25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

CarePointe ENT Settles HIPAA Lawsuit with Indiana Attorney General
Dec06

CarePointe ENT Settles HIPAA Lawsuit with Indiana Attorney General

In late September 2023, Indiana Attorney General Todd Rokita filed a lawsuit against CarePointe ENT over a ransomware attack and data breach that affected 48,742 individuals. A settlement has been reached that will see CarePointe pay $125,000 to resolve alleged violations of the Health Insurance Portability and Accountability (HIPAA) Act and state data privacy and security laws. CarePointe ENT operates three ear, nose, throat, sinus, and hearing centers in Merrillville, Munster & Hobart in Northwest Indiana. On June 25, 2021, CarePointe ENT experienced a ransomware attack which resulted in files being encrypted and data being exfiltrated. The stolen data included names, addresses, dates of birth, Social Security numbers, medical insurance information, and health information. Affected individuals were notified about the data breach in August 2021. AG Rokita launched an investigation into the attack to determine if CarePointe ENT had complied with its obligations under HIPAA and state laws. Despite claiming that it was committed to safeguarding patient information, CarePointe ENT...

Read More
Is Google Sheets HIPAA Compliant?
Dec06

Is Google Sheets HIPAA Compliant?

Google Sheets is HIPAA compliant and can be used to create, manage, and share spreadsheets containing Protected Health Information (PHI) provided organizations subscribe to a Google Workspace plan that supports HIPAA compliance and Google Drive is configured to control access to files saved as Google Sheets. In addition, system administrators are required to review and accept Google’s Business Associate Addendum to the Workspace Service Agreement. Under HIPAA Rules, healthcare organizations are required to implement safeguards to ensure the confidentiality, integrity, and availability of PHI. While it is straightforward to implement controls internally to keep data secure, oftentimes third parties are contracted to provide services that require access to PHI. They too must abide by HIPAA Rules covering privacy, security, and breach notifications. A third-party that requires access to PHI – or copies of health data – to perform services on behalf of a covered entity is considered a business associate. A covered entity and business associate must enter into a contract – a...

Read More
Is doxy.me HIPAA Compliant?
Dec06

Is doxy.me HIPAA Compliant?

On paper, doxy.me is HIPAA compliant and – subject to an organization subscribing to a business plan that supports HIPAA compliance – can be used to create, receive, store, and share Protected Health Information. However, concerns exist about the vendor’s understanding of HIPAA compliance and that the platform is unreliable for delivering quality patient care. Doxy.me is telemedicine platform that enables healthcare professionals to communicate remotely with patients via video, audio, and secure text messaging. The platform has been designed for ease-of-use, and – when subscribed to the premium service – healthcare professionals can take advantage of text and email notifications, secure payments, screen sharing, and group calling. In the context of is doxy.me HIPAA compliant, the perception a user might get from reviewing the HIPAA compliant video conferencing page on the doxy.me website is that it is. The page provides an explanation of the HIPAA requirements (albeit incorrect) and a list of capabilities that appears to fulfil these requirements. Doxy.me will also...

Read More

Urgent Action Required to Address Critical ownCloud Vulnerabilities

Three critical vulnerabilities in the ownCloud platform have been identified, one of which is being actively exploited. Urgent action is required to address the vulnerabilities to protect sensitive networks and sensitive data. The ownCloud platform is used extensively in healthcare for storing, synchronizing, and sharing files and collaborating and consolidating work processes. As such, the platform is a prime target for malicious actors as it allows them to access highly sensitive data. The Clop hacking groups demonstrated how serious vulnerabilities in file sharing platforms can be, having mass exploited vulnerabilities in Fortra’s GoAnywhere MFT and Progress Software’s MOVEit Transfer solution earlier this year. Security advisories were issued by ownCloud on November 21, 2023, about three vulnerabilities, the most serious of which has a maximum CVSS v3.1 severity score of 10. The remaining two vulnerabilities have been assigned CVSS scores of 9.8 and 9. Evidence of active exploitation of the flaws was identified by the cybersecurity firm Greynoise from November 25, 2023, with...

Read More

CitrixBleed Vulnerability Requires Urgent Action as Ransomware Groups Scale Up Attacks

Concern is growing as ransomware groups ramp up exploitation of a critical vulnerability in NetScaler ADS (formerly Citrix ADC) and NetScaler Gateway (Citrix Gateway) devices, dubbed CitrixBleed. Citrix issued a security advisory about the vulnerability on October 10, 2023, and issued a patch to correct the flaw, which can be exploited to bypass password protection and multifactor authentication. The buffer overflow vulnerability is tracked as CVE-2023-4966 and has a CVSS severity score of 9.4 out of 10. The vulnerability appears to have been exploited in the wild since August 2023. The vulnerability is easy to exploit and allows threat actors to take over legitimate user sessions. Once initial access has been gained, threat actors can elevate privileges, harvest credentials, move laterally, and access sensitive data and resources. The vulnerability affects the following NetScaler ADC and Gateway versions: NetScaler ADC and NetScaler Gateway 14.1-8.50 and later releases NetScaler ADC and NetScaler Gateway  13.1-49.15 and later releases of 13.1 NetScaler ADC and NetScaler Gateway...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist