25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Email Incidents Affect Patients of Winter Haven Hospital & The Kennedy Collective
May14

Email Incidents Affect Patients of Winter Haven Hospital & The Kennedy Collective

Patient and Employee Data Exposed in Phishing Attack on The Kennedy Collective The Kennedy Collective, a Trumball, CT provider of disability services formerly known as The Kennedy Center, has fallen victim to a phishing attack that exposed patient and employee data. An employee responded to a phishing email and disclosed their credentials, which allowed the attacker to access the employee’s email account. The account has been secured; however, the review of emails and attachments revealed they contained personal health information, and for a subset of those individuals, Social Security numbers and driver’s license information. The breach has been reported to the HHS’ Office for Civil Rights as involving the protected health information of 851 individuals. It is unclear how many employees have been affected. All affected individuals have been notified by mail and individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. The Kennedy Collective has taken steps to improve email security and has provided additional anti-phishing...

Read More
Black Basta Ransomware Group Targeting Healthcare Organizations
May13

Black Basta Ransomware Group Targeting Healthcare Organizations

All healthcare and public health (HPH) sector organizations have been warned to be on high alert and to implement mitigations against Black Basta ransomware attacks, as the ransomware-as-a-service (RaaS) group has the HPH sector in its crosshairs. In 2023, Black Basta was the third-most prolific ransomware group behind LockBit and ALPHV/Blackcat, but with the latter now shut down, Black Basta has taken second spot and attacks have been increasing, especially on critical infrastructure entities. Black Basta affiliates have conducted data theft and encryption attacks in 12 of the 16 critical infrastructure sectors, and recently the group has accelerated attacks on healthcare organizations. According to multiple CNN sources, Black Basta was behind the recent ransomware attack on Ascension which disrupted clinical operations at its 140 hospitals. Black Basta first emerged as a RaaS group in April 2022 and is thought to include members of the now-defunct Conti ransomware group. The RaaS group has been linked to the FIN7 threat actor. The group engages in double extortion tactics, where...

Read More

Palomar Health Medical Group Investigating Potential Cyberattack

Palomar Health Medical Group in California is investigating a potential cyberattack, Prudential Insurance Company of America and West Idaho Orthopedics and Sports Medicine have experienced ransomware attacks, and patient data has been exposed in a cyberattack on Georgia Institute for Plastic Surgery. Palomar Health Medical Group Investigating Potential Cyberattack Palomar Health Medical Group, a provider of primary and specialty care in North San Diego County, CA, is investigating a potential cyberattack after detecting suspicious activity within its computer network. The activity was detected on May 5, 2024, and the affected systems were taken offline to contain any malware. As a result of breach response processes, the patient portal, phones, and faxes are temporarily unavailable. With most communication systems down, patients have been advised to visit their physicians in person and to expect delays due to the disruption. Third-party cybersecurity specialists have been engaged to investigate the incident and identify the source of the disruption, and systems will be brought back...

Read More
OSHA Close to Issuing Proposed Heat Safety Rule
May10

OSHA Close to Issuing Proposed Heat Safety Rule

The Department of Labor’s Occupational Safety and Health Administration (OSHA) is a step closer to issuing new heat safety regulations after its draft rule addressing the dangers of workplace heat received the backing of the Advisory Committee on Construction Safety and Health (ACCSH). ACCSH advises OSHA on safety and health standards and policy matters, and after being presented with the draft rule on April 24, 2024, ACCSH unanimously recommended that OSHA expeditiously move forward and issue a Notice of Proposed Rulemaking. Currently, the Occupational Safety and Health (OSH) Act requires employers to address hazards in the workplace. Employers are required to protect workers from the dangers of heat exposure and must have a proper safety and health plan in place. At the very least, employers should provide adequate cool water, rest breaks, and shade or a cool rest area, and any new employees or employers who are returning to a high-heat workplace should be allowed time to acclimatize to the heat and managers and workers should be trained on how to recognize the signs of...

Read More
Only 49% of Critical Infrastructure Entities Acted on CISA Ransomware Vulnerability Warnings
May09

Only 49% of Critical Infrastructure Entities Acted on CISA Ransomware Vulnerability Warnings

In late 2022, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) launched a Ransomware Vulnerability Warning Pilot (RVWP) program that involved sending warnings to critical infrastructure entities when vulnerabilities were identified in their internet-facing devices. The program concentrated on vulnerabilities that were known to have been exploited by ransomware groups. CISA conducts scans of internet-exposed devices to identify known vulnerabilities that could potentially be exploited. If a vulnerability is detected on an internet-accessible device, CISA proactively sends a warning to allow action to be taken to correct the vulnerability before it can be exploited. When the pilot commenced, many warnings were sent about the ProxyNotShell vulnerabilities, which were being actively exploited by ransomware groups. According to Verizon’s 2024 Data Breach Investigations report, there has been a 180% YoY increase in cyberattacks that used vulnerability exploitation for initial access. Ransomware groups are actively seeking vulnerabilities to exploit and are finding plenty...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist