25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Feds Share Threat Intelligence on Play Ransomware Operation

A joint cybersecurity advisory has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) about Play ransomware, aka Playcrypt. Play ransomware is believed to be a closed group rather than a ransomware-as-a-service operation and has been active since June 2022. The Play ransomware group engages in double extortion tactics, exfiltrating sensitive data before encrypting files. The stolen data is used as leverage to get victims to pay the ransom. Victims are required to contact the group via email to find out how much they must pay to prevent the release of stolen data on the group’s data leak site and to obtain the keys to decrypt data. From June 2022 until October 2023, the Play ransomware group is known to have conducted at least 300 attacks on organizations around the world, including critical infrastructure in the United States. An analysis of the operation by Trend Micro in July 2023 found that 13.9% of victims of Play...

Read More
How Often Should Passwords be Changed in the EHR System?
Dec19

How Often Should Passwords be Changed in the EHR System?

The frequency with which passwords should be changed in the EHR system depends on factors such as the current NIST recommendations when weak or reused passwords have been identified, when EHR passwords have been compromised or shared without authorization, and when a member of staff leaves the workforce. In 2010, the Office of the National Coordinator for Health Information Technology (ONC) – a branch of the Department of Health and Human Services (HHS) – published “10 Best Practices for the Small Healthcare Environment” (PDF). The publication – the ONC claimed – was “not intended to provide guidance on how to comply with HIPAA”, but rather “a first step to the effective setup of new EHR systems in a way that minimizes the risk to health information maintained in EHRs”. However, the timing of the publication was not an accident. A year earlier, Congress had passed the HITECH Act and Meaningful Use program which incentivized healthcare providers to adopt technology for creating, maintaining, and providing access to Protected Health Information. The HITECH Act also required business...

Read More
ALPHV/BlackCat Ransomware Operation Disrupted by FBI
Dec19

ALPHV/BlackCat Ransomware Operation Disrupted by FBI

The ALPHV/BlackCat ransomware group has been disrupted by the Federal Bureau of Investigation, in partnership with Europol and law enforcement agencies in Denmark, Germany, Australia, Spain, Austria, the Netherlands, and the United Kingdom, in coordination with the United States Attorney’s Office for the Southern District of Florida and the Computer Crime and Intellectual Property Section of the Department of Justice. ALPHV/BlackCat ransomware group first emerged in November 2021 and became one of the most prolific ransomware groups of recent years, second only to the LockBit ransomware group. ALPHV/BlackCat is a ransomware-as-a-service operation that uses affiliates to conduct attacks for a cut of any ransoms they generate. In its 2 years of operation, the group has claimed more than 1,000 victims worldwide and has collected hundreds of millions of dollars in ransom payments. In early December 2023, the group’s Tor negotiation and data leak sites were taken offline which led to several security researchers suggesting that the group may have been the subject of a law...

Read More

Optum Medical Care of New Jersey Settles OCR HIPAA Right of Access Investigation

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged violations of the HIPAA Privacy Rule with Optum Medical Care of New Jersey for $160,000. Optum Medical Care of New Jersey, formerly known as Riverside Medical Group and Riverside Pediatric Group, is a private multi-specialty physician group with approximately 150 locations in New Jersey and Southern Connecticut. In the Fall of 2021, OCR received six complaints from individuals who had not been provided with their records after sending a request to Optum Medical Care. The requests were to obtain a copy of an individual’s own records or requests from parents for copies of their minor children’s records. The HIPAA Privacy Rule gives individuals the right to obtain a copy of their medical records and those of their minor children. When a request is received by a HIPAA covered entity, the records must be provided within 30 calendar days, although under certain limited circumstances, a 30-day extension is possible. OCR launched an investigation in February 2022 in response to the...

Read More
Is Marketo HIPAA Compliant?
Dec19

Is Marketo HIPAA Compliant?

Marketo is HIPAA compliant and can be used to collect, store, analyze, and share Protected Health Information (PHI) between members of the same organization’s workforce or systems, provided the email marketing and lead management platform is used in Adobe’s Experience Cloud for Healthcare and its use is supported by a Business Associate Agreement. Marketo is a popular marketing automation platform that was acquired in 2018 by Adobe. At the time of the acquisition, Marketo was not HIPAA compliant because the previous vendor would not enter into a Business Associate Agreement with covered entities and business associates. However, Adobe has recently added the platform to its Experience Cloud for Healthcare and is marketing the platform as a HIPAA-Ready Service under its rebranded name “Marketo Engage”. What is a HIPAA-Ready Service? A HIPAA-Ready Service is any service in Adobe’s Experience Cloud for Healthcare that has additional features and functionalities to support HIPAA compliance. For example, under a standard Marketo Engage plan, organizations would have to purchase database...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist