25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

August 2023 Healthcare Data Breach Report
Sep20

August 2023 Healthcare Data Breach Report

There was a 21.4% month-over-month increase in healthcare data breaches in August. 68 data breaches of 500 or more records were reported to the HHS’ Office for Civil Rights, which makes August the second-worst month of the year for data breaches, with reported data breaches reported well above the 2023 monthly average of 58.2 data breaches per month. 463 healthcare data breaches have been reported this year up to August 31, 2023 – a slight increase from the 460 data breaches reported in the corresponding period last year. While there was a 34.3% month-over-month fall in the number of breached records, July’s total was exceptionally high. In August, almost 12 million records were reported as having been exposed or stolen, which is well above the 2023 average of 7.49 million records a month. So far in 2023, the records of 71,479,579 individuals have been exposed or stolen. At this time last year, 29.27 million records had been breached, and 2022 was a bad year for breached healthcare data. If healthcare data breaches continue to occur at the scale seen in the first 8 months of...

Read More
What Does OSHA Stand for in Medical Terms?
Sep19

What Does OSHA Stand for in Medical Terms?

What OSHA stands for in medical terms is the standards adopted by the Occupational Safety and Health Administration to increase the safety and health of employees in the healthcare industry. There can be many benefits of OSHA compliance for medical facilities. These benefits include: A reduction in workplace injuries and illnesses Increased workforce productivity Increased workforce retention Easier workforce recruitment Protection against liability Lower insurance costs Compliance with other standards “Another Set of Standards That Have to be Complied With” You can understand the frustration of a healthcare compliance team who have got everything in place to comply with HIPAA, CMS’ Conditions for Participation in Medicare, ADA, the 21st Century Cures Act, the FD&C Act, and a host of other state and federal healthcare regulations, when a member of the legal team asks the question “What does OSHA stand for in medical terms?”. The appropriate answer to the question is that OSHA stands for the Occupational Safety and Health Administration – an agency of the Department of...

Read More
Lazarus Group Actively Exploiting ManageEngine Vulnerability in Attacks on Healthcare Organizations
Sep19

Lazarus Group Actively Exploiting ManageEngine Vulnerability in Attacks on Healthcare Organizations

Healthcare organizations in the United States have been warned that a vulnerability in Zoho’s ManageEngine products is being actively exploited by the North Korean state-sponsored threat actor, the Lazarus Group. The vulnerability is tracked as CVE-2022-47966 and affects 24 ManageEngine products. The vulnerability can be exploited if SAML single-sign-on is enabled or has ever been enabled in a vulnerable ManageEngine product. Successful exploitation of the flaw allows a threat actor to remotely execute code. The Lazarus Group has been exploiting the vulnerability to deliver a remote access trojan (RAT) called QuiteRAT, which is believed to be the successor of MagicRAT. Some attacks have seen a new malware tool deployed called CollectionRAT. Both of these malware variants allow the threat actor to perform a range of actions, including arbitrary command injection. According to researchers at Cisco Talos, the Lazarus Group has been targeting Internet backbone infrastructure and healthcare organizations in Europe and the United States since February, with the first attacks starting...

Read More

PHI of Almost 75,000 Individuals Exposed in Email Incident at AmeriBen

IEC Group, Inc., doing business as AmeriBen, a medical benefits administration services provider, has recently reported an email-related HIPAA data breach to the HHS’ Office for Civil Rights that affected up to 74,884 individuals. The incident was reported as an unauthorized access/disclosure incident. It is unclear from the breach notice whether the incident involved an unauthorized third party or an insider. AmeriBen said it has no reason to believe that any of the exposed information will be misused but has advised the affected individuals to monitor their Explanation of Benefits statements as a precaution. The email account contained protected health information such as employees’ first and last names, claimants first and last names, case numbers, employer CERT codes, provider name, provider city, claim number, date(s) of service, internal INEL codes, and amounts billed and paid. Sanford Health Affected by Cyberattack on Imaging Vendor Sanford Health has recently alerted certain patients that some of their protected health information was exposed in a security incident at its...

Read More

Nuance Communications: 13 Healthcare Clients In North Carolina Affected by MOVEit Hack

Nuance Communications, a Microsoft-owned computer software company that provides software for sharing radiology documentation between providers, has recently confirmed it was affected by the mass hacking of a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer solution. Nuance was notified by Progress Software on May 31, 2023, that a previously unknown vulnerability had been identified and a patch was provided to fix the issue; however, the vulnerability had already been exploited between May 28 and 29 by the Clop group. The data stolen in the attack included the following data types: name, address, email address, birth date, gender, date(s) of service, service locations, practitioners’ names, imaging reports, diagnoses, treatments provided, medication dosages, medical record numbers or other patient identifiers, relative names, power of attorney names, health insurance numbers, diagnostic study identifiers (accession number, study UID) and patient identifiers such as medical record number. No diagnostic images were exposed. Nuance disclosed the data...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist