NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

First Lawsuit Filed Over 23andMe Data Breach

On Friday, October 6, 2023, 23andMe, a direct-to-consumer genetic testing that offers ancestry and health reports, confirmed that it was investigating a cyberattack that resulted in unauthorized individuals gaining access to certain customer accounts. The announcement about the 23andMe data breach came a few days after stolen data started to be listed for sale on a dark net marketplace. In the website announcement, 23andMe said it had launched an investigation and engaged third-party forensics experts to assist, and said the investigation is ongoing. The preliminary results suggest there has not been a breach of its systems, although 23andMe said in the breach notice that an unauthorized third party obtained certain information from users’ accounts, although did not mention in the website notice that stolen data had been listed for sale, although confirmed to certain media outlets that it is in the process of validating the listed data. The stolen data included names, sex, date of birth, genetic ancestry results, profile photos, and geographical location that had been...

Read More

Lack of Antivirus Software Behind PhilHealth Ransomware Attack

Last month, the Philippine Health Insurance Corporation (PhilHealth), the national health insurer in the Philippines, experienced a ransomware attack that forced it to shut down many of its computer systems. The Medusa ransomware group conducted the attack and proceeded to leak the sensitive data of plan members when the $300,000 ransom wasn’t paid. As if the ransomware attack and data leak were not bad enough, further information has emerged on how the attack failed to be prevented. PhilHealth had antivirus software in place, but the license had been allowed to expire, rendering the protection almost useless. The license to use the software expired on April 15, 2023, and the ransomware attack occurred on September 22, 2023. PhilHealth has confirmed that its antivirus software was out of date and blamed complicated government procurement processes on why the license hadn’t been renewed and an alternative solution had not been implemented. PhilHealth has confirmed that antivirus software has now been implemented, although the software is currently on a free trial, which will expire...

Read More
California Extends Workplace Violence Prevention Requirements to Most Employers
Oct11

California Extends Workplace Violence Prevention Requirements to Most Employers

Employers in California must ensure they implement detailed Workplace Violence Prevention Plans following the passing of Senate Bill 553 by the California legislature, and the signing of the bill by Governor Gavin Newsom. The bill aims to improve protection for employees against workplace violence, which is a leading cause of death in the workplace. The Occupational Safety and Health Administration (OSHA) has yet to impose national standards for workplace violence, although OSHA has taken action against several hospitals and health systems that have failed to provide a safe working environment with controls to protect employees from violence in the workplace under existing standards in the OSH Act. States are permitted to introduce their own workplace violence standards. The California Division of Occupational Safety and Health (Cal/OSHA) has required hospitals to implement safety rules to protect employees from workplace violence since April 2017, and those requirements have now been extended to virtually all employers in the state. The new law includes exceptions, such as...

Read More

Zero-Day Vulnerability Exploited to Launch Record-Breaking DDoS Attacks

A zero-day vulnerability in the HTTP/2 protocol has been exploited to conduct distributed denial of service (DDoS) attacks at an unprecedented scale. Google mitigated one attack that peaked at 398 million requests per second (rps). The previous record saw 46 million rps at its peak. Record-breaking attacks have also been reported by other cloud giants, such as Amazon Web Services (AWS) and Cloudflare. HTTP/2 is used by all modern web servers and is critical to how the Internet works. HTTP/2 is used by around 60% of web applications and governs how users interact with websites. The HTTP/2 protocol allows multiple requests to be made quickly for different elements of content within the same connection, which is far more efficient than the HTTP/1.x approach, which establishes multiple parallel TCP connections to retrieve content from a server. The vulnerability – CVE-2023-44487 – has been dubbed HTTP/2 Rapid Reset and abuses a feature called stream cancellation to launch massive, high-volume DDoS attacks. In a standard HTTP/2 DDoS attack, an attacker opens up as many...

Read More
Who is Covered by OSHA?
Oct10

Who is Covered by OSHA?

OSHA covers most private sector businesses and their workforces in all fifty states, the District of Columbia, and other U.S. jurisdictions – either directly through Federal OSHA or through an OSHA-approved state plan. However, the situation relating to public sector employees is more complicated. In this article, we will discuss: Who is covered by OSHA in the private sector? Who is not covered by OSHA in the private sector? Special arrangements in the private sector Who is covered by OSHA in the public sector? Who is Covered by OSHA in the Private Sector? OSHA applies to all businesses in the private sector with at least one employee unless the business operates in an industry in which workplace safety and health is regulated by another federal agency such as the Mine Safety and Health Administration, the Department of Energy, or the Coast Guard. Although required to comply with OSHA’s hazard-specific standards, small businesses with fewer than ten employees and those operating in a low risk industry are partially exempt from OSHA compliance inasmuch as they are not required...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist