25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

CitrixBleed Vulnerability Requires Urgent Action as Ransomware Groups Scale Up Attacks

Concern is growing as ransomware groups ramp up exploitation of a critical vulnerability in NetScaler ADS (formerly Citrix ADC) and NetScaler Gateway (Citrix Gateway) devices, dubbed CitrixBleed. Citrix issued a security advisory about the vulnerability on October 10, 2023, and issued a patch to correct the flaw, which can be exploited to bypass password protection and multifactor authentication. The buffer overflow vulnerability is tracked as CVE-2023-4966 and has a CVSS severity score of 9.4 out of 10. The vulnerability appears to have been exploited in the wild since August 2023. The vulnerability is easy to exploit and allows threat actors to take over legitimate user sessions. Once initial access has been gained, threat actors can elevate privileges, harvest credentials, move laterally, and access sensitive data and resources. The vulnerability affects the following NetScaler ADC and Gateway versions: NetScaler ADC and NetScaler Gateway 14.1-8.50 and later releases NetScaler ADC and NetScaler Gateway  13.1-49.15 and later releases of 13.1 NetScaler ADC and NetScaler Gateway...

Read More

When Was HIPAA Enacted?

HIPAA was enacted at various stages following the passage of the Health Insurance Portability and Accountability Act in 1996, with some measures effective immediately, others enacted within 90 days, and those relating to the privacy and security of health information taking several years.   There are several reasons for there being different dates when HIPAA was enacted. The first is that HIPAA covered more than just the privacy and security of individually identifiable health information. It introduced measures to make health insurance more accessible, portable, and renewable, and enforced changes on the healthcare and health insurance industries to reduce fraud and abuse. Additionally, HIPAA was not an entirely new law. In order to (for example) make health insurance more accessible, portable, and renewable, it was necessary to amend existing laws such as the Employee Retirement Income Security Act (ERISA) and the Social Security Act. Some amendments to these laws were enacted immediately, while others took effect sixty or ninety days later. Most of the new provisions in HIPAA...

Read More
Is Microsoft OneNote HIPAA Compliant?
Dec05

Is Microsoft OneNote HIPAA Compliant?

Microsoft OneNote is HIPAA compliant and can be used to create, store, and share Protected Health Information (PHI) when an organization subscribes to a Microsoft 365 plan that supports HIPAA compliance and the OneNote app if configured to comply with the Security Rule. If these conditions are not met, organizations can still use OneNote, but not to create, store, or share PHI. Microsoft OneNote is a digital note taking application that can be used on smartphones, tablets, and desktop computers. The application can be used to create, store, and share to do lists, screen grabs, and audio files. Healthcare professionals will no doubt see the appeal of OneNote, but care must be taken when using the application to avoid violations of HIPAA Rules. Before any software or cloud platform can be used in connection with any electronic PHI (ePHI), it is first necessary to enter into a business associate agreement with the software/platform provider. If ePHI is to be used, adding it to the application or sharing data through it means the software/platform provider will be classed as a business...

Read More
Is Signal HIPAA Compliant?
Dec05

Is Signal HIPAA Compliant?

Signal is not a HIPAA compliant messaging solution and cannot be used to collect, store, or transmit electronic PHI because user accounts are set up “per user” – making it impossible to apply most administrative and activity monitoring safeguards required by the Security Rule. For this reason, Signal will not enter into a Business Associate Agreement with HIPAA covered entities. HIPAA Compliance and Instant Messaging Platforms Instant messaging platforms are convenient and make it easy to communicate with patients; however, if the platforms are used to transmit electronic protected health information (ePHI), they must be HIPAA compliant unless a patient exercises their Privacy Rule right to receive healthcare communications via a non-compliant channel. That means appropriate technical, administrative, and physical safeguards must be implemented to ensure the confidentiality, integrity, and availability of any transmitted or stored ePHI. Signal, like several other instant messaging apps, has a strong focus on privacy and offers end-to-end encryption of messages. Signal also...

Read More

East River Medical Imaging Cyberattack Affects 606,000 Patients

East River Medical Imaging in New York has started notifying 605,809 patients that some of their protected health information has been exposed or stolen in a cyberattack that was detected on September 20, 2023. The network was immediately taken offline, and a forensic investigation was launched to determine the nature and scope of the incident. The investigation determined there had been unauthorized access to its network between August 31, 2023, and September 20, 2023, and during that time, files containing patient data had been accessed and copied from its network. The compromised information varied from individual to individual and may have included names, contact information, insurance information, exam and/or procedure information, referring physician names, imaging results, and/or Social Security numbers. Employee data was also compromised, including names, contact information, financial account information, Social Security numbers, and/or driver’s license numbers. East River Medical Imaging said it has enhanced its network monitoring capabilities and will continue to assess...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist