NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Two LockBit Ransomware Affiliates Plead Guity and Face Up to 70 Years in Prison
Jul22

Two LockBit Ransomware Affiliates Plead Guity and Face Up to 70 Years in Prison

The Department of Justice has announced that two foreign nationals have pleaded guilty to charges related to their participation in the LockBit ransomware operation and for using ransomware to attack businesses in the United States and worldwide. The LockBit ransomware-as-a-service (RaaS) operation emerged in 2020 and rapidly became the most prolific ransomware group worldwide. LockBit ransomware has been used to attack more than 2,500 victims, including 1,800 in the United States, and has generated more than $500 million in ransom payments. In February 2024, an international law enforcement operation (Operation Chronos) seized the infrastructure of the group, including data leak sites, servers, around 14,000 accounts involved with data exfiltration, and around 200 cryptocurrency accounts that were used by the group and its affiliates. The group survived the disruption but has since operated at a reduced capacity. Ruslan Magomedovich Astamirov, 21, a Russian national of the Chechen Republic in Russia, and Mikhail Vasiliev, 34, a dual Canadian and Russian national of Bradford,...

Read More
Faulty CrowdStrike Software Update Causing Major Disruption at U.S. Healthcare Organizations
Jul20

Faulty CrowdStrike Software Update Causing Major Disruption at U.S. Healthcare Organizations

After the massive disruption and financial difficulties caused by the Change Healthcare ransomware attack, the last thing healthcare providers need right now is further disruption; however, many hospitals have been forced to cancel appointments and delay services due to a faulty software update that has disabled their Windows devices. While the update has affected Windows devices, the issue was a faulty software update from the Cybersecurity company CrowdStrike that affects users of its Falcon threat detection platform. It was supposed to be just another routine software update; however, the bug crashed Windows devices and triggered the dreaded blue screen of death, preventing Windows devices from rebooting and rendering them inoperable. Mac and Linux systems were not affected by the update. “I want to sincerely apologize directly to all of you,” said CrowdStrike CEO, George Kurtz. “All of CrowdStrike understands the gravity and impact of the situation.” Kurtz stressed that there was no unauthorized access to systems, the problem has been identified, and the...

Read More
June 2024 Healthcare Data Breach Report
Jul19

June 2024 Healthcare Data Breach Report

In June 2024, 47 data breaches of 500 or more healthcare records were reported to the HHS’ Office for Civil Rights (OCR), the fewest number of breaches since October 2023. Data breaches were down 9.6% from May 2024, and 30.9% down from June 2023, and were well below the 12-month average of 64 data breaches a month. For the second consecutive month, the number of breached records has fallen. Across the 47 breaches reported in June, the protected health information of 3,837,356 individuals was exposed, stolen, or impermissibly disclosed. June’s compromised record total is the second lowest monthly total in 2024, 54.7% lower than May 2024, and well below the 12-month average of 11,637,320 breached records a month. It is likely to be a very different story next month, as Change Healthcare will be mailing breach notification letters to the individuals affected by its February 2024 ransomware attack from July 20, 2024, which means OCR will soon be notified about the extent of the breach. The CEO of Change Healthcare’s parent company, UnitedHealth Group, told a senate hearing that the...

Read More
What is the Confidentiality Definition in Healthcare?
Jul19

What is the Confidentiality Definition in Healthcare?

The confidentiality definition in healthcare is an ethical obligation to preserve authorized restrictions on access to – and disclosures of – sensitive personal information gathered in association with the care of a patient. In this respect, the ethical confidentiality definition in healthcare is broader than the legal confidentiality definition in HIPAA. The ethical confidentiality definition in healthcare is derived from the definition of confidentiality used in Title 44, Chapter 35 of the US Code relating to Information Security. The definition states “confidentiality […] means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.” The reason it is a derived definition rather than an actual definition is because few healthcare regulations define “confidentiality”. Even the “Confidentiality of SUD Patient Records” (42 Part 2) does not define confidentiality – despite giving HHS the authority to impose penalties on healthcare providers that fail to maintain the confidentiality of SUD patient...

Read More
CISA Issues Alert About Multiple Philips Vue PACS Vulnerabilities
Jul19

CISA Issues Alert About Multiple Philips Vue PACS Vulnerabilities

More than a dozen vulnerabilities have been identified in the Philips Vue PACS image management and communication system, including critical vulnerabilities that can be remotely exploited in a low-complexity attack. Successful exploitation of the vulnerabilities could allow an unauthenticated individual to remotely execute code, install unauthorized software, eavesdrop, view, or modify data, or negatively impact the confidentiality, integrity, or availability of the system or data. The 13 vulnerabilities affect all versions prior to 12.2.8.410. Vue PACS Vulnerabilities CVE Type CVSS v3.1 CVSS v4 CVE-2017-17485 Deserialization of untrusted data 9.8 9.3 CVE-2020-11113 Deserialization of untrusted data 8.8 7.1 CVE-2020-10673 Deserialization of untrusted data 8.8 8.7 CVE-2023-40159 Exposure of sensitive information to an unauthorized actor 8.2 8.8 CVE-2020-35728 Deserialization of untrusted data 8.1 9.3 CVE-2021-20190 Deserialization of untrusted data 8.1 9.3 CVE-2020-14061 Deserialization of untrusted data 8.1 9.3 CVE-2021-28165 Uncontrolled resource consumption 7.5 8.8 CVE-2020-40704...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist