25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

CISA Publishes Guidance on Securing Cloud Services

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published guidance that details security and resilience best practices to adopt when utilizing cloud services. The new guidance can be followed by all organizations; however, the guidance is of particular importance for federal agencies and critical infrastructure entities. Cybercriminals and advanced persistent threat actors are increasingly targeting supply chains to attack federal government networks and critical infrastructure, and many attacks now target cloud-based environments. The latest guidance can be used by federal agencies, critical infrastructure entities, and others to secure cloud business application environments and protect information created, accessed, shared, and stored in those environments. The guidance was developed under CISA’s Secure Cloud Business Applications (SCuBA) project, which was established and funded through the American Rescue Plan Act of 2021. The aim of the project is to develop consistent, effective, modern, and manageable security configurations that will help secure agency...

Read More

15-Year Employee Privacy Breach Discovered by Metro Health System

Metro Health System in Cleveland, OH, has discovered an employee has accessed patient records without a valid work reason. The unauthorized access was discovered on April 27, 2023, and the subsequent investigation confirmed that patient records had been accessed without authorization at various times over the past 15 years. The earliest incident occurred in 2008. The information viewed included patient names, dates of birth, and clinical information. No Social Security numbers or financial information were accessed. A spokesperson for Metro Health said the employee has been disciplined per its sanctions policy and no evidence has been found to indicate redisclosure of patient data or any misuse of that information. Affected individuals are being notified by mail, steps are being taken to improve its privacy practices, and further HIPAA training has been provided to the workforce. COX Health Affected by Hacking of Fortra GoAnywhere File Transfer Solution Springfield, MO-based CoxHealth has recently confirmed that patient data was compromised in a January 2023 cyberattack on its...

Read More
Atlantic General Hospital Increases Ransomware Victim Count to Almost 140,000 Individuals
Jun27

Atlantic General Hospital Increases Ransomware Victim Count to Almost 140,000 Individuals

In March 2023, Atlantic General Hospital notified the Maine Attorney General that it had fallen victim to a ransomware attack in which the protected health information of 30,704 individuals was exposed; however, the ransomware attack was far more extensive than was previously thought and the total has been upwardly revised to 136,981 individuals. The attack was detected on January 29, 2023, and the forensic investigation confirmed hackers had access to its network between January 20 and January 29, 2023. The initial review of files that were potentially compromised in the breach was completed on March 6, 2023, and confirmed that names, medical record numbers, treating/referring physician names, health insurance information, subscriber numbers, medical history information, and diagnosis/treatment information may have been accessed or acquired. Notification letters were sent on March 24, 2023, and complimentary credit and identity monitoring services were offered to affected individuals. The investigation into the attack continued, and additional files were discovered to have been...

Read More
Interview: Wei Pan, Head of Engineering, Celo Health
Jun27

Interview: Wei Pan, Head of Engineering, Celo Health

As part of our interview series, we spoke with Wei Pan, Head of Engineering at Celo Health. Celo Health is the developer of a HIPAA-compliant secure messaging platform that enables healthcare teams to collaborate seamlessly and securely on patient care. Tell the readers about your career in the healthcare industry I hold more than 15 years of experience in software development, specifically in the area of healthcare security.  I graduated from the University of Auckland with a bachelor’s and a master’s in computer science. My development expertise is focused on cloud software architectures and web applications, iOS, Android, and Microsoft technologies. A key part of my career over the years, has been managing development teams in different parts of the world. I’ve been able to manage these dynamics successfully primarily because of the type of development methodology I’ve implemented called Kanban.  This is an agile development method focused on process improvement, managing workflow efficiently, fostering team collaboration and transparency, and reducing lead time for new ideas...

Read More
What is the Mission of OSHA?
Jun27

What is the Mission of OSHA?

The mission of OSHA is to ensure safe and healthy working conditions for workers in the United States by setting and enforcing workplace safety and health standards, and by providing training, outreach, education, and assistance to employers. OSHA fulfills its mission by: Developing workplace safety and health standards. Providing training programs and employer education. Enforcing OSHA standards via targeted inspections. Facilitating confidential worker complaints. Investigating fatalities, catastrophes, and complaints. Providing on-site and virtual compliance assistance. Mandating injury and illness recordkeeping and reporting. Offering grants for non-profit employee training. Publishing fact sheets – both online and in print. Organizing cooperative programs with labor groups. The Occupational Safety and Health Administration (OSHA) was formed as a result of the passage of the Occupational Safety and Health Act in 1970. The mission of OSHA – which operates under the auspices of the Department of Labor – is to protect the rights of workers to safe and healthy working...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist