25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

IBM and Johnson & Johnson Health Care Systems Sued Over August 2023 Data Breach

A lawsuit has been filed against IBM Corp. and Johnson & Johnson Health Care Systems Inc. over an August 2023 data breach that exposed the protected health information of thousands of people who used the Janssen CarePath patient assistance program. IBM is a business associate of Johnson & Johnson and manages the application and database that supports the Janssen CarePath platform. After being notified about a technical issue within the platform that could be exploited to gain access to sensitive data, IBM investigated and discovered there had been unauthorized access on August 2, 2023. The information accessed by an unauthorized third party included names, contact information, dates of birth, health insurance information, medications, and healthcare conditions. Affected individuals were offered complimentary credit monitoring services for 12 months. It is currently unclear how many patients were affected. Last year 1,16 million patients used the Janssen CarePath patient assistance program. On September 22, 2023, a class action lawsuit was filed in the US District Court for...

Read More

HITECH Act and Meaningful Use

When the HITECH ACT and Meaningful Use incentive program was enacted in 2009, it was described as “the most important piece of healthcare legislation to be passed in the last 20 to 30 years” and “the foundation for health care reform”. Not only did the HITECH Act and Meaningful Use incentive program aim to have every US citizen´s health information electronically accessible within five years, it also introduced new measures to protect the integrity of electronic Protected Health Information (ePHI). One of the key measures introduced by the HITECH Act and Meaningful Use incentive program was to make Business Associates and subcontractors liable for any unauthorized disclosures of ePHI attributable to their own negligence. Previously, Business Associates and subcontractors could avoid liability for breaches of ePHI by claiming they were unaware of the requirement to be HIPAA compliant. HITECH closed that loophole. Other Measures Introduced in the HITECH Act and Meaningful Use Program Several other measures were introduced in the HITECH ACT and Meaningful Use incentive...

Read More
CommonSpirit Health Increases Ransomware Attack Cost Estimate to $160 Million
Sep26

CommonSpirit Health Increases Ransomware Attack Cost Estimate to $160 Million

The Chicago, IL-based Catholic health system, CommonSpirit Health, has reported an operating loss of $1.4 billion for fiscal year 2023, up slightly from the $1.3 billion operating loss reported for fiscal year 2022. The CommonSpirit Health ransomware attack in October 2022 was a significant factor in the $1.4 billion operating loss as it caused significant disruption to its billing and collection activities. CommonSpirit Health has estimated the financial losses caused by the attack have now reached 160 million, which includes losses caused by business disruption, remediation costs, and other business expenses. The latest figure is $10 million greater than its previous estimate issued in May 2023. While the attack only caused short-term disruption to patient services, significant disruptions were experienced with claims processing and collections, and the records of 624,000 patients, family members, and caregivers were exposed and potentially stolen. CommonSpirit Health has previously stated that it anticipates its cybersecurity insurance to cover a significant percentage of the...

Read More

Insider Security Threat Costs up 40% in 4 Years

The average annual cost of insider security threats has increased by 40% in 4 years to $16.2 million per organization, according to the 2023 Cost of Insider Risks Report from DTEX Systems. This is the fifth year that DTEX Systems has conducted its insider threat benchmark study to gain insights into the financial consequences that result from insider risks.  This year the study was conducted by the Ponemon Institute on 1,075 IT and IT security professionals at organizations with 500-75,000 employees in North America, Africa, the Middle East, and the Asia-Pacific region. Insider risks are classified as malicious and non-malicious. Malicious incidents are caused by insiders wishing to cause harm and include espionage, IP threats, unauthorized disclosures, fraud, sabotage, and workplace violence. Non-malicious insider incidents include negligent incidents, where harm was caused through carelessness or inattentiveness such as ignoring warnings, non-careless mistakes, and incidents where non-malicious insiders were outsmarted by an adversary, such as phishing and BEC attacks that have...

Read More

Healthcare Industry Sees Sharp Increase in Advanced Email Attacks

The healthcare industry has seen a sharp increase in advanced email attacks this year, according to new data from Abnormal Security. In the year to August 2023, advanced email attacks are up 167% on 2022 levels and business email compromise (BEC) attacks have increased by 279%. Healthcare organizations are attractive targets for cybercriminals as they store large volumes of highly sensitive data and they are heavily reliant on access that that information. Attacks that prevent access to IT systems and protected health information put patient safety at risk and downtime causes significant financial losses, which makes the industry a prime target for extortion. There was a significant increase in advanced email attacks early in 2023, which include BEC, malware, social engineering, and phishing attacks. The year started with an average of 55.66 attacks per 1,000 mailboxes in January and increased to more than 100 attacks per 1,000 mailboxes in March, before falling to a consistent average of 61.16 attacks per 1,000 mailboxes for the rest of the year. Based on last year’s data,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist