25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Blackcat Affiliate Behind Change Healthcare Ransomware Claims Group Stole $22 Million Ransom
Mar05

Blackcat Affiliate Behind Change Healthcare Ransomware Claims Group Stole $22 Million Ransom

The ALPHV/Blackcat ransomware group appears to have shut down its ransomware-as-a-service (RaaS) operation, indicating there may be an imminent rebrand. The group claims to have shut down its servers, its ransomware negotiation sites are offline, and a spokesperson for the group posted a message, “Everything is off, we decide.” A status message of “GG” was later added and ALPHV/Blackcat claimed that their operation was shut down by law enforcement and said it would be selling its source code. Security experts disagree and say there is clear evidence that this is an exit scam, where the group refuses to pay affiliates their cut of the ransom payments and pockets all the funds. ALPHV/Blackcat is a ransomware-as-a-service operation where affiliates are used to conduct attacks and are paid a percentage of the ransoms they generate. Affiliates typically receive around 70% of any ransoms they generate and the ransomware group takes the rest. Following the disruption of the Blackcat operation by law enforcement in December 2023, Blackcat has been trying to recruit...

Read More

235,000 Individuals Affected by Yakima Valley Radiology Data Breach

Yakima Valley Radiology has suffered a data breach that has affected 235,249 individuals. Data breaches have also been reported by Employee Benefits Corporation of America, Benefit Design Group, and Lena Pope Home. Yakima Valley Radiology Yakima Valley Radiology in Washington has recently notified 235,249 individuals that there has been unauthorized access to a limited amount of patient data. The breach was detected on August 18, 2023, and third-party forensics experts were engaged to investigate the breach. Yakima Valley Radiology said unauthorized individuals gained access to its network on August 18, 2023, and cybersecurity professionals were engaged to investigate the breach. Considerable time and effort were put into determining what information had been exposed and which individuals had been affected. On January 31, 2024, it was confirmed that “a limited amount of personal information” was removed from its network, which for some individuals included names and Social Security numbers. Those individuals have been offered complimentary credit monitoring services....

Read More

Healthcare Experiences More Third-Party Data Breaches Than Any Other Sector

A recent analysis of data breaches by Security Scorecard for its Global Third-Party Cybersecurity Breaches Report found healthcare was the worst affected industry with the highest volume of third-party breaches, followed by financial services. More than one-quarter (28%) of all breaches occurred at healthcare organizations, with financial services the second most targeted sector (16%). 35% of all reported healthcare data breaches occurred at third-party vendors, with financial services having the second highest percentage of third-party breaches (16%). Across all industry sectors, 29% of data breaches occurred at third parties. 98% of organizations had at least one relationship with a vendor that had previously experienced a data breach. The research for the study was conducted by SecurityScorecard’s Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team. The data was collected through an internally developed feed that collects information on data breaches from publicly available sources. The data corresponds to data breaches that were made public in Q4, 2023, not...

Read More
What Does it Mean To Be On the HHS OIG Exclusion List?
Mar04

What Does it Mean To Be On the HHS OIG Exclusion List?

If an individual or organization is on the HHS OIG Exclusion List, it means they been excluded from participating in Federally funded healthcare programs such as Medicare and Medicaid; and not only can they not bill the programs directly for goods or services, their goods or services cannot be acquired by any other healthcare provider that participates in a Federal healthcare program. In 1977, the Medicare-Medicaid Anti-Fraud and Abuse Amendments mandated that healthcare practitioners who were convicted of a criminal offense against Medicare or Medicaid (i.e., under the False Claims Act) should be excluded from participating in Medicare and Medicaid “for such period as [the Secretary for Health and Human Services] deems appropriate”. The exclusion clause (§1128A of the Social Security Act) was extended by the Civil Monetary Penalties Law in 1981 to cover all individuals and organizations that submit false, fraudulent, or otherwise improper claims to Medicare or Medicaid; and extended again by HIPAA in 1996 to prohibit excluded individuals and organizations from participating in any...

Read More

Cogdell Memorial Hospital Cyberattack Affects 87,000 Patients

Cyberattacks and data breaches have recently been reported by Cogdell Memorial Hospital, Hospice of Huntington, Santa Clarita Community College District, MedQ, Inc., and The Mental Health Center of North Central Alabama. Cogdell Memorial Hospital, Texas On October 10, 2023, Cogdell Memorial Hospital in Snyder, TX, identified unusual activity in its computer systems. Its network was secured, and a third-party cybersecurity firm was engaged to investigate the breach. The investigation confirmed there had been unauthorized access to its systems, and files may have been viewed or acquired that contained patients’ protected health information. The review of the affected files was completed on January 17, 2024, and it was confirmed that 86,981 individuals had been affected and had their names, addresses, dates of birth, Social Security numbers, medical record numbers, and medical treatment information exposed. Those individuals have been notified by mail and told to remain vigilant against incidents of identity theft and fraud. Cogdell Memorial Hospital said it is improving network...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist