25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

June 2024 Healthcare Data Breach Report
Jul19

June 2024 Healthcare Data Breach Report

In June 2024, 47 data breaches of 500 or more healthcare records were reported to the HHS’ Office for Civil Rights (OCR), the fewest number of breaches since October 2023. Data breaches were down 9.6% from May 2024, and 30.9% down from June 2023, and were well below the 12-month average of 64 data breaches a month. For the second consecutive month, the number of breached records has fallen. Across the 47 breaches reported in June, the protected health information of 3,837,356 individuals was exposed, stolen, or impermissibly disclosed. June’s compromised record total is the second lowest monthly total in 2024, 54.7% lower than May 2024, and well below the 12-month average of 11,637,320 breached records a month. It is likely to be a very different story next month, as Change Healthcare will be mailing breach notification letters to the individuals affected by its February 2024 ransomware attack from July 20, 2024, which means OCR will soon be notified about the extent of the breach. The CEO of Change Healthcare’s parent company, UnitedHealth Group, told a senate hearing that the...

Read More
What is the Confidentiality Definition in Healthcare?
Jul19

What is the Confidentiality Definition in Healthcare?

The confidentiality definition in healthcare is an ethical obligation to preserve authorized restrictions on access to – and disclosures of – sensitive personal information gathered in association with the care of a patient. In this respect, the ethical confidentiality definition in healthcare is broader than the legal confidentiality definition in HIPAA. The ethical confidentiality definition in healthcare is derived from the definition of confidentiality used in Title 44, Chapter 35 of the US Code relating to Information Security. The definition states “confidentiality […] means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.” The reason it is a derived definition rather than an actual definition is because few healthcare regulations define “confidentiality”. Even the “Confidentiality of SUD Patient Records” (42 Part 2) does not define confidentiality – despite giving HHS the authority to impose penalties on healthcare providers that fail to maintain the confidentiality of SUD patient...

Read More
CISA Issues Alert About Multiple Philips Vue PACS Vulnerabilities
Jul19

CISA Issues Alert About Multiple Philips Vue PACS Vulnerabilities

More than a dozen vulnerabilities have been identified in the Philips Vue PACS image management and communication system, including critical vulnerabilities that can be remotely exploited in a low-complexity attack. Successful exploitation of the vulnerabilities could allow an unauthenticated individual to remotely execute code, install unauthorized software, eavesdrop, view, or modify data, or negatively impact the confidentiality, integrity, or availability of the system or data. The 13 vulnerabilities affect all versions prior to 12.2.8.410. Vue PACS Vulnerabilities CVE Type CVSS v3.1 CVSS v4 CVE-2017-17485 Deserialization of untrusted data 9.8 9.3 CVE-2020-11113 Deserialization of untrusted data 8.8 7.1 CVE-2020-10673 Deserialization of untrusted data 8.8 8.7 CVE-2023-40159 Exposure of sensitive information to an unauthorized actor 8.2 8.8 CVE-2020-35728 Deserialization of untrusted data 8.1 9.3 CVE-2021-20190 Deserialization of untrusted data 8.1 9.3 CVE-2020-14061 Deserialization of untrusted data 8.1 9.3 CVE-2021-28165 Uncontrolled resource consumption 7.5 8.8 CVE-2020-40704...

Read More
Memorial Sloan Kettering Cancer Center Employees Tricked by Phishing Email
Jul19

Memorial Sloan Kettering Cancer Center Employees Tricked by Phishing Email

Memorial Sloan Kettering Cancer Center (MSK) has announced that the protected health information of 12,274 individuals has been exposed in a phishing attack. On April 26, 2024, MSK identified suspicious activity in an employee email account. The account was used to send an email to many other MSK employees that contained a link to a spoofed web page that prompted users to log in to their MSK accounts and captured their credentials when they were entered. Several employees were tricked by the email because the message had been sent from a valid MSK account and appeared to be a valid internal request. An analysis of the compromised email accounts confirmed they contained some protected health information, including first and last names, medical record numbers, diagnoses, medication names, treatment types, and dates of treatment. A subset of the affected individuals also had their contact information (address, email, telephone number) and dates of birth exposed. MSK confirmed that the breach was limited to email accounts, medical records were not accessed, and Social Security numbers...

Read More
ITRC: More Than 1 Billion Individuals Affected by H1, 2024 Data Compromises
Jul18

ITRC: More Than 1 Billion Individuals Affected by H1, 2024 Data Compromises

The first half of 2024 saw a significant increase in the number of victims of data breaches, according to a recently published H1 Data Breach Analysis by the Identity Theft Resource Center. In the first 6 months of the year, there were 1,571 publicly reported compromises, up 14% from H1, 2023, and more than 1 billion victims. The size of some of the data breaches was astonishing. The two biggest attacks in terms of the number of affected individuals occurred at Ticketmaster Entertainment and Advance Auto Parts, with the former involving the personal data of 560 million individuals and the latter affecting 380 million individuals. A data breach at Dell Technologies affected 49 million individuals, a breach at LoanDepot affected 16.9 million individuals, and a healthcare data breach at Kaiser Foundation Health Plan rounded out the top 5 and affected 13.4 million individuals. Two other healthcare data breaches made the top 10 – The attack on the debt collection firm, Financial Business and Consumer Solutions, Inc., which affected 3,435,640 individuals, and the attack on the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist