NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Blackbaud Settles Multistate Data Breach Investigation for $49.5 Million
Oct05

Blackbaud Settles Multistate Data Breach Investigation for $49.5 Million

A $49.5 million settlement has been reached between Blackbaud and 49 states and the District of Columbia to resolve allegations of insufficient data security practices and an inadequate response to its 2020 ransomware attack. Blackbaud is a Delaware corporation headquartered in Charleston, South Carolina, that provides donor relationship management software to a wide range of organizations, including healthcare providers, educational institutions, and religious and cultural organizations. On May 14, 2020, Blackbaud experienced a ransomware attack that resulted in the exfiltration of sensitive donor information. While data encryption was prevented, more than one million files were stolen in the attack, which included data from around one-quarter of its clients (13,000), including many healthcare organizations. Blackbaud publicly disclosed the ransomware attack on July 16, 2020. The impacted clients then notified their donors about the theft of their information, however, it was not until late September that Blackbaud confirmed that financial information and Social Security numbers...

Read More

HPH Sector Warned About Remote Access Software Risks

Healthcare professionals often require remote access to their networks and electronic health records, such as for providing remote patient care. While remote access tools can improve efficiency and allow secure access to data, these solutions also provide a possible entry point into healthcare networks for malicious actors, and attacks exploiting vulnerabilities in remote access solutions are on the rise. Remote access solutions include virtual private networks (VPNs) that encrypt connections between a user’s device and internal networks; remote desktop software such as Remote Desktop Protocol (RDP) and Virtual Network Computing (VNC) that allow computers to be accessed remotely by users and IT support staff; telehealth platforms that support video conferencing; and secure messaging apps, which are used to communicate securely internally and externally. Telehealth platforms and secure messaging solutions may also integrate with EHRs. All of these solutions can improve efficiency and productivity; however, they introduce risks that need to be carefully managed. Vulnerabilities in...

Read More
Insider Threats to Healthcare Records
Oct05

Insider Threats to Healthcare Records

Insider threats to healthcare records can be attributable to a number of motivations, vulnerabilities, and opportunities, or a combination of all three. To maintain the privacy and security of healthcare records, covered entities, and business associates must minimize the motivations, vulnerabilities, and opportunities for insider threats to healthcare records to a reasonable and appropriate level. Between November 2021 and October 2022, approximately 19% of all data breaches were attributable to internal actors according to the Verizon Data Breach Investigations Report 2023. However, when data breaches in the healthcare sector were analyzed separately, the percentage of data breaches attributable to internal actors increased to approximately 35%. The Verizon Report notes a number of the data breaches attributed to internal actors in the healthcare sector were not malicious and were the result of human error. Nonetheless, it is important for healthcare organizations to factor all types of insider threats into their risk assessments in order to prevent HIPAA violations, financial...

Read More
Progress Software WS_FTP Server Vulnerability Exploited After Release of PoC Code
Oct04

Progress Software WS_FTP Server Vulnerability Exploited After Release of PoC Code

Last week, Progress Software issued a security advisory about 8 vulnerabilities that had been discovered in WS_FTP Server, and customers were advised to update to the latest version immediately to prevent exploitation. Prompt patching of known vulnerabilities is vital and the mass exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer application in May, and the earlier mass exploitation of zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer solution should have put users on alert that these vulnerabilities are popular targets for cyber threat actors. Progress Software issued an alert about the vulnerabilities on September 27, 2023, and urged all customers to update to WS_FTP Server 8.8.2, which was patched against all 8 vulnerabilities, or to at least disable or remove the Ad Hoc Transfer module that was affected by the vulnerabilities. The first exploits of the vulnerabilities were detected by researchers at Rapid7 on Saturday, three days after the patches were released. Rapid8 said it detected exploits of one of the...

Read More

Arietis Health Notifies 54 Entities About Exposure of Patient Data

It has been more than 5 months since the Clop group mass exploited a zero-day vulnerability in the MOVEit Transfer file transfer solution, and victims of the attacks are still coming to light. Aretis Health LLC is a provider of billing services to NorthStar Anesthesia, which provides anesthesia and pain management services to entities across the United States. Arietis Health said its MOVEit Transfer software was hacked, and its investigation revealed on July 26, 2023, that the Clop group may have acquired the data of patients of 54 entities served by NorthStar Anesthesia. Aretis Health notified NorthStar Anesthesia about the breach on August 3, 2023, and now that the affected files have been reviewed, Aretis Health can mail individual notification letters. The information compromised in the attack included patient names, dates of birth, driver’s license or other state identification card numbers, addresses, Social Security numbers, medical record numbers, patient account numbers, health insurance information, diagnosis and treatment information, clinical and prescription...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist