25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

71% of Ransomware Attack Victims Refuse to Pay the Ransom

The latest data from the ransomware remediation firm, Coveware, shows the number of victims of ransomware attacks choosing to pay the ransom has fallen to a record low. At the start of 2019, 85% of victims of ransomware attacks paid a ransom following an attack, by the middle of 2021 the percentage had fallen to 46%, and in Q4, 2023, only 29% of victims paid the ransom. In 2019, ransomware groups started engaging in double extortion tactics, where access is gained to victims’ networks and data is exfiltrated before file encryption. Ransom payments are required to obtain the keys to decrypt files and to prevent stolen data from being leaked or sold. For many victims, the main reason for paying the ransom was to prevent a data leak rather than to obtain the keys to decrypt files. Coveware reports that in ransomware attacks involving data theft, in Q3, 2023, only 26% of victims paid the ransom. There are many reasons behind the steady decline in ransom payments. One of the main factors is better preparedness, such as ensuring that a backup is made of all sensitive data and the backup...

Read More
Is Mailchimp HIPAA Compliant?
Jan30

Is Mailchimp HIPAA Compliant?

Mailchimp is not HIPAA compliant because the email service provider is unable to provide the required satisfactory assurances that it will appropriately safeguard Protected Health Information (PHI), which prohibits covered entities and business associates entering into a Business Associate Agreement and disclosing PHI via the Mailchimp platform. Mailchimp is an automated email marketing platform that can be used to send marketing emails, newsletters, and other information emails to mailing lists. It is an effective mass communication solution for covered entities and business associates with large mailing lists who want to keep internal mail servers free for operational purposes. However, the platform cannot be used to collect, maintain, or transmit PHI, as Mailchimp states in its Terms of Use: “You are responsible for determining whether the Service is appropriate for you, in light of your obligations under any regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), […] or other applicable laws. If you are subject to regulations (such as HIPAA) and...

Read More

Keenan & Associates Data Breach Affects More Than 1.5 Million Individuals

The Torrance, CA-based insurance broker Keenan & Associates has recently reported a cybersecurity incident to the Maine Attorney General that has affected 1,509,616 individuals. Keenan & Associates is part of AssuredPartners NL, one of the largest brokerage firms in the United States. The company has clients across a variety of industries, including healthcare and the public sector, and is the third-party administrator of Prime Healthcare’s employee benefit health plan. Prime Healthcare was one of the affected clients. The cybersecurity incident was detected on Sunday, August 27, 2023, when some of its network servers were disrupted. Action was immediately taken to contain the attack and isolate the affected network servers and third-party cybersecurity experts were engaged to investigate to determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that there had been unauthorized access to its internal systems at various points between August 21, 2023, and August 27, 2023, and during that time, certain files were exfiltrated from its...

Read More

314,000 Patients Affected by Cyberattack on CompleteCare Health Network

CompleteCare Health Network, a health system serving patients in southern New Jersey, has recently confirmed that the protected health information of 313,973 patients has potentially been compromised in an October 2023 ransomware attack. An unauthorized third party gained access to certain CompleteCare Health Network computer systems and attempted to use ransomware to encrypt files. CompleteCare Health Network said this was a sophisticated ransomware attack that was detected and stopped on or around October 12, 2023. Third-party cybersecurity experts were engaged to investigate the attack and determine the nature of any unauthorized activity, and whether any patient data was involved. The substitute breach notice on the CompleteCare Health Network states, “Please know that we have taken steps to ensure your data will not be further published or distributed,” which appears to confirm that there was data exfiltration, the threat group behind the attack threatened to publish the data, and payment was made to prevent that outcome. CompleteCare Health Network conducted a review of all...

Read More

Plaza Radiology Data Breach Affects Up to 569,000 Patients

Plaza Radiology, which does business as Chattanooga Imaging across several locations in Tennessee and North Georgia, has suffered a cyberattack and data breach that has affected up to 569,000 patients. Plaza Radiology identified the cyberattack on October 21, 2023, but did not disclose any details about the nature of the attack, other than stating that the initial results of the forensic investigation confirmed there had been unauthorized access to a small number of files on its network that contained patient information. The analysis of the results from the forensic investigation is ongoing and, at this stage, there have been no reports of any actual or attempted misuse of patient data. Plaza Radiology reported the data breach to the HHS’ Office for Civil Rights on December 20, 2023, and said it will be mailing individual notification letters to the affected patients when the specific individuals affected have been identified and the types of data involved have been determined. Legal counsel for Plaza Radiology confirmed that several steps have been taken in response to the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist