25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Class Action Lawsuit Filed Against Cencora/Lash Group Over Cyberattack
Jun06

Class Action Lawsuit Filed Against Cencora/Lash Group Over Cyberattack

A lawsuit has been filed against Cencora Inc. and The Lash Group LLC over a recently disclosed data breach. The lawsuit, which is likely to be one of many, names Keith Wolford as the plaintiff, and alleges the defendants failed to implement reasonable and appropriate safeguards to ensure the confidentiality of personally identifiable and protected health information. As a result of those failures, patient data has been impermissibly disclosed to cybercriminals. Cencora, a wholesale drug company formerly known as AmerisourceBergen and the parent company of The Lash Group, announced in May 2024 that an unauthorized third party accessed its network and exfiltrated sensitive data. The forensic investigation confirmed that the stolen data included personal and health information such as first names, last names, dates of birth, diagnoses, and/or medications and prescriptions. Notifications were issued to the affected individuals in May 2024 and free credit monitoring and remediation services have been offered for 24 months. Cencora notified the Securities and Exchange Commission (SEC)...

Read More
Panorama Eyecare Notifies 377K Individuals a Year After Ransomware Attack
Jun06

Panorama Eyecare Notifies 377K Individuals a Year After Ransomware Attack

In July 2023, the LockBit ransomware group added Panorama Eyecare to its data leak site and claimed to have exfiltrated 798 GB of data from the Fort Collins, CO-based physician-led management services organization  The ransomware group claimed to have obtained data from its clients, including Eye Center of Northern Colorado, Denver Eye Surgeons, Cheyenne Eye Clinic & Surgery Center, and 2020 Vision Center. Panorama Eyecare has now confirmed the attack, a year after the intrusion was first detected. According to the breach notification issued to the Maine Attorney General, the intrusion was detected on June 3, 2023. The letters state that the forensic investigation confirmed that an unauthorized actor had access to its network between May 22, 2023, and June 4, 2023, and that as a result of the cybersecurity incident the attacker “may have accessed and removed certain files from our network environment.” The reason for the delay in issuing HIPAA notification letters was due to the comprehensive review of the impacted files which took until May 9, 2024, to complete. That review...

Read More
FBI Urges LockBit Ransomware Victims to Contact IC3; 7,000 Decryption Keys Obtained
Jun06

FBI Urges LockBit Ransomware Victims to Contact IC3; 7,000 Decryption Keys Obtained

The Federal Bureau of Investigation (FBI) is urging victims of LockBit ransomware attacks to get in touch with the Internet Crime Complaint Center (IC3). The FBI has obtained more than 7,000 decryption keys that can be used by past victims to recover from their data breaches for free. At the 2024 Boston Conference on Cyber Security yesterday, FBI Cyber Assistant Director Bryan Vorndran confirmed that the FBI has obtained a significant number of decryption keys from its ongoing efforts to disrupt the LockBit ransomware operation. The FBI was involved in an international law enforcement operation – Operation Cronos – headed by the UK National Crime Agency that resulted in 34 servers being seized and more than 2,500 decryption keys being obtained. The FBI was able to create a free decryptor to allow victims to recover their files for free, with more obtained from its ongoing operation against the group. The FBI has also been able to confirm that LockBit ransomware-as-a-service (RaaS) operation was set up by a Russian coder named Dimitri Khoroshev, aka LockBitsupp, who has now been...

Read More
Is OneDrive HIPAA Compliant?
Jun06

Is OneDrive HIPAA Compliant?

Microsoft OneDrive is HIPAA compliant provided covered entities subscribe to a plan that supports OneDrive HIPAA compliance, agree to the terms of Microsoft’s Business Associate (Data Protection) Addendum, and configure the file storage service to be used in compliance with HIPAA.   Microsoft OneDrive is a convenient file storage service that facilitates document sharing and collaboration. Many healthcare organizations subscribe to a Microsoft or Office 365 business plan that includes OneDrive; and, when the file storage service is used for administrative and operational purposes that do not involve disclosures of Protected Health Information (PHI), HIPAA compliance is not an issue. However, when the service is used to store and share files that contain PHI, it is important OneDrive is HIPAA compliant. This means that the Microsoft or Office 365 business plan must include the capabilities to support HIPAA compliance, and that the capabilities are configured to ensure OneDrive is used in compliance with HIPAA. It is also important a Business Associate Agreement is in place....

Read More
HHS Must Take Immediate Action to Improve Cybersecurity at Large Healthcare Organizations
Jun06

HHS Must Take Immediate Action to Improve Cybersecurity at Large Healthcare Organizations

Senate Finance Committee chair, Senator Ron Wyden (D-OR) wrote to Department of Health and Human Services (HHS) Secretary Xavier Becerra this week calling for immediate action against large healthcare companies to ensure they improve their cybersecurity practices. “The current epidemic of successful cyberattacks against the health care sector is a direct result of HHS’s failure to appropriately regulate and oversee this industry,” said Sen. Wyden. This year has seen major cyberattacks on large healthcare organizations including Change Healthcare and Ascension that have caused massive disruption to healthcare services across the United States. The attacks have disrupted patient care and caused actual harm to patients, and a huge amount of highly sensitive patient data has been stolen and is now in the hands of cybercriminals putting them at risk of identity theft and fraud. Change Healthcare, part of UnitedHealth Group (UHG), is the largest healthcare company in the United States, yet a hacker gained access to its internal network due to lax cybersecurity practices. The hacker used...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist