25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Sav-Rx Data Breach Affects 2.8 Million Individuals
May27

Sav-Rx Data Breach Affects 2.8 Million Individuals

A&A Services, a Fremont, Nebraska-based provider of Medication Benefit Management solutions to health plans that does business as Sav-Rx, has been affected by a cyberattack that was detected on October 8, 2023. A&A Services has confirmed that the Sav-Rx data breach involved the HIPAA protected health information of 2,812,336 individuals. A security breach was identified when there was an interruption to its computer network. Steps were taken to secure those systems and prevent further unauthorized access and third-party cybersecurity experts were engaged to contain the activity and investigate the cause of the disruption. Sav-Rx was able to restore its systems the following day with no material disruption to patient care, prescriptions continued to be shipped without delay, and since its adjudication system was unaffected, network pharmacy chains faced no disruption. The investigation revealed its systems were accessed by an unauthorized third party on October 3, 2024. While the incident was remediated swiftly, the investigation revealed that the threat actor behind the...

Read More
Systems Now Online at Lurie Children’s Hospital Following January Cyberattack
May27

Systems Now Online at Lurie Children’s Hospital Following January Cyberattack

Lurie Children’s Hospital of Chicago has confirmed that the last of its patient-facing systems were brought back online on May 20, 2024, following its January 31 cyberattack. While the children’s hospital is no longer addressing an active cyberattack, it is likely to take some time for patients to be able to view their full records via the MyChart portal. Since January 31, 2024, hospital staff have been operating under downtime procedures and have been recording patient information manually, and that information must now be added to MyChart. While records prior to the cyberattack can be viewed, there may be gaps in records until the information collected during the downtime is added. No timeframe has been provided on how long that process will take. Lurie Children’s Hospital has yet to confirm the extent of any data breach and will issue notifications to affected individuals when the investigation and data review has been completed. Lurie Children’s Hospital said a known criminal threat group conducted the attack. The Rhysida threat group claimed responsibility for the attack and...

Read More
Email Accounts Compromised at Children’s Minnesota and the LA County Dept. of Mental Health
May24

Email Accounts Compromised at Children’s Minnesota and the LA County Dept. of Mental Health

Email security breaches have been reported by Children’s Healthcare in Minnesota and the Los Angeles County Department of Mental Health that exposed patient information. Children’s Health Care, Minnesota Children’s Health Care, a children’s hospital in Minneapolis, MN, has discovered that patients’ protected health information has been exposed in an email security incident that was detected on March 13, 2024. Suspicious activity was identified in its email system and the forensic investigation confirmed that there had been unauthorized access to two employee email accounts between February 29, 2024, and March 25, 2024. The review of the emails and attachments is ongoing; however, it has been determined that patient information related to the surgical services department was stored in those accounts. The information potentially compromised in the attack included names, addresses, dates of birth, insurance carrier names, medical record numbers, provider names, treatment cost information, and/or limited treatment information related to care received at Children’s...

Read More
HPH Sector Warned About Business Email Compromise Attacks
May24

HPH Sector Warned About Business Email Compromise Attacks

The Department of Health and Human Services (HHS) Health Sector Cybersecurity Coordination Center (HC3) has issued a warning to the healthcare and public health (HPH) sector about business email compromise (BEC) attacks. BEC is a form of spear phishing that uses social engineering and deception to trick individuals into disclosing sensitive information or making fraudulent wire transfers. While these attacks tend not to cause the level of disruption as malware ransomware attacks, they are one of the most damaging and expensive types of cybercrime and cost businesses billions of dollars each year. According to the Federal Bureau of Investigation (FBI) Internet Crime Complaints Center (IC3), there were 277,918 domestic and international incidents reported between October 2013 and December 2022 resulting in more than $50 billion in losses, including 137,601 incidents in the United States and more than $17 billion in reported losses. BEC attacks target human weaknesses, such as the tendency to trust authority figures, act impulsively, and respond emotionally to urgent requests. These...

Read More
New CMS Web Portal Makes it Easier to Report Hospitals That Fail to Provide Emergency Abortion Care
May24

New CMS Web Portal Makes it Easier to Report Hospitals That Fail to Provide Emergency Abortion Care

The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has created a new web portal to make it easier for patients and healthcare workers to file complaints about emergency departments that they believe have unlawfully denied care. While the portal can be used to file complaints about any denial of care that is thought to violate the Emergency Medical Treatment and Active Labor Act (EMTALA), it was created in response to the overturning of Roe v. Wade and the introduction of state laws that severely restrict or ban abortion care. EMTALA was enacted in 1986 to prevent hospitals from turning away patients suffering life-threatening health emergencies. Under EMTALA, hospitals must perform screening examinations to determine if a patient is experiencing an emergency, and if confirmed, stabilizing treatment must be provided. If that treatment cannot be provided, they must appropriately transfer the patient to another facility to allow that care to be provided. Shortly after the Supreme Court’s decision that overturned Roe V. Wade and removed...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist