25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Amerita Named in Class Action Lawsuit Over Data Breach at PharMerica

The specialty infusion company Amerita is facing a class action lawsuit over a recent cyberattack and data breach at its parent company, PharMerica. On September 5, 2023, suspicious activity was detected within the computer networks of PharMerica and Amerita. The forensic investigation confirmed that an unauthorized third party gained access to its systems between March 12 and March 13, 2023, and potentially accessed the sensitive data of 5.8 million individuals. PharMerica reported the breach on behalf of itself and its parent company, BrightSpring Health Services. The personal and protected health information of almost 220,000 Amerita patients was also compromised in the attack, including names, addresses, diagnoses, medications, and health insurance information. The Money Message ransomware group claimed responsibility for the attack and claimed on its data leak site to have stolen 4.7 terabytes of data, and then proceeded to leak certain files, some of which contained patient data. Class action lawsuits have already been filed against PharMerica over the data breach, and now a...

Read More
Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors
Oct02

Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new cybersecurity awareness program – Secure Our World – through which the agency will be promoting behavioral change across the nation. The aim of the campaign is to get individuals, families, and small- to medium-sized businesses to take action every day to protect themselves while online and when using connected devices. The new campaign was launched as part of Cybersecurity Awareness Month, which this year focuses on four key behaviors that can greatly improve security when they are consistently adopted across an organization: Using strong passwords and a password manager Implementing multifactor authentication Learning how to recognize phishing and reporting phishing attempts Updating software promptly While organizations should consider transitioning to passwordless authentication, until it can be fully implemented it is vital to ensure that password best practices are followed. Strong, unique passwords should be sent for each account, with passwords consisting of random letters, numbers, and special...

Read More

79% Of Healthcare Organizations Experienced an API Security Incident in the Past 12 Months

78% of healthcare organizations experienced an Application Programming Interface (API) security incident in the past 12 months, up 9% from 2022, according to a new survey from Noname Security. APIs continue to pose significant risks to organizations and security incidents are increasing, especially in industries that store large volumes of personally identifiable information such as healthcare, eCommerce, and financial services, which saw the biggest increases in attacks. Healthcare experienced the biggest increase in API security incidents out of the 6 industries represented in the study and is the second most likely industry to experience an API security incident, behind financial services. Healthcare organizations need to share information internally between different medical systems, communicate data to other healthcare organizations, and share medical records with patients’ personal health and well-being devices, with data sharing facilitated through APIs. While APIs facilitate compliant data sharing, the lack of data standards across the industry and multiple siloed...

Read More
FDA Publishes New Guidance on Medical Device Cybersecurity Requirements
Sep29

FDA Publishes New Guidance on Medical Device Cybersecurity Requirements

The U.S. Food and Drug Administration (FDA) has published new guidance on its requirement for medical device manufacturers to include details of the cybersecurity measures that have been implemented for new products in premarket submissions. Medical devices with wireless, internet, and network-connected capabilities are increasingly being used in healthcare and while these devices have helped to improve the care provided to patients, they have the potential to threaten patient safety if they lack appropriate cybersecurity protections. Cyberattacks on the healthcare industry have increased, with advanced persistent threat actors and cybercriminal groups actively targeting the sector. Many attacks have rendered medical devices inoperable and have forced critical IT systems to be shut down which have clinical impacts that put patient safety at risk, such as delaying diagnoses and treatments. “Increased connectivity has resulted in individual devices operating as single elements of larger medical device systems. These systems can include healthcare facility networks, other devices, and...

Read More

Users of Progress Software WS_FTP Server Urged to Immediately Upgrade

Progress Software, the company behind the MOVEit Transfer file transfer solution that was recently subject to mass hacking and data theft attacks by the Clop threat group, has issued a warning to all users of its WS_FTP Server file transfer software to apply patches to fix 8 vulnerabilities, including two critical flaws that can be exploited in low-complexity attacks that require no user interaction. The vulnerabilities affect the WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager interface. CVE-2023-40444 (CVSS: 10) is a maximum-severity remote code execution vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. A pre-authenticated attacker could exploit a .NET deserialization vulnerability in the Ad hoc Transfer Module and remotely execute commands on the underlying  WS_FTP Server operating system. CVE-2023-42657 (CVSS: 9.9) is a critical directory traversal vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. Successful exploitation of the vulnerability would allow an attacker to perform file operations...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist