25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The Importance of Identity and Access Management (IAM) in Healthcare

Identity and access management in healthcare is a best practice for ensuring employees, vendors, contractors, and subcontractors are provided with appropriate access to the technology resources and data they need to perform their required duties and policies, procedures, and technology are in place to prevent unauthorized individuals from accessing resources and sensitive data. Identity and access management consists of administrative, technical, and physical safeguards to keep resources and data locked down, with access to resources and data granted based on job role, authority, and responsibility. Identity and access management, in short, is about providing the right people with access to the right resources and data, at the right time, for the right reasons, while preventing unauthorized access at all times. For a business with a small staff and few third-party vendors, identity and access management is straightforward. With few individuals requiring access to systems and data, ensuring everyone has access to the systems and data they need and nothing more is a relatively simple...

Read More
How does OSHA Enforce its Standards?
Jul04

How does OSHA Enforce its Standards?

OSHA enforces its standards via inspections and investigations when an imminent workplace danger is reported to the Administration, when an injury occurs in a workplace accident, or when a report is received alleging a safety or health issues which violates an OSHA standard. Not every business subject to OSHA’s safety and health standards can be inspected or investigated simultaneously, so the agency has established a system of priorities. The system of priorities is: An imminent danger in the workplace. Catastrophes and fatal accidents. Complaints of alleged violations. Planned inspections at high-hazard workplaces. Follow-up inspections to establish if previously cited violations have been corrected. OSHA regards an imminent danger to be any situation where there is reasonable certainty a risk exists that can be expected to cause death or severe injury before the risk can be eliminated through the normal inspection and enforcement process. Cases such as these can be brought to OSHA’s attention by an employer or an employee, and are reviewed by an area director before a priority...

Read More

559,000 Individuals Affected by Murfreesboro Medical Clinic & SurgiCenter Cyberattack

Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee has recently confirmed that the protected health information of more than half a million patients was compromised in what it describes as “a series of attacks on our network and IT systems,” which were discovered on or around April 24, 2023. An investigation was launched after securing its network, and it was confirmed that a “well-known cyber extortion operation” was behind the attack and gained access to the network on or around April 22, 2023.  The group was not named by MMC, but it appears to be the BianLian threat group. MMC said it was unable to determine whether files were accessed or removed from its network; however, the parts of the network that were accessed contained files that included the protected health information of 559,000 patients. The information potentially accessed or stolen included full names, dates of birth, home addresses, phone numbers, copies of driver’s licenses, full or partial social security numbers, dependent information, dates of service, medical and diagnostic information related to...

Read More

Cyberattacks Reported by Precision Imaging Centers, Marshall & Melhorn, and Atrium Health Wake Forest Baptist

Precision Imaging Centers in Jacksonville, FL, has recently notified 31,010 patients about a security breach that occurred on or around November 2, 2022. Unauthorized individuals gained access to its network and exfiltrated files containing sensitive patient information. The compromised information varied from patient to patient and may have included first and last names, addresses, dates of birth, Social Security numbers, driver’s license numbers, government-issued identification numbers, health insurance information, medical conditions/diagnoses, and other health or medical information. Precision Imaging Centers said the attack was conducted by a high-profile threat actor group, and shortly after the attack was confirmed, a law enforcement operation resulted in the threat group’s websites and servers being seized, which suggests the threat actor behind the attack was the Hive ransomware group. Precision Imaging Centers said no evidence of misuse of personal information has been detected. Precision Imaging Centers isolated its network when the breach was detected, and a forensic...

Read More

Cyberattack Affects Multiple Residential Care Facilities in Pennsylvania

The Williamsport Home, a retirement village in Pennsylvania, and Senior Choice, Inc., a provider of skilled nursing care at three inpatient facilities in Pennsylvania – The Atrium in Johnstown, Beacon Ridge in Indiana, and The Patriot in Somerset – have been affected by a cyberattack that was detected on April 24, 2023. Steps were immediately taken to secure the network when the security breach was detected and while the investigation into the cyberattack is ongoing, it has been determined that unauthorized individuals gained access to certain business operation systems between April 18 and April 24, 2023. The systems used directly for residential care do not appear to have been compromised; however, the business systems compromised in the attack contained protected health information that was potentially accessed or obtained. The types of information that were exposed varied from individual to individual and may have included one or more of the following: Name, address, birth date, admission date, discharge date, death date, medical record number, provider or facility name,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist