25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Ransomware Attacks Reported by Foursquare Healthcare and Hi-School Pharmacy

Foursquare Healthcare Ltd, a Rockwall, TX-based operator of short-term rehabilitation, skilled nursing, and long-term nursing care facilities has recently confirmed it experienced a ransomware attack in September. The ransomware attack was detected on September 27, 2023, and the forensic investigation confirmed the attackers accessed its network between September 27, 2023, and September 29, 2023, and acquired certain files that contained employee and patient information. The information in the files varied from individual to individual and included names along with one or more of the following: address, billing information, Social Security number, banking information, and clinical information regarding care received at its clinics. The attack did not cause any material disruption to Foursquare care or services and no evidence has been found to indicate that any of the stolen data has been misused for identity theft or fraud. Foursquare said it has received assurances that all of the stolen data has been deleted. That usually, but not always, means the ransom was paid. Foursquare...

Read More

9 Prime Healthcare Hospitals Affected by MOVEit Data Breach

Ontario, CA-based Prime Healthcare has been affected by a data breach at its revenue cycle management vendor, CBIZ KA. The vendor used Progress Software’s MOVEit Transfer solution, a zero-day vulnerability in which was exploited by the Clop hacking group in late May 2023. Prime Healthcare received a copy of the stolen files from CBIZ KA on September 20, 2023, and has confirmed that they contained names in combination with one or more of the following: date of birth, address, medical record number, Social Security Number, admission date, and discharge date. Prime Healthcare operates 45 hospitals, although only 9 were affected: Saint Clare’s Hospital, Saint Michael’s Medical Center, and St. Mary’s General Hospital in New Jersey, Roxborough Memorial Hospital, Lower Bucks Hospital, and Suburban Community Hospital in Pennsylvania, Garden City Hospital and Lake Huron Medical Center in Michigan, and Landmark Medical Center in Rhode Island. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity protection...

Read More

23andMe Updates Terms of Service to Prevent Class Action Lawsuits

23andMe has updated its terms and conditions in an attempt to prevent its customers from joining class action lawsuits following a massive data breach that affected 6.9 million of its customers. In October 2023, a collection of the data was uploaded to a dark web forum that was allegedly stolen from 23andMe. The dataset contained information on around 1 million Ashkenazi Jews and 100,000 individuals of Chinese descent, then the hacker advertised a further dataset a couple of weeks later that contained the information of a further 4.1 million individuals. 23andMe investigated and determined that approximately 14,000 accounts were compromised in a credential stuffing attack, which was made possible due to password reuse by those customers. The compromised accounts were used to access the ancestry data of 6.9 million users through the DNA Relatives feature (5.5 million users) and the Family Tree feature (1.4 million users). Per its financial reports, 23andMe has around 14 million customers, which means almost half were affected by the data breach. 23andMe maintains that there was no...

Read More
Is Google Keep HIPAA Compliant?
Dec08

Is Google Keep HIPAA Compliant?

Google Keep is HIPAA compliant and can be used to create notes containing Protected Health Information and share them via Google Dive provided organizations subscribe to a Google Workspace plan that supports HIPAA compliance and Google Drive is configured to control access to notes saved in Google Keep. In addition, it will be necessary to review and accept Google’s Business Associate Addendum to the Workspace Service Agreement. Many healthcare professionals would like to use an electronic note taking app but are concerned about potential HIPAA violations. These services are certainly useful and can help to improve efficiency. If you are looking for a HIPAA compliant note application, Google Keep is a natural choice. Google Keep enables notes to be taken on one device which can be subsequently be accessed on multiple devices. The notes can include include voice notes, photos, and other files. Information created on Google Keep can be accessed across multiple devices via Google Drive. Google Drive is part of Workspace (formerly G Suite) which supports HIPAA compliance for all...

Read More
OCR Imposes First HIPAA Penalty in a Phishing Attack Investigation
Dec07

OCR Imposes First HIPAA Penalty in a Phishing Attack Investigation

The HHS’ Office for Civil Rights (OCR) has agreed to settle a landmark cyber investigation and has imposed its first financial penalty under the Health Insurance Portability and Accountability Act (HIPAA) to resolve Security Rule violations related to a phishing attack. Lafourche Medical Group, a Louisiana-based medical group specializing in emergency medicine, occupational medicine, and laboratory testing, reported a data breach to OCR on May 28, 2021, involving the protected health information (PHI) of up to 34,862 individuals. According to the breach notification, a hacker gained access to the email account of one of its owners on March 30, 2021, following a response to a phishing email that spoofed one of the medical group’s owners. The threat actor gained access to the Microsoft 365 environment, which contained patient data. Lafourche Medical Group said that because of the size of the email system, it was not possible to determine all patient information that had been exposed so notification letters were mailed to all patients. The exposed data included names, addresses, dates...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist