25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

177,000 Patients Affected by Breach at Northeast Orthopedics and Sports Medicine

Data breaches have recently been reported by Northeast Orthopedics and Sports Medicine, NewGen Administrative Services, Orlando VA Medical Center, Orthopedic Associates of Flower Mound, and Kids Care Dental & Orthodontics. Northeast Orthopedics and Sports Medicine, New York Northeast Orthopedics and Sports Medicine in Nanuet, NY, has recently announced that it fell victim to a cyberattack that has affected 177,276 individuals and exposed the protected health information of 177,101 patients. Unusual activity was identified in its network on November 22, 2023. Third-party forensics specialists were engaged to assist with the investigation, and on December 22, 2023, confirmed that there had been unauthorized access to data on its network. The review of the affected files confirmed they contained names, Social Security numbers, driver’s license information, payment information, dates of birth, medical record information, health insurance information, and treatment and diagnosis information. Northeast Orthopedics and Sports Medicine has implemented additional safeguards to prevent...

Read More

Lurie Children’s Hospital Restores EHR System a Month After Ransomware Attack

It has been just over a month since Ann & Robert H. Lurie Children’s Hospital in Chicago experienced a ransomware attack that forced it to take down its phone, email, and medical record systems. Lurie Children’s Hospital, which treats more than 220,000 patients a year, detected a breach of its systems on January 31, 2024, and has confirmed that “a known threat actor” gained access to its systems but did not state whether ransomware was used and has yet to confirm the extent of the data breach. The known threat actor is the Rhysida ransomware group, which is a relatively new ransomware-as-a-service operation that has been active since May 2023. The group mostly targets organizations in education, government, and manufacturing; however, several attacks have been conducted on healthcare organizations including Singing River Health System and Prospect Medical Holdings. The group is not a major player in the ransomware market but is a well-established group that conducted at least 74 attacks in 2023 – around 2% of all ransomware attacks globally, and last year was behind 4% of...

Read More
Sen. Cassidy Proposes Legislative Updates to Improve Health Data Privacy
Mar07

Sen. Cassidy Proposes Legislative Updates to Improve Health Data Privacy

Senator Bill Cassidy (R-LA), Ranking Member of the U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee, has published a white paper that proposes updates to the Health Insurance Portability and Accountability Act (HIPAA) to improve privacy protections for health information and urges Congress to take action to expand privacy protections for all health data. The white paper – Strengthening Health Data Privacy for Americans: Addressing the Challenges of the Modern Era – follows Sen. Cassidy’s September 2023 request for information from healthcare industry stakeholders on the current state of HIPAA, how best to enhance health data privacy, and ensure that health data collected by entities that are not bound by HIPAA is also protected. New technologies are being introduced in healthcare and interoperability of health data is increasing, which is helping to improve care and patients’ access to their health information; however, new technology has increased the attack surface and improved access can easily lead to increased vulnerability for inappropriate data...

Read More

Multiple Class Action Lawsuits Filed in Response to Change Healthcare Ransomware Attack

Change Healthcare experienced a Blackcat ransomware attack on February 21, 2024, and is still recovering from the incident, with many systems still offline more than 2 weeks after the attack. The Blackcat ransomware group claimed to have stolen 6TB of data before encrypting files and the affiliate behind the attack alleged a $22 million ransom was paid by Optum to have the stolen data and obtain the decryption keys. The affiliate claims the Blackcat group stole the funds and didn’t pay, Blackcat claimed law enforcement shut down its operation, and the affiliate still has 6TB of the stolen data.  Nether Change Healthcare, Optum, of their parent company, UnitedHealth Group, have confirmed the extent of any data breach and whether a ransom was paid, only issuing a statement saying they are currently focused on the investigation and bringing their systems back online. Given the history of the Blackcat group, it is likely that the stolen data includes a significant amount of patient data, and with Change Healthcare processing around 15 billion healthcare transactions each year –...

Read More
HHS Responds to Change Healthcare Cyberattack with New Flexibilities for Affected Providers
Mar06

HHS Responds to Change Healthcare Cyberattack with New Flexibilities for Affected Providers

The Department of Health and Human Services (HHS) has issued a statement about the February 2024 Blackcat ransomware attack on UnitedHealth Group-owned Change Healthcare. The attack took more than 100 of Change Healthcare’s systems out of action, which has had far-reaching consequences for the providers that rely on those systems for checking insurance coverage, submitting claims, and getting paid. Several industry groups wrote to the HHS requesting assistance for their members, who are experiencing severe cash flow problems as they have been unable to receive payments without Change Healthcare’s systems. UnitedHealth Group has set up a temporary financial assistance program to help providers who have been unable to receive payments, but the move has been criticized by industry groups due to the limited eligibility and onerous terms. The HHS said it recognized the impact the cyberattack has had on healthcare operations nationwide and that its first priority is to help coordinate efforts to avoid disruptions to care. The HHS is in regular contact with UnitedHealth Group leadership...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist