NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS Updates Security Risk Assessment Tool
Sep11

HHS Updates Security Risk Assessment Tool

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule. The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule. The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk...

Read More
Orthanc DICOM Server Vulnerability Can Lead to Denial of Service
Sep11

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack. Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments. It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency. An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition. The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 7.2. The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency. The vulnerability affects all Orthanc DICOM Server prior to 1.13.0. Orthanc...

Read More
Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits
Sep11

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information. Central Maine Medical Center Data Breach Settlement Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach. The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals. Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single...

Read More
High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect
Sep10

High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect

Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration. The vulnerabilities were identified by security researcher Abhinav Agarwal using autonomous agents running his published methodology on AI-assisted vulnerability discovery. “Mirth Connect is effectively a switchboard between healthcare systems. It can sit between lab systems, imaging systems, databases, and clinical applications, so a vulnerability in the integration layer can expose much more than one isolated application,” Agarwal told The HIPAA Journal. A potential problem is that healthcare organizations may not know that they have a...

Read More
Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data
Sep10

Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data. The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist