25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Imagine360 Suffers Breaches of Two File-Sharing Platforms

Imagine360, a Wayne, PA-based provider of a self-funded health plan solution for employers, was the victim of two cyberattacks this year involving its file-sharing solutions. The first attack was detected on or around January 30, when suspicious activity was detected within its Citrix file-sharing solution, which Imagine 360 uses to securely exchange files related to self-insured health plans. Steps were immediately taken to secure the platform by taking it offline, passwords were reset, and an investigation was launched into the attack. A few days later, while Imagine360 was investigating the Citrix breach, a vulnerability was exploited in another file-sharing platform – Fortra’s GoAnywhere Transfer solution. Fortra determined that an unauthorized actor – now known to be the Clop ransomware group – exploited a zero-day vulnerability and stole sensitive data. Imagine360 independently investigated both security incidents and confirmed that its own systems were unaffected and remained secure at all times; however, files were stolen in both attacks between January 28 and January...

Read More

The Importance of Identity and Access Management (IAM) in Healthcare

Identity and access management in healthcare is a best practice for ensuring employees, vendors, contractors, and subcontractors are provided with appropriate access to the technology resources and data they need to perform their required duties and policies, procedures, and technology are in place to prevent unauthorized individuals from accessing resources and sensitive data. Identity and access management consists of administrative, technical, and physical safeguards to keep resources and data locked down, with access to resources and data granted based on job role, authority, and responsibility. Identity and access management, in short, is about providing the right people with access to the right resources and data, at the right time, for the right reasons, while preventing unauthorized access at all times. For a business with a small staff and few third-party vendors, identity and access management is straightforward. With few individuals requiring access to systems and data, ensuring everyone has access to the systems and data they need and nothing more is a relatively simple...

Read More
How does OSHA Enforce its Standards?
Jul04

How does OSHA Enforce its Standards?

OSHA enforces its standards via inspections and investigations when an imminent workplace danger is reported to the Administration, when an injury occurs in a workplace accident, or when a report is received alleging a safety or health issues which violates an OSHA standard. Not every business subject to OSHA’s safety and health standards can be inspected or investigated simultaneously, so the agency has established a system of priorities. The system of priorities is: An imminent danger in the workplace. Catastrophes and fatal accidents. Complaints of alleged violations. Planned inspections at high-hazard workplaces. Follow-up inspections to establish if previously cited violations have been corrected. OSHA regards an imminent danger to be any situation where there is reasonable certainty a risk exists that can be expected to cause death or severe injury before the risk can be eliminated through the normal inspection and enforcement process. Cases such as these can be brought to OSHA’s attention by an employer or an employee, and are reviewed by an area director before a priority...

Read More

559,000 Individuals Affected by Murfreesboro Medical Clinic & SurgiCenter Cyberattack

Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee has recently confirmed that the protected health information of more than half a million patients was compromised in what it describes as “a series of attacks on our network and IT systems,” which were discovered on or around April 24, 2023. An investigation was launched after securing its network, and it was confirmed that a “well-known cyber extortion operation” was behind the attack and gained access to the network on or around April 22, 2023.  The group was not named by MMC, but it appears to be the BianLian threat group. MMC said it was unable to determine whether files were accessed or removed from its network; however, the parts of the network that were accessed contained files that included the protected health information of 559,000 patients. The information potentially accessed or stolen included full names, dates of birth, home addresses, phone numbers, copies of driver’s licenses, full or partial social security numbers, dependent information, dates of service, medical and diagnostic information related to...

Read More

Cyberattacks Reported by Precision Imaging Centers, Marshall & Melhorn, and Atrium Health Wake Forest Baptist

Precision Imaging Centers in Jacksonville, FL, has recently notified 31,010 patients about a security breach that occurred on or around November 2, 2022. Unauthorized individuals gained access to its network and exfiltrated files containing sensitive patient information. The compromised information varied from patient to patient and may have included first and last names, addresses, dates of birth, Social Security numbers, driver’s license numbers, government-issued identification numbers, health insurance information, medical conditions/diagnoses, and other health or medical information. Precision Imaging Centers said the attack was conducted by a high-profile threat actor group, and shortly after the attack was confirmed, a law enforcement operation resulted in the threat group’s websites and servers being seized, which suggests the threat actor behind the attack was the Hive ransomware group. Precision Imaging Centers said no evidence of misuse of personal information has been detected. Precision Imaging Centers isolated its network when the breach was detected, and a forensic...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist