25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Ransomware Attack Key Factor in H1 Operating Losses of $102.6 Million for Point32 Health

Point32Health has reported operating losses of $102.7 million for the first 6 months of 2023 on $4.8 billion in revenue, compared to losses of $25.8 million in the first 6 months of 2022 on $4.9 billion in revenue. The $76.9 million difference has largely been attributed to the ransomware attack it detected on April 17, 2023., although details of the actual cost of the attack have not been released. The attack saw sensitive data exfiltrated from the systems of Harvard Pilgrim Health Care between March 28, 2023, and April 17, 2023, including the HIPAA protected health information of current and former subscribers, their dependents, and current contracted providers. The compromised information included names, Social Security numbers, and taxpayer identification numbers. The breach was reported to the HHS’ Office for Civil Rights as affecting 2,550,922 individuals. The attack resulted in systems being taken offline for several weeks, including the systems that support the Harvard Pilgrim Health Care Commercial and Medicare Advantage Stride℠ plans (HMO)/(HMO-POS). The recovery process...

Read More
Know Your Adversary: HC3 Shares Details of Chinese APT Groups Targeting the Healthcare Sector
Aug24

Know Your Adversary: HC3 Shares Details of Chinese APT Groups Targeting the Healthcare Sector

The healthcare industry is actively targeted by financially motivated cybercriminal gangs; however, state-sponsored hacking groups also seek access to healthcare networks and are actively targeting healthcare providers and other entities in the healthcare and public health sector. In a recently published security advisory, the Health Sector Cybersecurity Coordination Center (HC3) provides a threat profile of some of the most capable Chinese hacking groups that are known to target U.S. healthcare organizations. While at least one Chinese state-sponsored hacking group is known to conduct cyberattacks for financial gain, most groups conduct attacks for espionage purposes and to obtain intellectual property (IP) of interest to the government of the People’s Republic of China, such as IP related to medical technology and medicine. For instance, Chinese hackers targeted pharmaceutical firms during the pandemic seeking COVID-19 vaccine research data. One of the most active threat groups is known as APT41 (also BARIUM, Winnti, LEAD, WICKED SPIDER, WICKED PANDA, Blackfly, Suckfly,...

Read More

Mississippi Health System Investigating Cyberattack

Singing River Health System in Mississippi, which operates Pascagoula Hospital, Ocean Springs Hospital, and Gulfport Hospital, detected unusual activity within its IT systems last week and is investigating a potential cyberattack. On Monday, the health system took its IT systems offline to preserve system integrity and downtime procedures remain in place. Shannon Wall, SRHS Chief Marketing Officer, said “We are working diligently with third-party specialists to investigate the source of this disruption and to confirm its impact on our systems as soon as possible. We have also engaged with the appropriate law enforcement authorities.” She also confirmed that the IT security team is working around the clock to investigate the incident, ensure systems are secured, and will start bringing systems back online when it is safe to do so. A timeline has not been provided on when systems will be restored. Further details on the nature of the attack, such as if this is a ransomware incident, have not been released. The health system is continuing to see patients but there are delays due to...

Read More

Digital Health Security Initiative Launched by the HHS

The U.S. Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) has announced the launch of the Digital Health Security (DIGIHEALS) project which seeks to improve the electronic infrastructure of the U.S. healthcare industry. ARPA-H is a funding agency that was created in 2022 to support biomedical and health research, specifically research that has the potential to advance aspects of medicine and health that cannot be achieved through more traditional research and commercial activity. Over the past few years, cybercriminals have been targeting the healthcare sector and have been using ransomware to prevent access to critical systems and data. In many attacks, hospitals have been forced to divert ambulances, cancel appointments, and delay care. Many attacks have caused disruption for months and some attacks have resulted in the permanent closure of healthcare facilities. “The DIGIHEALS project comes when the U.S. healthcare system urgently requires rigorous cybersecurity capabilities to protect patient privacy, safety, and lives,” said...

Read More
When Should the OSHA Annual Summary be Posted?
Aug22

When Should the OSHA Annual Summary be Posted?

The OSHA annual summary should be posted in a conspicuous place (or places) where notices to employees are customarily posted no later than February 1 of the year following the year covered by the summary. This article explains what the OSHA annual summary is, who is required to post a summary, and what the summary should include. What is the OSHA Annual Summary? Who is Required to Post a Summary? What Should the Summary Include? Who Certifies the Summary is Accurate? How Long Must a Summary Remain Posted? Conclusion: Be Aware of the Posting Requirements What is the OSHA Annual Summary? The OSHA annual summary is a form (Form 300A or equivalent) that summarizes the recordable work-related injuries and illnesses that occurred during the previous calendar year. The summary has to be completed by all employers unless exempted due to the size of the business or the nature of activities. Note: Exemption from the posting requirements does not exempt an employer from reporting a workplace incident that results in a fatality or severe injury. “Covered employers” – i.e., those required to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist