25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Progress Software WS_FTP Server Vulnerability Exploited After Release of PoC Code
Oct04

Progress Software WS_FTP Server Vulnerability Exploited After Release of PoC Code

Last week, Progress Software issued a security advisory about 8 vulnerabilities that had been discovered in WS_FTP Server, and customers were advised to update to the latest version immediately to prevent exploitation. Prompt patching of known vulnerabilities is vital and the mass exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer application in May, and the earlier mass exploitation of zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer solution should have put users on alert that these vulnerabilities are popular targets for cyber threat actors. Progress Software issued an alert about the vulnerabilities on September 27, 2023, and urged all customers to update to WS_FTP Server 8.8.2, which was patched against all 8 vulnerabilities, or to at least disable or remove the Ad Hoc Transfer module that was affected by the vulnerabilities. The first exploits of the vulnerabilities were detected by researchers at Rapid7 on Saturday, three days after the patches were released. Rapid8 said it detected exploits of one of the...

Read More

Arietis Health Notifies 54 Entities About Exposure of Patient Data

It has been more than 5 months since the Clop group mass exploited a zero-day vulnerability in the MOVEit Transfer file transfer solution, and victims of the attacks are still coming to light. Aretis Health LLC is a provider of billing services to NorthStar Anesthesia, which provides anesthesia and pain management services to entities across the United States. Arietis Health said its MOVEit Transfer software was hacked, and its investigation revealed on July 26, 2023, that the Clop group may have acquired the data of patients of 54 entities served by NorthStar Anesthesia. Aretis Health notified NorthStar Anesthesia about the breach on August 3, 2023, and now that the affected files have been reviewed, Aretis Health can mail individual notification letters. The information compromised in the attack included patient names, dates of birth, driver’s license or other state identification card numbers, addresses, Social Security numbers, medical record numbers, patient account numbers, health insurance information, diagnosis and treatment information, clinical and prescription...

Read More

McLaren Health Care Ransomware Attack Affects 2.1 Million Patients

McLaren Health Care, a 14-hospital health system based in Grand Blanc, Michigan, has confirmed that it recently fell victim to a ransomware attack and has warned patients that files containing patient information were stolen in the attack and may be leaked on the dark web. Suspicious activity was detected in its IT systems in late August, and it was later confirmed that this was a ransomware attack. Its computer network was taken offline while the incident was investigated, which caused disruption across its healthcare facilities, although healthcare services continued to be provided at all locations and patient care was unaffected Last week, the ALPHV/BlackCat ransomware group claimed responsibility for the attack and added McLaren Health Care to its dark web data leak site. ALPHV is a spin-off of the now-defunct Conti ransomware group and has a history of attacking healthcare organizations.  The group claims to have exfiltrated more than 6 terabytes of data in the attack and says the stolen data includes the sensitive information of 2.5 million patients. While McLaren Health Care...

Read More

Prospect Medical Holdings Cyberattack Puts Connecticut Hospital Deal at Risk

On August 1, 2023, Los Angeles, CA-based Prospect Medical Holdings identified suspicious activity in some of its IT systems. A forensic investigation was conducted to determine the nature and scope of the security breach, and it was confirmed on September 13, 2023, that an unauthorized third party had access to some of its IT systems between July 31 and August 3, 2023, and during that time, accessed and/or acquired files containing the information of certain patients and employees. The exposed data related to patients of the following facilities: Southern California Hospital at Culver City Southern California Hospital at Hollywood Southern California Hospital at Van Nuys Los Angeles Community Hospital Los Angeles Community Hospital at Norwalk Los Angeles Community Hospital at Bellflower Foothill Regional Medical Center Prospect Medical Holdings has also confirmed that 24,130 current and former employees and dependents of Prospect Medical’s Eastern Connecticut Health Network (ECHN) and Waterbury Health facilities also had their information exposed. The exposed information varies...

Read More

HHS Issues Warning Issued About LokiBot Malware

The Health Sector Cybersecurity Coordination Center (hC3) has published an Analyst Note about LokiBot – one of the most prevalent and persistent malware families. LokiBot, aka Loki PWS, has been used in attacks on a variety of industry sectors over the past 8 years, including critical infrastructure organizations; however, there has been a notable increase in the use of the malware since July 2020 The malware is used in attacks on Windows and Android devices and steals usernames, passwords, and other credentials from more than 100 different clients, along with cryptocurrency wallets and payment card information. The malware can take screenshots, log keystrokes, and steal cookies and system data, allowing multi-factor authentication to be bypassed. The malware also creates a backdoor in infected systems that allows attackers to deliver other malicious payloads such as ransomware. LokiBot was first offered for sale in 2015 for $540 and proved popular due to its relatively low price. The malware is now better at evading security solutions, has more extensive capabilities, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist