25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Cloud Usage Grows But Protecting PHI Can Be a Challenge

The cloud is taking over from on-premises infrastructures, but healthcare still lags other sectors for cloud adoption. Cloud adoption has accelerated in healthcare since the pandemic as hybrid working gained significant ground. To support a hybrid workforce, improve efficiency, and cut costs, increasing numbers of healthcare organizations have started their transition to cloud infrastructure and data storage. According to Skyhigh Security’s Cloud Adoption Report – Healthcare Edition, around 50% of organizations across all industry sectors have embraced cloud-based services but the figure drops to 25% of healthcare organizations. Across all industries, healthcare organizations store the least amount of sensitive data in the cloud, with only 47% of healthcare organizations using the cloud for sensitive data storage compared to 61% across all industries. The healthcare industry collects huge volumes of sensitive data that information is extremely valuable to cybercriminals and cyberattacks have been increasing. The latest figures from the HHS’ Office for Civil Rights breach portal...

Read More

Snatch Ransomware Group Behind Mount Desert Island Hospital Cyberattack

Mount Desert Island Hospital, Inc. (MDIH) in Bay Harbor, ME, has provided a supplemental data breach notification to the Maine Attorney General about a data security incident first reported on July 17, 2023. Suspicious activity was detected within its network on May 7, 2023, and the forensic investigation determined that an unauthorized third party had access to its network between April 28, 2023, and May 7, 2023. MDIH said it initiated a review of the files on the compromised parts of its network and has now confirmed that they contained the personal and protected health information of 32,661 individuals, including 26,046 Maine residents. The exposed information included employee data: names in combination with one or more of the following data elements: date of birth, driver’s license/state identification number, Social Security number, and financial account information. Patient data was also exposed: name, address, date of birth, driver’s license/state identification number, Social Security number, financial account information, medical record number, Medicare or Medicaid...

Read More
Reader Offer: Free HIPAA Compliance Checklist
Sep22

Reader Offer: Free HIPAA Compliance Checklist

As a Covered Entity or Business Associate, it is important to be aware of which HIPAA compliance standards apply to your organization. Do you have the correct procedures in place to avoid costly data breaches, HIPAA violations, and regulatory fines? Find out now with our comprehensive HIPAA Compliance Checklist that has been compiled by leading compliance experts. Use the form to download this checklist. Non Compliance Is Not An Option HIPAA compliance standards are enforced by HHS Office of Civil Rights, the Centres for Medicare and Medicaid, and the Federal Trade...

Read More
Feds Issue Snatch Ransomware Warning Following Attack on Hospital
Sep21

Feds Issue Snatch Ransomware Warning Following Attack on Hospital

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint security advisory about Snatch ransomware. The Snatch ransomware group has recently conducted an attack on a hospital in Maine and has claimed responsibility for an attack on the Florida Department of Veterans Affairs. The group poses a significant threat to the healthcare and public health (HPH) sector. Snatch ransomware is not a new ransomware variant, having first been detected in 2018, but CISA and the FBI say the group has recently been observed using new tactics, techniques, and procedures (TTPs) in its attacks. The timing of the alert may also have been prompted by an uptick in attacks over the past few months. Snatch ransomware was used in the May 2023 attack on Mount Desert Island Hospital and the group recently leaked more than 260GB of data that was stolen in the attack, and the group has targeted several critical infrastructure sectors. Snatch ransomware is offered under the ransomware-as-a-service (RaaS) model, where affiliates are...

Read More

PurFoods Sued Over 1.2 Million-Record Mom’s Meal Data Breach

PurFoods LLC is being sued over a cyberattack that exposed the personally identifiable information (PII) and protected health information (PHI) of 1,237,681 individuals who used the services of its subsidiary, Mom’s Meals. Through Mom’s Meals, PurFoods provides a food delivery service for Medicare, Medicaid, and self-pay individuals with chronic health conditions. According to the Mom’s Meals data breach notifications, the company experienced a cyberattack that saw unauthorized individuals access its network between January 16 and February 22, 2023, and deploy software (ransomware) to encrypt files on the network. While data theft was not confirmed, the possibility of data exfiltration could not be ruled out. The review of the affected files was completed on July 10, 2023, and confirmed that names, Social Security numbers, driver’s license numbers, state identification numbers, financial account and payment card information, medical record numbers, health information, treatment information, diagnosis codes, meal categories and costs, health insurance information and patient...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist