NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Pharmacy Association and 40 Providers Sue Change Healthcare Over Cyberattack
Jul24

Pharmacy Association and 40 Providers Sue Change Healthcare Over Cyberattack

The National Community Pharmacists Association (NCPA) and more than three dozen healthcare providers in 22 U.S. states are suing Change Healthcare, Optum, and UnitedHealth Group over its February 2024 ransomware attack and data breach. The Blackcat ransomware attack was discovered on February 21, 2024, when parts of Change Healthcare’s systems were encrypted. To contain the attack and prevent further unauthorized access, Change Healthcare took its systems offline, including the Change Healthcare platform that acts as a claims processing, revenue, and payment cycle management service that connects payers, providers, and patients. The platform and other offline Change Healthcare systems are relied upon by providers across the country and those systems touch the protected health information of 1 in 3 Americans. The platform remained offline for several weeks, and Change Healthcare still has not fully recovered from the attack. The HIPAA Journal has covered the Change Healthcare ransomware attack in detail here. This single point of failure left the healthcare industry immobilized and...

Read More
Michigan Medicine Suffers Another Email Data Breach
Jul23

Michigan Medicine Suffers Another Email Data Breach

University of Michigan Medicine (Michigan Medicine) has recently notified 56,953 individuals about the exposure of some of their protected health information. According to a recent news release, patient data was stored in three employee email accounts which were accessed by an unauthorized third party between May 23, and May 29, 2024. When suspicious email activity was detected, the affected accounts were immediately secured to prevent further unauthorized access by blocking the attacker’s IP address and changing account passwords. An investigation was launched to determine the nature and scope of the breach which confirmed that the incident was limited to three employee email accounts. Michigan Medicine conducted a review of the affected email accounts between June 10, 2024, and June 27, 2024, and confirmed that sensitive data was present in the accounts. The email accounts were used for communications related to payment and billing coordination. Michigan Medicine did not find any evidence to suggest the aim of the attack was to obtain patient information; however, data theft...

Read More
MCG Health Settles Class Action Data Breach Lawsuit for $8.8 Million
Jul23

MCG Health Settles Class Action Data Breach Lawsuit for $8.8 Million

The Seattle, WA-based software company, MCG Health, has proposed a $8.8 million settlement to resolve a consolidated class action lawsuit stemming from a February 2020 data breach that involved the protected health information of 793,283 individuals. It took MCG Health two years to discover that a threat actor had obtained data from its network, with that determination made on March 25, 2022. Patients of at least 10 of its clients had information compromised in the incident including names, Social Security numbers, medical codes, postal addresses, telephone numbers, email addresses, and dates of birth. Several class action lawsuits were filed in response to the breach that made similar claims and alleged negligence, invasion of privacy, bailment, breach of implied contract, breach of confidence, and a violation of the Washington Consumer Protection Act. The lawsuits were consolidated into a single action in the U.S. District Court for the Western District of Washington – In re: MCG Health Data Security Issue Litigation. MCG Health has not admitted any wrongdoing and chose to...

Read More
What is FISMA Compliance?
Jul22

What is FISMA Compliance?

FISMA compliance is compliance with applicable standards and guidelines developed by the National Institute of Standards and Technology (NIST) following the passage of the Federal Information Security Management Act of 2002 (FISMA). FISMA compliance is mandatory for federal agencies, state and local government agencies in receipt of federal funding, and service providers working with federal, state, and local government agencies, When FISMA was passed in 2002, it required all federal agencies to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency. The requirements also applied to information and systems provided or managed by third party service providers, and was later extended to include state and local government agencies in receipt of federal funding. To support covered entities in meeting the FISMA compliance requirements, FISMA authorized NIST to develop standards and guidelines to protect federal information and information systems. NIST subsequently...

Read More
Cyberattack on The Medibase Group Affects 35,000 Patients
Jul22

Cyberattack on The Medibase Group Affects 35,000 Patients

Cyberattacks have recently been announced by the Medibase Group, Therapeutic Health Services, and the law firm Smith, Gambrell & Russell. The Medibase Group The Medibase Group, Inc., a Woodstock, GA-based provider of software solutions, technical assistance, and business office solutions to healthcare delivery organizations, has experienced a cyberattack that exposed the protected healthcare information of 35,106 patients of its healthcare provider clients. The cyberattack occurred on or around January 26, 2024, and involved unauthorized access to one of Medibase’s systems. Prompt action was taken to contain the attack, and a leading security and forensics company was engaged to assist with the investigation. The investigation confirmed that the attack was limited to the Medibase system, and no client systems were compromised. The review of the affected files revealed they contained full names, Social Security numbers, dates of birth, admission/discharge dates, outstanding balance amounts, and health insurance information. While data theft is possible, Medibase believes the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist