NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is OSHA Certification?
Oct17

What is OSHA Certification?

OSHA certification is a recognition workers obtain for completing courses in OSHA’s Safety and Health Fundamentals Program. Some OSHA certification courses are designed to teach general workplace safety, while others may be geared towards specific hazards or specific roles. Examples include: Job Hazard Analysis Health Hazard Awareness Electrical Standards Industrial Hygiene Machinery and Machine Guarding Standards Permit-Required Confined Space Entry Bloodborne Pathogen Exposure Control Occupational Noise Exposure Hazards Training Guidelines for Safe Patient Handling Fall Hazard Awareness for the Construction Industry How to Obtain OSHA Certification in the Fundamentals Program OSHA’s Safety and Health Fundamentals Program awards certificates to participants who complete a minimum of seven courses. The courses vary in length from 4 hours up to 35 hours, and participants must complete at least 68 contact hours of training for a construction or general industry certificate, or 77 contact hours of training for a maritime certificate. The courses are run at OSHA Training...

Read More

Governor Newsom Signs California Delete Act into Law

The California Delete Act enables state residents to request that data brokers delete all personal data maintained about them via a centralized database maintained on the CPPA website rather than having to make a request to each data broker in California. The Act also requires data brokers to visit the database at least once every 45 days to review and process new deletion requests. On October 10, 2023, California Governor Gavin Newsom signed the Delete Act (Senate Bill 362) into law. The bill was introduced in April 2023 by Senator Josh Becker to give California residents greater control over their personal information and how it is used by data brokers. Data brokers sell millions of consumers’ data points to the highest bidder. That information includes purchasing data, which can be accessed by retailers and used to serve targeted ads. More sensitive information may also be collected and sold, such as geolocation information and even reproductive health information. The new law will allow state residents to request that data brokers delete their personal data and/or forbid them...

Read More

HHS Stresses Importance of Having an Effective Cybersecurity Incident Response Plan

The Health Sector Cybersecurity Coordination Center (HC3) has published a threat brief that highlights the importance of developing an effective cybersecurity incident response plan. Given the extent to which healthcare organizations are targeted by malicious actors and the number of data breaches now being reported by HIPAA-regulated entities, a successful attack and data breach is now an inevitability. It is no longer a case of if there will be a cyberattack, it is a case of when and how many. Without a tried and tested incident response plan, valuable time will be lost responding to an attack which not only results in a longer response and higher costs. Inappropriate actions taken in response to an attack could result in evidence being inadvertently destroyed and incident response planning failures may also lead to civil monetary penalties and other regulatory activities, increased reputational damage, extended disruption to patient care, and costly lawsuits. What is a Cybersecurity Incident Response Plan? A cybersecurity incident response plan is a written document that has...

Read More
SEC Launches Investigation into Progress Software’s MOVEit Hack
Oct17

SEC Launches Investigation into Progress Software’s MOVEit Hack

In May 2023, a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer solution was mass exploited by the Clop ransomware group. Progress Software MOVEit disclosed the vulnerability on May 31, and deployed a patch the same day; however, the Clop ransomware group had already exploited the vulnerability and stole files from many of its customers. The total number of affected customers has yet to be confirmed, but Emsisoft says that as of October 16, 2023, at least 2,551 organizations are known to have been affected and the data of more than 64 million individuals has been stolen. The education sector was the worst affected, accounting for around 41% of victims, followed by healthcare (19%), and finance/professional services (12%). Emsisoft estimated the total cost of the attack to be $10,637,147,400, based on average data breach costs calculated by IBM in its 2023 Cost of a Data Breach Report. In a recent filing with the U.S. Securities and Exchange Commission (SEC), Progress Software reported $2.9 million in losses due to the attack up to the end of August 2023;...

Read More

HPH Sector Warned About NoEscape Ransomware Attacks

In May 2023, a new ransomware-as-a-service (RaaS) group started conducting attacks and in the past 5 months has attacked several industry sectors, including healthcare. Many new ransomware groups develop their ransomware variants using leaked source code from other ransomware families; however, NoEscape claims to have developed its own ransomware code and associated infrastructure from scratch although the encryptors used by NoEscape are virtually identical to those used by the now-defunct Avaddon ransomware, which along with other similarities has led security researchers to believe that NoEscape is a rebrand of Avaddon ransomware, which ceased operations in June 2021. The NoEscape RaaS group recruits affiliates to conduct attacks in exchange for a percentage of any ransoms they generate and provides ransomware to encrypt files. The ransomware is capable of deleting shadow copies and system backups and can force a reboot and operate in safe mode, where security solutions can be disabled more easily. NoEscape is used to encrypt files on Windows and Linux machines, as well as VMware...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist