25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

November 8, 2023, Healthcare Data Breach Round-Up
Nov08

November 8, 2023, Healthcare Data Breach Round-Up

Mulkay Cardiology Consultants at Holy Name Medical Center has recently confirmed that it fell victim to a ransomware attack. The attack was detected on September 5, 2023, when files on its network were encrypted. According to the breach notice, Mulkay was able to rebuild its systems and recover the encrypted files from backups. Third-party forensics experts were engaged to investigate the breach and determined that its systems were compromised between September 1, 2023, and September 5, 2023, and during that time, files were exfiltrated that contained personal and protected health information. The compromised information included names, addresses, dates of birth, Social Security numbers, driver’s license numbers or state IDs, medical treatment information, and health insurance information. Mulkay said it has enhanced its technical safeguards to prevent similar incidents in the future. Affected individuals have been notified and offered complimentary credit monitoring services. The breach was reported to the Maine Attorney General and HHS’ Office for Civil Rights as involving...

Read More

BlackCat Ransomware Group Claims Responsibility for Attack on Henry Schein

The BlackCat (ALPHV) ransomware group has claimed responsibility for an attack on Henry Schein, a Fortune 500 distributor of dental and medical supplies and provider of practice management software and solutions for healthcare providers. Henry Schein confirmed on October 15, 2023, that it had experienced a cybersecurity incident, which was detected on October 14, 2023. The incident affected a portion of its manufacturing and distribution business, which caused temporary disruption to its business operations.  More than three weeks on and the company is still experiencing technical difficulties with its website and webshop.  Third-party cybersecurity consultants have been engaged to investigate the breach and the data impact, and law enforcement has been notified. The incident is still being investigated; however, it has been determined that users of its client management software were unaffected. In a November 13, 2023, notice to its customers, Henry Schein said “We do not have all the details of what data may have been compromised. Customer and personal (sic) identifiable...

Read More
OSHA Violation Cases in Healthcare
Nov07

OSHA Violation Cases in Healthcare

Considering the size of the healthcare industry and the potential number of workplace hazards, there are relatively few OSHA violation cases in healthcare. For example, in the year to September 2023, the Occupational Safety and Health Administration issued 626 citations for OSHA violation cases in healthcare. The top ten reasons for citations in the health care and social assistance NAICS category (where indicated) were violations of: The bloodborne pathogen standard The hazard communication standard The respiratory protection standard The control of hazardous energy standard OSHA’s form filling requirements The formaldehyde standard OSHA’s general requirements The asbestos standard The wiring methods, components, and equipment standard. The exit route standard (maintenance, safeguards, and features) OSHA does not publish citation-by-citation information because of the volume of citations issued each year across all industries. Federal OSHA – not including state plans – issued 45,950 citations nationwide in the year to September 2023. Nonetheless, it is possible to tell from...

Read More
Is FaceTime HIPAA Compliant?
Nov07

Is FaceTime HIPAA Compliant?

Many sources suggest Facetime is not HIPAA compliant because Apple will not enter into a Business Associate Agreement with covered entities to use the video and audio service to transmit Protected Health Information. However, is it necessary to enter into a Business Associate Agreement to use Facetime in compliance with HIPAA? Will Apple Sign A BAA for FaceTime? An extensive search of the Apple website has revealed no indication that Apple will sign a business associate agreement with healthcare organizations for any of its services. The only mention of its services in relation to HIPAA-covered entities is in relation to iCloud, which Apple clearly states should not be used by healthcare providers or their business associates to create, receive, maintain or transmit PHI. Since Apple is not prepared to sign a business associate agreement for FaceTime, that would indicate FaceTime is not a HIPAA compliant service. However, business associate agreements only need to be signed by business associates. So, is Apple a business associate? The HIPAA Conduit Exception Rule The HIPAA Conduit...

Read More

BlackSuit Ransomware Poses a Credible Threat to the HPH Sector

The Health Sector Cybersecurity Coordination Center (HC3) has published an analyst note about BlackSuit ransomware, a new ransomware group believed to pose a credible threat to the healthcare and public health (HPH) sector. Security researchers have identified several similarities between BlackSuit ransomware and Royal ransomware, with the latter group having actively targeted the HPH sector like the Conti ransomware group that Royal is believed to have replaced. BlackSuit has already been used in at least one attack on the HPH sector in October this year, so it is fair to assume that BlackSuit will be used in further attacks on the sector. That attack was on a provider of medical scans and radiology services to more than 1,000 hospitals in 48 states. Like many other ransomware operations, BlackSuit ransomware is used in double extortion attacks, where sensitive data is exfiltrated before file encryption and ransoms must be paid to prevent the release of the stolen data as well as to decrypt the encrypted files. So far, BlackSuit ransomware has only been used in a limited number of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist