25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

7 Benefits of Patient Scheduling Software
Feb09

7 Benefits of Patient Scheduling Software

Patient scheduling software is software that can be used by patients to self-book healthcare appointments, by physicians to fill their schedules, and by medical practices to synchronize patient appointments with physician and treatment room availability in order to optimize the use of time and resources. Depending on the capabilities of the software and how it is used, there can be dozens of benefits of patient scheduling software. This article discusses the seven most common benefits. How Does Patient Scheduling Software Work? Patient scheduling software most often consists of a cloud-based appointment booking platform which integrates with a healthcare organization’s practice management system and EHR system. Patients access the platform via a web link, patient portal, and/or mobile app to see what slots are available for their preferred physician – or the most relevant physician – and self-book appointments. The booking platform automatically adds each self-booked appointment to physicians’ schedules. Physicians access their schedules via a web portal or mobile app...

Read More

Penn State Health Agrees to Pay $11.7M for Improperly Billing Medicare

Penn State Health has agreed to pay $11,712,336 to resolve allegations of civil liability for submitting claims to Medicare for Annual Wellness Visit services that violated Medicare rules and regulations. Penn State Health is a five-hospital health system serving patients and communities across central Pennsylvania. Between December 2015 and November 2022, Penn State Health submitted claims to Medicare for Annual Wellness Visit services; however, those services were not supported by the medical record. When the issue was discovered by Penn State Health, corrective action was immediately taken, and the matter was voluntarily reported to the United States Attorney’s Office. The United States Attorney’s Office for the Middle District of Pennsylvania has recently announced that Penn State Health has agreed to pay $11,712,336 to resolve allegations of civil liability for improper billing. “We have worked with [the] United States Attorney’s Office and Health and Human Services Office of Inspector General on a settlement and repayment of any reimbursements that did not fully...

Read More

What is CIS Critical Security Control 18 in Healthcare?

CIS Critical Security Control 18 in healthcare – often abbreviated to CIS CSC 18, or CIS Control 18 – is the Center for Internet Security’s control for identifying weaknesses and vulnerabilities in an organization’s networks, devices, systems, and applications via penetration testing. In a healthcare environment, CIS Control 18 can help organizations better defend Protected Health Information against both internal and external threats. The CIS Critical Security Controls consist of eighteen sets of safeguards designed to resist the most common types of cyberattacks. Each set of safeguards contains up to fourteen recommended best practices depending on the nature of the Control. For example, CIS Control 3 (Data Protection) has fourteen safeguards, whereas CIS Control 18 (Penetration Testing) has just five safeguards. The eighteen sets of safeguards are not intended to be a security compliance checklist, but rather “the backbone of an effective cybersecurity ecosystem”. The Controls are sufficiently flexible to allow organizations to prioritize different Control sets – or...

Read More

Ransom Payments Exceeded $1 Billion in 2023

A new report from Chainalysis has revealed victims of ransomware attacks paid hackers $1.1 billion in 2023 to obtain the keys to unlock their data and to prevent the release of information stolen in the attacks. Last year was the first time that ransom payments exceeded $1bn and the annual total was a sizeable jump from the $567 million that was paid in 2022. These are also conservative figures, as the researchers are unaware of all of the cryptocurrency wallets used by ransomware gangs. Ransom payments have been increasing each year but there was a fall in ransom payments in 2022, which dropped from $983 million in 2021 to $567 million in 2022. The researchers believe this anomaly is linked to the Russia-Ukraine war. Many hackers changed their operations from ransomware attacks to attacks focused on espionage and destruction on Ukrainian targets and those that did continue with ransomware found it harder to get paid as Western targets became concerned about sanctions risks, given that many ransomware groups are based in Russia. In 2023, there was a shift back to ransomware attacks...

Read More
CISA Pre-Ransomware Alerts Helped 154 Healthcare Organizations Save Millions in Costs
Feb08

CISA Pre-Ransomware Alerts Helped 154 Healthcare Organizations Save Millions in Costs

In the past year, more than 150 healthcare organizations have benefitted from alerts from the Cybersecurity and Infrastructure Security Agency (CISA) about vulnerabilities and intrusions that have helped them to implement mitigations before harm has been caused. These alerts have helped victims of attacks avoid delays to patient care and saved millions of dollars in costs. In March 2023, CISA launched its Pre-Ransomware Notification Initiative which sees alerts issued if vulnerabilities are detected that are known to be actively exploited by ransomware groups to allow organizations to take action to prevent the vulnerabilities from being exploited. There is a dwell time after vulnerabilities have been exploited before ransomware is deployed, which can be a few hours to a few days. If organizations are alerted about an attack in the early stages, it is possible to block the attack before data theft and file encryption. Since launching the pilot program in January 2023, CISA has sent more than 1,200 such notifications, including to 154 healthcare organizations about early-stage...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist