety and continuity of care due to an IT outage. Its facilities remain open for existing inpatients and care continues to be provided. The outage occurred on September 26, 2024, and it has since been confirmed that it was caused by a ransomware attack that has affected multiple systems. The incident has affected its phone system, and it has not been possible to view messages in the patient portal. The health system has implemented its downtime procedures and is doing all it can to minimize disruption to patients. UMC Health System is still responding to the outage and has launched an investigation to determine the extent of the breach and will issue updates as the investigation and recovery progress. At this stage, it is not possible to tell to what extent, if any, patient data has been compromised. Updates on the attack can be found here. Community Clinic of Maui – Malama I Ke Ola Health Center Community Clinic of...

Read More
Michigan Medicine Experiences Another Email Account Hacking Incident
Sep27

Michigan Medicine Experiences Another Email Account Hacking Incident

The data breaches at Michigan Medicine keep on coming, with the latest incident involving unauthorized access to an employee’s email account on July 30, 2024. The email account was reviewed and found to contain the protected health information of 57,891 individuals. A similarly sized email data breach was announced by Michigan Medicine in July, with that incident involving unauthorized access to three employee email accounts in May 2024. Two years ago, another email breach occurred as a result of a response to a phishing email that exposed the protected health information of 33,000 patients. The Ann Arbor, MI-based healthcare provider said one of its employees accepted an unsolicited multifactor authentication prompt, which allowed an unauthorized individual to access the email account and its contents. The account was disabled as soon as the unauthorized access was detected, and an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation confirmed that patient data was present in emails and attachments that were used for...

Read More
Democratic Senators Propose Mandatory Cybersecurity Standards in Healthcare and Greater Accountability
Sep27

Democratic Senators Propose Mandatory Cybersecurity Standards in Healthcare and Greater Accountability

Two Democratic senators have announced new legislation to update XI and XVIII of the Social Security Act to strengthen, increase oversight of, and compliance with security standards for health information. The proposed legislation will address healthcare infrastructure cybersecurity and ensure that serious financial penalties are imposed for compliance failures. The legislation – The Health Infrastructure Security and Accountability Act – was introduced by Senate Finance Committee Chair Ron Wyden (D-OR) and Senator Mark Warner (D-VA) and seeks to introduce minimum standards for cybersecurity to make it harder for cybercriminals to breach healthcare networks. Currently, the HHS’ Office for Civil Rights Breach Portal shows 394 large data breaches have been reported in 2024 that are attributed to hacking/IT incidents, and those breaches have affected more than 43 million individuals. In 2023, 602 data breaches were reported as hacking/IT incidents involving the healthcare records of more than 151 million individuals. These cyberattacks have delayed and disrupted patient care,...

Read More
Cascade Eye and Skin Centers Settles Alleged HIPAA Violations for $250,000
Sep27

Cascade Eye and Skin Centers Settles Alleged HIPAA Violations for $250,000

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled alleged HIPAA violations with the Washington healthcare provider Cascade Eye and Skin Centers, P.C. for $250,000. OCR launched an investigation of the privately-owned Washington healthcare provider after learning on May 26, 2017, that patient data had been exposed in a March 2017 ransomware attack. According to OCR, the ransomware group had access to a network server where 291,000 files containing patients’ protected health information were stored. The investigation uncovered one of the most common HIPAA compliance failures – the lack of a comprehensive, accurate, organization-wide risk analysis to identify potential risks and vulnerabilities to electronic protected health information (ePHI), as required by 45 C.F.R. § 164.308(a)(1)(ii)(A). OCR also determined there were insufficient reviews of activity in information systems that contained ePHI., as required by 45 C.F.R. § 164.308(a)(l)(ii)(D). Cascade Eye and Skin Centers was given the opportunity to settle the alleged HIPAA violations and...

Read More
2024 National Cybersecurity Awareness Month
Sep26

2024 National Cybersecurity Awareness Month

October is National Cybersecurity Awareness Month – a month-long effort to raise awareness of the importance of cybersecurity and highlight security best practices. National Cybersecurity Awareness Month is led by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance and this year’s theme is “Secure Our World.” The focus this year is to engage everyone in combating cyber threats by changing behaviors and creating healthy cyber habits. To help “Secure Our World,” there are four easy steps that everyone can take to stay safe online, protect their personal data, and make it harder for cybercriminals to succeed in their attacks. Recognize and Report Phishing Be constantly alert to potential threats such as unsolicited messages, requests for personal information, or credentials with unknown sources, and report suspicious messages immediately. Use Strong Passwords and a Password Manager Ensure that accounts are protected with strong passwords, including upper and lower case letters, numbers, and symbols, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist