NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Sen. Cassidy Proposes Legislative Updates to Improve Health Data Privacy
Mar07

Sen. Cassidy Proposes Legislative Updates to Improve Health Data Privacy

Senator Bill Cassidy (R-LA), Ranking Member of the U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee, has published a white paper that proposes updates to the Health Insurance Portability and Accountability Act (HIPAA) to improve privacy protections for health information and urges Congress to take action to expand privacy protections for all health data. The white paper – Strengthening Health Data Privacy for Americans: Addressing the Challenges of the Modern Era – follows Sen. Cassidy’s September 2023 request for information from healthcare industry stakeholders on the current state of HIPAA, how best to enhance health data privacy, and ensure that health data collected by entities that are not bound by HIPAA is also protected. New technologies are being introduced in healthcare and interoperability of health data is increasing, which is helping to improve care and patients’ access to their health information; however, new technology has increased the attack surface and improved access can easily lead to increased vulnerability for inappropriate data...

Read More

Multiple Class Action Lawsuits Filed in Response to Change Healthcare Ransomware Attack

Change Healthcare experienced a Blackcat ransomware attack on February 21, 2024, and is still recovering from the incident, with many systems still offline more than 2 weeks after the attack. The Blackcat ransomware group claimed to have stolen 6TB of data before encrypting files and the affiliate behind the attack alleged a $22 million ransom was paid by Optum to have the stolen data and obtain the decryption keys. The affiliate claims the Blackcat group stole the funds and didn’t pay, Blackcat claimed law enforcement shut down its operation, and the affiliate still has 6TB of the stolen data.  Nether Change Healthcare, Optum, of their parent company, UnitedHealth Group, have confirmed the extent of any data breach and whether a ransom was paid, only issuing a statement saying they are currently focused on the investigation and bringing their systems back online. Given the history of the Blackcat group, it is likely that the stolen data includes a significant amount of patient data, and with Change Healthcare processing around 15 billion healthcare transactions each year –...

Read More
HHS Responds to Change Healthcare Cyberattack with New Flexibilities for Affected Providers
Mar06

HHS Responds to Change Healthcare Cyberattack with New Flexibilities for Affected Providers

The Department of Health and Human Services (HHS) has issued a statement about the February 2024 Blackcat ransomware attack on UnitedHealth Group-owned Change Healthcare. The attack took more than 100 of Change Healthcare’s systems out of action, which has had far-reaching consequences for the providers that rely on those systems for checking insurance coverage, submitting claims, and getting paid. Several industry groups wrote to the HHS requesting assistance for their members, who are experiencing severe cash flow problems as they have been unable to receive payments without Change Healthcare’s systems. UnitedHealth Group has set up a temporary financial assistance program to help providers who have been unable to receive payments, but the move has been criticized by industry groups due to the limited eligibility and onerous terms. The HHS said it recognized the impact the cyberattack has had on healthcare operations nationwide and that its first priority is to help coordinate efforts to avoid disruptions to care. The HHS is in regular contact with UnitedHealth Group leadership...

Read More

Personal Touch Holding Corp. Settles Class Action Data Breach Lawsuit

Personal Touch Holding Corp. has received preliminary approval for a settlement to resolve a class action lawsuit that was filed following a January 2021 ransomware attack and data breach that affected 753,107 patients. The Lake Success, NY-based provider of home health services operates around 30 Personal Touch Home Care subsidiaries in more than half a dozen U.S. states. In January 2021, a ransomware group gained access to cloud-stored business records and the data of 29 of its subsidiaries. Initial access was gained when an employee responded to a phishing email and downloaded malware. Individuals who had previously received services from Personal Touch or its subsidiaries had their names, addresses, telephone numbers, dates of birth, Social Security numbers, financial information, including check copies, credit card numbers, bank account information, medical treatment information, health insurance card, health plan benefit numbers, and medical record numbers compromised in the attack. A class action lawsuit – Everetts v. Personal Touch Holding Corp. – was filed in...

Read More
Blackcat Affiliate Behind Change Healthcare Ransomware Claims Group Stole $22 Million Ransom
Mar05

Blackcat Affiliate Behind Change Healthcare Ransomware Claims Group Stole $22 Million Ransom

The ALPHV/Blackcat ransomware group appears to have shut down its ransomware-as-a-service (RaaS) operation, indicating there may be an imminent rebrand. The group claims to have shut down its servers, its ransomware negotiation sites are offline, and a spokesperson for the group posted a message, “Everything is off, we decide.” A status message of “GG” was later added and ALPHV/Blackcat claimed that their operation was shut down by law enforcement and said it would be selling its source code. Security experts disagree and say there is clear evidence that this is an exit scam, where the group refuses to pay affiliates their cut of the ransom payments and pockets all the funds. ALPHV/Blackcat is a ransomware-as-a-service operation where affiliates are used to conduct attacks and are paid a percentage of the ransoms they generate. Affiliates typically receive around 70% of any ransoms they generate and the ransomware group takes the rest. Following the disruption of the Blackcat operation by law enforcement in December 2023, Blackcat has been trying to recruit...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist