25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

AHA Calls for HHS to Drop Website Tracking Technology Rule
Oct02

AHA Calls for HHS to Drop Website Tracking Technology Rule

The American Hospital Association (AHA) has called for Congress to urge the Department of Health and Human Services to withdraw its new rule that prohibits HIPAA-regulated entities from using online tracking technologies on their websites and applications. The AHA represents more than 5,000 member hospitals, health systems, and other healthcare organizations, and its clinician partners include more than 270,000 affiliated physicians and 2 million nurses and other caregivers. The AHA requested the withdrawal of the rule in its response to Sen. Bill Cassidy’s recent request for information on health information privacy and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Online tracking technologies include Google Analytics and Meta Pixel code, which are used by hospitals for collecting and analyzing information about how individuals interact on their websites. The information collected through these tools helps hospitals to make improvements to their online portals and provide relevant and reliable health information to their communities. A study conducted in...

Read More

Amerita Named in Class Action Lawsuit Over Data Breach at PharMerica

The specialty infusion company Amerita is facing a class action lawsuit over a recent cyberattack and data breach at its parent company, PharMerica. On September 5, 2023, suspicious activity was detected within the computer networks of PharMerica and Amerita. The forensic investigation confirmed that an unauthorized third party gained access to its systems between March 12 and March 13, 2023, and potentially accessed the sensitive data of 5.8 million individuals. PharMerica reported the breach on behalf of itself and its parent company, BrightSpring Health Services. The personal and protected health information of almost 220,000 Amerita patients was also compromised in the attack, including names, addresses, diagnoses, medications, and health insurance information. The Money Message ransomware group claimed responsibility for the attack and claimed on its data leak site to have stolen 4.7 terabytes of data, and then proceeded to leak certain files, some of which contained patient data. Class action lawsuits have already been filed against PharMerica over the data breach, and now a...

Read More
Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors
Oct02

Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new cybersecurity awareness program – Secure Our World – through which the agency will be promoting behavioral change across the nation. The aim of the campaign is to get individuals, families, and small- to medium-sized businesses to take action every day to protect themselves while online and when using connected devices. The new campaign was launched as part of Cybersecurity Awareness Month, which this year focuses on four key behaviors that can greatly improve security when they are consistently adopted across an organization: Using strong passwords and a password manager Implementing multifactor authentication Learning how to recognize phishing and reporting phishing attempts Updating software promptly While organizations should consider transitioning to passwordless authentication, until it can be fully implemented it is vital to ensure that password best practices are followed. Strong, unique passwords should be sent for each account, with passwords consisting of random letters, numbers, and special...

Read More

79% Of Healthcare Organizations Experienced an API Security Incident in the Past 12 Months

78% of healthcare organizations experienced an Application Programming Interface (API) security incident in the past 12 months, up 9% from 2022, according to a new survey from Noname Security. APIs continue to pose significant risks to organizations and security incidents are increasing, especially in industries that store large volumes of personally identifiable information such as healthcare, eCommerce, and financial services, which saw the biggest increases in attacks. Healthcare experienced the biggest increase in API security incidents out of the 6 industries represented in the study and is the second most likely industry to experience an API security incident, behind financial services. Healthcare organizations need to share information internally between different medical systems, communicate data to other healthcare organizations, and share medical records with patients’ personal health and well-being devices, with data sharing facilitated through APIs. While APIs facilitate compliant data sharing, the lack of data standards across the industry and multiple siloed...

Read More
FDA Publishes New Guidance on Medical Device Cybersecurity Requirements
Sep29

FDA Publishes New Guidance on Medical Device Cybersecurity Requirements

The U.S. Food and Drug Administration (FDA) has published new guidance on its requirement for medical device manufacturers to include details of the cybersecurity measures that have been implemented for new products in premarket submissions. Medical devices with wireless, internet, and network-connected capabilities are increasingly being used in healthcare and while these devices have helped to improve the care provided to patients, they have the potential to threaten patient safety if they lack appropriate cybersecurity protections. Cyberattacks on the healthcare industry have increased, with advanced persistent threat actors and cybercriminal groups actively targeting the sector. Many attacks have rendered medical devices inoperable and have forced critical IT systems to be shut down which have clinical impacts that put patient safety at risk, such as delaying diagnoses and treatments. “Increased connectivity has resulted in individual devices operating as single elements of larger medical device systems. These systems can include healthcare facility networks, other devices, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist