25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Russian National Sanctioned for Medibank Ransomware Attack
Jan24

Russian National Sanctioned for Medibank Ransomware Attack

A Russian national who was involved in a ransomware attack on the Australian health insurance provider Medibank in 2022 has been sanctioned by the governments on Australia, the United States, and the United Kingdom. Alexander Ermakov (aka blade_runner, GistaveDore, GustaveDore, or JimJones), 33, is believed to have been a member of the now-disbanded ransomware group REvil. REvil was one of the most notorious cybercriminal groups until July 2021 when the group ceased operations and disappeared. Prior to that, the group was a ransomware-as-a-service group that encrypted appropriately 175,000 computers and was paid an estimated $200 million in ransom payments from its attacks. In October 2022, REvil gained access to the Medibank network and stole the data of approximately 9.7 million of its customers and then used ransomware to encrypt files. The stolen data included names, dates of birth, Medicare numbers, and highly sensitive medical information including mental health, sexual health and drug use data. As a Russian national, Ermakov is unlikely to face justice for the Revil attacks...

Read More

Lincare Holdings Proposes $7.25 Million Settlement to Resolve Data Breach Lawsuit

A $7.25 million settlement has been proposed to resolve a class action lawsuit – In re: Lincare Holdings Inc. Data Breach Litigation – filed against Lincare Holdings over a September 2021 data breach that affected 2,918,444 individuals. Lincare Holdings is a provider of in-home respiratory care and equipment. In September 2021, unauthorized activity was detected within its network and the forensic investigation confirmed an unauthorized third party had gained access to files containing patient data. The exposed HIPAA protected health information included names, addresses, Lincare account numbers, dates of birth, treatment information, provider names, dates of service, diagnosis and procedure information, account or record numbers, health insurance information, and prescription information, and for a small number of affected individuals, Social Security numbers. Legal action was taken by the affected individuals who alleged that Lincare Holdings was negligent for failing to implement reasonable and appropriate cybersecurity measures, and had those measures been...

Read More

Patch Fortra GoAnywhere Now: Exploit Code Released for Critical Flaw

Fortra has disclosed and patched a critical vulnerability in its GoAnywhere Managed File Transfer (MFT) solution. The vulnerability – CVE-2024-0204 – is an authentication bypass bug due to a path traversal weakness. If exploited, an unauthenticated user can create a new admin user via the administration portal and remotely take control of the customer’s environment and gain access to their network. The vulnerability has a CVSS severity score of 9.8 out of 10. Fortra explained in its security advisory that the vulnerability affects all versions of GoANywhere MFT prior to 7.4.1. All users of the file transfer solution should ensure they update to version 7.4.1 as soon as possible. If it is not possible to immediately upgrade, Fortra has suggested temporary workarounds. For non-container deployments, users should delete the InitialAccountSetup.xhtml file in the install directory and restart the services. For container deployments, the InitialAccountSetup.xhtml file should be deleted and replaced with an empty file, followed by a restart. Managed file transfer solutions are...

Read More
Is Intercom HIPAA Compliant?
Jan24

Is Intercom HIPAA Compliant?

Intercom is HIPAA compliant and can be used to collect, store, and process electronic Protected Health Information (ePHI) provided organizations subscribe to an “Expert” business plan and agree to the terms of Intercom’s Business Associate Agreement. Thereafter, it is important the software is configured to support HIPAA compliance and that users are trained to operate Intercom in compliance with HIPAA. Intercom is a customer service and engagement solution that enables organizations to provide top-quality support for customers via multiple communication channels. Depending on which business plan an organization subscribes to, the platform can provide proactive support with in-context messaging, an AI-powered workspace, and automated workflows. At the highest “Expert” level, Intercom includes advanced collaboration, security, and reporting tools for large support teams. For organizations in the healthcare sector, customer service and engagement solutions such as Intercom can significantly reduce the volume of resources required to run an efficient support center while providing...

Read More
What is a Healthcare Compliance Plan?
Jan24

What is a Healthcare Compliance Plan?

A healthcare compliance plan is a document that outlines the compliance obligations of a healthcare organization, lists what measures already exist to fulfil the compliance obligations, identifies gaps in compliance, and determines what measures are required to fill the gaps. A healthcare compliance plan is a valuable tool for organizations subject to multiple federal, state, local, and industry regulations because it can deduplicate compliance requirements and enhance compliance efficiency. Most healthcare organizations are subject to multiple federal, state, local, and industry regulations. In addition, most comply with voluntary standards to achieve or maintain accreditation. If an organization attempted to comply with each regulation and standard individually, it would likely never likely achieve a state of compliance due to number of duplicated regulations, provisions that preempt provisions of other regulations, multiple training requirements, and the speed at which regulations and standards change. A healthcare compliance plan can simplify compliance planning by combining...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist