NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Is Google Docs HIPAA Compliant?
Oct16

Is Google Docs HIPAA Compliant?

Google Docs is HIPAA compliant provided that, before using the service to create, receive, maintain, or transmit PHI, organizations subscribe to a Google Workspace business plan, configure the service to comply with HIPAA, and sign Google’s Business Associate Addendum. It is not possible to use a free Google Docs account to create, receive, maintain, or transmit PHI as the free service does not include the features required to support HIPAA compliance. Does Google Docs Encrypt Data? In order for Google Docs to be HIPAA compliant, stored data must be encrypted. Data must also be encrypted during uploading and downloading. We can confirm that Google uses 128-bit or stronger Advanced Encryption Standard (AES) to protect data in transit to the platform, and between and in its data centers. Is Google Considered a Conduit? The Department of Health and Human Services has made it clear in recent guidance that cloud service providers are not – in the vast majority of cases – considered conduits, so the HIPAA Conduit Exception Rule does not apply. Instead, cloud service providers are classed...

Read More

CISA Shares Vulnerabilities and Misconfigurations Exploited by Ransomware Gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintains a Known Exploited Vulnerabilities (KEV) Catalog, which includes a list of all common vulnerabilities and exposures (CVEs) that are known to have been exploited by malicious actors. In January, CISA launched its Ransomware Vulnerability Warning Pilot (RVWP) program, under which critical infrastructure organizations are warned when Internet-accessible devices and systems are discovered on their networks that have unpatched vulnerabilities that could be exploited by ransomware actors. Organizations cannot address vulnerabilities on their networks that they are unaware of. The RVWP program aims to shine a light on security blind spots to allow organizations to take action and address the vulnerabilities before they are exploited in ransomware attacks. Under this program, CISA has already issued warnings to more than 800 organizations about unpatched vulnerabilities on their networks. Last week, CISA published two new resources to help network defenders combat ransomware campaigns. The KEV Catalog has been...

Read More

Cook County Health Patients Affected by Cyberattack at Medical Transcription Firm

Cook County Health, which operates John H. Stroger, Jr. Hospital and Provident Hospital in Chicago, IL, has been informed by one of its business associates, Perry Johnson & Associates, Inc., (PJ&A) that patient data has potentially been compromised in a cyberattack. PJ&A provides medical transcription services to Cook County Health and has access to patients’ protected health information. PJ&A notified Cook County Health on July 21, 2023, that it was investigating a cyberattack, and confirmed on July 26, 2023, that the personal information of Cook County Health patients was stored on the compromised parts of its network. The forensic investigation confirmed that an unauthorized third party accessed the systems where patient data was stored in April 2023. It has been more than two months since Cook County Health was informed about the attack; however, PJ&A has yet to provide a final list of the affected patients and the compromised data, so notification letters have yet to be mailed. Cook County Health said the information likely compromised in the incident...

Read More

McLaren Health Facing Multiple Class Action Lawsuits over Ransomware Attack

Multiple lawsuits have been filed against McLaren Health over its August 2023 ransomware attack. The 15-hospital Michigan health system was attacked by an affiliate of the ALPHV/BlackCat ransomware group in August 2023, who claims to have exfiltrated the sensitive data of approximately 2.5 million patients. McLaren Health was added to the group’s data leak site on September 29, 2023, and threats were issued to publish the stolen data if the ransom is not paid. The threat actor also boasted about having an active backdoor into McLaren Health’s computer systems.  The HIPAA Journal has confirmed that the group’s data leak site included patient names, patient ID numbers, genders, dates of birth, ages, addresses, Social Security numbers, race, language spoken, religion, pregnancy status, physician names, and other sensitive data. The attack prompted Michigan Attorney General Dana Nessel to issue a warning to current and former patients advising them to secure their medical and financial accounts and monitor for any attempted misuse of their personal information. “This attack shows, once...

Read More
CISA and FBI Update AvosLocker Ransomware Cybersecurity Advisory
Oct13

CISA and FBI Update AvosLocker Ransomware Cybersecurity Advisory

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued an update on AvosLocker ransomware, which includes known indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with the AvosLocker ransomware variant. AvosLocker is a relatively new ransomware-as-a-service operation that was first identified in July 2021. While the group is not as prominent as LockBit Clop, and ALPHV (BlackCat), AvosLocker ransomware affiliates have compromised organizations across multiple critical infrastructure sectors. The group engages in exfiltration-based extortion, requiring the payment of a ransom to prevent the release of stolen data and for the keys to decrypt files. AvosLocker affiliates use legitimate software and open source tools during their ransomware operations. The group has been observed using Splashtop Streamer, Tactical RMM, PuTTy, AnyDesk, PDQ Deploy, and Atera Agent as backdoor access vectors, the open source networking tunneling tools Ligolo and Chisel, Cobalt Strike...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist