25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is ISO/IEC 27001 in Healthcare?
Feb06

What is ISO/IEC 27001 in Healthcare?

ISO/IEC 27001 in healthcare is a standard for managing the security of confidential data that sets out a framework for establishing, implementing, maintaining, and continually improving an information security management system. Healthcare organizations that achieve ISO/IEC 27001 certification can use the certification to demonstrate a good faith attempt to comply with the HIPAA Security Rule. Most organizations in the healthcare sector are required to comply with the HIPAA Security Rule – a set of standards and implementation specifications designed to ensure the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI). To fulfil the requirement, most organizations implement the necessary security controls and develop emergency preparedness plans. However, this approach to protecting the confidentiality, integrity, and availability of ePHI is not always effective. In its most recent report to Congress on reported breaches of unsecured PHI, HHS’ Office for Civil Rights received 64,180 notifications of data breaches affecting more than...

Read More

Emerging Ransomware Groups Disproportionately Attack Healthcare Organizations

Ransomware activity almost doubled in 2023 according to the annual GuidePoint Research and Intelligence Team (GRIT) Ransomware Report. The GRIT team identified 4,519 victims of ransomware attacks in 2023 up from 2,507 in 2022. The United States was the most targeted country accounting for 49% of attacks, with 8 out of the 10 most impacted countries located in North America or Europe. On average, 12.4 victims were posted on data leak sites each day in 2023, an 80.1% increase in public postings from 2022. While the increase was largely driven by mass exploitation campaigns, these attacks only accounted for 5% of total victims in 2023, showing there was also a significant increase in ransomware activity overall. The main ransomware players in 2023 were LockBit, Alphv, and Clop, with LockBit by far the most active, having conducted more attacks than Alphv and Clop combined. These established groups conducted 85% of attacks and used well-defined tactics. They are also drivers of innovation and tactical change across the ransomware ecosystem with emerging and developing groups tending to...

Read More

ITRC: Data Compromises Reach All-time High in 2023

There was a huge increase in data compromises in 2023 but a fall in the number of individuals affected by those incidents, according to the Identity Theft Resource Center’s (ITRC) 2023 Data Breach Report. There was a 78% increase in publicly reported data compromises in 2023 with 3,205 incidents reported which is a 72% increase from the previous high-water mark of 1,860 data compromises that was set in 2021. The increase in incidents is staggering, as ITRC CEO Eva Velasquez explained. “Just the increase from the past record high to 2023’s number is larger than the annual number of events from 2005 until 2020 (except for 2017).” Even with such a high percentage increase, the estimated number of individuals affected by data compromises fell by 16% year-over-year to 353,027,892 individuals. ITRC reports that there is a general downward trend in the number of individuals affected by data breaches as criminals are focusing on quality rather than quantity and are searching for specific information that can be used for identity-related fraud and scams rather than conducting mass attacks....

Read More
Florida Leads the Way for Affordable Care Act Plans
Feb05

Florida Leads the Way for Affordable Care Act Plans

Florida leads the way for Affordable Care Act health insurance with 4.2 million people in the state having signed up for Affordable Care Act insurance plans, according to data from the Department of Health and Human Services (HHS). A record 21.4 million people across the United States have now signed up for Affordable Care Act insurance plans, including around 5 million new registrations and 16 million people who renewed their coverage in the Open Enrollment Period from November 1, 2023, to January 16, 2024. The high number of individuals with Affordable Care Act plans in Florida is partly due to the large population and also because many people have retired and moved to the state, which means they no longer have access to employer-sponsored coverage. Florida has the third highest number of uninsured people behind Texas and California and for many Florida residents, Affordable Care Act plans are the only option available. “For decades, when it came to federal programs we could depend on to keep Americans covered, three were always top of mind – Medicare, Medicaid, and Social...

Read More

Ann & Robert H. Lurie Children’s Hospital Responding to Cyberattack

On February 1, 2024, Ann & Robert H. Lurie Children’s Hospital in Chicago announced on its website and social media channels that it is responding to a cybersecurity incident and has been forced to take its network systems offline. The cyberattack has been reported to law enforcement agencies and Lurie Children’s is working collaboratively with those agencies and third-party cybersecurity experts to investigate the attack and bring network systems back online as soon as it is safe to do so. The 360-bed acute care hospital is a leading provider of pediatric care in Illinois and one of the biggest children’s healthcare providers in the Midwest, serving 239,000 children each year. The cyberattack has disrupted normal operations and caused delays to medical care for certain patients, with ultrasound and CT scan results temporarily unavailable. Some appointments and elective procedures have been canceled to ensure patient safety. The hospital has confirmed that its emergency services are unaffected, and it is operating under a first-come, first-served approach and is...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist