NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

79% Of Healthcare Organizations Experienced an API Security Incident in the Past 12 Months

78% of healthcare organizations experienced an Application Programming Interface (API) security incident in the past 12 months, up 9% from 2022, according to a new survey from Noname Security. APIs continue to pose significant risks to organizations and security incidents are increasing, especially in industries that store large volumes of personally identifiable information such as healthcare, eCommerce, and financial services, which saw the biggest increases in attacks. Healthcare experienced the biggest increase in API security incidents out of the 6 industries represented in the study and is the second most likely industry to experience an API security incident, behind financial services. Healthcare organizations need to share information internally between different medical systems, communicate data to other healthcare organizations, and share medical records with patients’ personal health and well-being devices, with data sharing facilitated through APIs. While APIs facilitate compliant data sharing, the lack of data standards across the industry and multiple siloed...

Read More
FDA Publishes New Guidance on Medical Device Cybersecurity Requirements
Sep29

FDA Publishes New Guidance on Medical Device Cybersecurity Requirements

The U.S. Food and Drug Administration (FDA) has published new guidance on its requirement for medical device manufacturers to include details of the cybersecurity measures that have been implemented for new products in premarket submissions. Medical devices with wireless, internet, and network-connected capabilities are increasingly being used in healthcare and while these devices have helped to improve the care provided to patients, they have the potential to threaten patient safety if they lack appropriate cybersecurity protections. Cyberattacks on the healthcare industry have increased, with advanced persistent threat actors and cybercriminal groups actively targeting the sector. Many attacks have rendered medical devices inoperable and have forced critical IT systems to be shut down which have clinical impacts that put patient safety at risk, such as delaying diagnoses and treatments. “Increased connectivity has resulted in individual devices operating as single elements of larger medical device systems. These systems can include healthcare facility networks, other devices, and...

Read More

Users of Progress Software WS_FTP Server Urged to Immediately Upgrade

Progress Software, the company behind the MOVEit Transfer file transfer solution that was recently subject to mass hacking and data theft attacks by the Clop threat group, has issued a warning to all users of its WS_FTP Server file transfer software to apply patches to fix 8 vulnerabilities, including two critical flaws that can be exploited in low-complexity attacks that require no user interaction. The vulnerabilities affect the WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager interface. CVE-2023-40444 (CVSS: 10) is a maximum-severity remote code execution vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. A pre-authenticated attacker could exploit a .NET deserialization vulnerability in the Ad hoc Transfer Module and remotely execute commands on the underlying  WS_FTP Server operating system. CVE-2023-42657 (CVSS: 9.9) is a critical directory traversal vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. Successful exploitation of the vulnerability would allow an attacker to perform file operations...

Read More

The HIPAA Journal’s Response to Sen. Cassidy’s RFI on Health Data Privacy

Dear Sen. Cassidy, The HIPAA Journal appreciates the opportunity to submit comments per your September 7, 2023, request for information on improving health data privacy while balancing the need to support medical research and medical technology innovation, specifically with respect to potential Health Insurance Portability and Accountability Act (HIPAA) updates. While HIPAA is not perfect, it has served as an effective framework that restricts uses and disclosures of protected health information (PHI) while allowing legitimate uses of healthcare data, and requires covered entities and their business associates that collect, store, maintain, and transmit PHI implement appropriate safeguards to ensure the privacy of PHI. It has been two decades since the HIPAA Privacy and Security Rules were signed into law, during which time the amount of health information collected by non-HIPAA-regulated entities has been increasing to a point where the health data collected by non-HIPAA-covered entities through fitness trackers, mobile devices, and health apps likely exceeds the data collected by...

Read More
Interview: Rachel Sheley, Security Strategist/vCISO, GreyCastle Security
Sep28

Interview: Rachel Sheley, Security Strategist/vCISO, GreyCastle Security

The HIPAA Journal has spoken with Rachel Sheley, Security Strategist and Virtual Chief Information Security Officer (vCISO) at GreyCastle Security to find out about her career in the healthcare industry, her current role in cybersecurity, and her experiences with HIPAA compliance. Tell the readers about your career in the healthcare industry. My career in the healthcare industry has been centered around ensuring the confidentiality, integrity, and availability of healthcare data while navigating the complex landscape of healthcare regulations. My expertise in information security, risk management, and compliance is crucial in safeguarding patient information and maintaining the trust of healthcare organizations and their patients. Obtaining the Healthcare Information Security & Privacy Practitioner (HCISPP) certification in 2019 indicates my knowledge of healthcare information security and privacy. This certification is highly relevant in the healthcare sector, as it demonstrates expertise in safeguarding sensitive healthcare data, complying with regulations like HIPAA, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist