25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Employee Health Plan Data Exposed in Forever 21 Data Breach
Sep04

Employee Health Plan Data Exposed in Forever 21 Data Breach

Fashion retailer Forever 21 has notified the Maine Attorney General of a data breach in which the health plan data of 539,207 current and former employees was exposed. Breach notification letters are being sent to everyone potentially affected by the breach. However, the letters reveal little about the nature of the attack or what specific data was exposed. According to the notification published on the Maine Attorney General website, Forever 21 experienced an “external system breach” between January 5 and March 21, 2023. The nature of the information breached is “name or other personal identifier in combination with Social Security number”, and identity theft services are being offered to those potentially affected. The notification also includes a link to the company’s breach notification letter to potentially affected individuals. The letter provides limited information about the nature of the attack or what specific data was exposed, stating that an unauthorized third party “accessed certain Forever 21 systems” and “obtained select files from certain Forever 21 systems”. With...

Read More

Essential Elements of the MSP Security Stack

Managed service providers are being increasingly used by healthcare providers to help them achieve HIPAA Security Rule compliance. Here we explore the essential elements of the MSP security stack that are needed to meet the needs of healthcare organizations. Growing Demand for MSP Security Services The healthcare industry has long been a target for cybercriminals and cyberattacks and data breaches are increasing each year, with threat actors developing increasingly sophisticated ways of breaching defenses and gaining access to sensitive healthcare data. To protect against these threats, healthcare organizations need to adopt a defense-in-depth strategy, where multiple cybersecurity solutions are deployed to protect their network, applications, and data, along with monitoring solutions to rapidly detect breaches of their defenses. They also need to implement and test an incident response plan for when hackers succeed. That is a massive job for any healthcare organization and one that many small- and medium-sized healthcare organizations struggle with. It is therefore no surprise...

Read More

Orrick, Herrington & Sutcliffe Sued Over Ransomware Attack and Data Breach

The San Francisco, CA-based law firm, Orrick, Herrington & Sutcliffe LLP, is facing a class action lawsuit over a ransomware attack and data breach that was detected on March 13, 2023. The law firm determined that part of its network had been compromised by an unauthorized third party, which gained access to a file share that was used to store client files. The unauthorized access was immediately blocked; however, the forensic investigation confirmed that files containing personal information had been exfiltrated from its servers between February 28 and March 13, 2023. The compromised information included names, addresses, dates of birth, and Social Security numbers. The law firm offered the affected individuals complimentary credit monitoring and identity theft protection services. On August 11, 2023, a lawsuit was filed in the U.S. District Court for the Northern District of California on behalf of plaintiff Dennis R Werley, and more than 152,818 similarly situated individuals who had their personal information compromised in the attack. The lawsuit alleges the law firm...

Read More
PHI Included in Mom’s Meals Data Breach
Aug31

PHI Included in Mom’s Meals Data Breach

The parent company of the Mom’s Meals home delivery meal service – PurFood LLC – has published a Notice of Data Event on its website and filed a Data Breach Notification with the Maine Attorney General following a cyberattack earlier this year in which personal information relating to 1,237,681 customers, employees, and contractors is believed to have been stolen, and according to the HHS’ Office for Civil Rights breach portal, the protected health information of up to 1,229,233 individuals was involved. PurFood LLC – trading as Mom’s Meals – delivers refrigerated ready-to-eat meals nationwide to customers with special nutritional requirements. As well as supplying private customers, the company works with more than five hundred health plans, managed care organizations, and other agencies to provide access to meals for people covered by Medicare and Medicare. According to a Notice of Data Event on the company’s website, Mom’s Meals experienced a cyberattack between January 16, 2023, and February 22, 2023, that resulted in customer, employee, and contractor data being...

Read More

Study Reveals State of External Exposure Management

CyCognito has published its latest State of External Exposure Management Report, which highlights the extent to which vulnerabilities affect organizations and how easy it is for hackers to exploit those vulnerabilities. For the report, CyCognito’s researchers aggregated and analyzed 3.5 million digital assets across its customer base between June 2022 and May 2023, which includes small, medium, and large enterprises, including Fortune 500 companies. The study found that 70% of web applications had severe security gaps, such as lacking web application firewall (WAF) protection and not using encrypted connections such as HTTPS, with 25% of web applications lacking both protections. A typical enterprise has more than 12,000 web apps such as APIs, SaaS applications, databases, and servers. The researchers found at least 30% of those web apps have more than 3,000 assets and had at least one exploitable or high-risk vulnerability. The study confirmed the extent to which personally identifiable information (PII) is put at risk. 74% of assets containing PII were found to be exposed to at...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist