25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Credential Stuffing Attack Exposed United HealthCare Member Data

United HealthCare (UHC) has started notifying certain members that some of their protected health information may have been disclosed to unauthorized individuals as a result of credential stuffing attacks on the UHC mobile application. Credential stuffing is a type of attack where username and password combinations obtained in a breach at one platform are used to access accounts on an unrelated platform. These attacks can only succeed if usernames and passwords have been reused on multiple platforms. The accounts subjected to unauthorized access included information such as names, birthdates, addresses, health insurance member ID numbers, service dates, provider names, claim details, and group names and numbers. No Social Security numbers, financial information, or driver’s license numbers were exposed. The attacks occurred between February 19 and February 25, 2023. UHC took its portal offline immediately when the attacks were detected to prevent further unauthorized access and a password reset was performed. The investigation found no evidence to suggest the credentials had been...

Read More

HC3: Ransomware Groups are Exploiting GoAnywhere and PaperCut Vulnerabilities

The Health Sector Cybersecurity and Coordination Center (HC3) has issued a fresh ransomware warning to the healthcare and public health (HPH) sector following a spate of attacks on the HPH sector in April by the Clop and LockBit ransomware groups. HC3 has issued multiple alerts about the Clop and LockBit ransomware-as-a-service groups which have conducted multiple attacks on the healthcare sector. Clop was behind the attacks on Fortra’s GoAnywhere MFT solution in January/February 2023 and the 2022 attacks on the Accellion File Transfer Application (FTA), both of which exploited zero-day vulnerabilities in those solutions. The latest alert about LockBit was issued in December 2022 following multiple attacks on HPH sector organizations. The Clop group exploited the GoAnywhere MFT vulnerability (CVE-2023-0669) and stole data from around 130 organizations, and both groups have been observed exploiting two other recently disclosed vulnerabilities – CVE-2023-27350 and CVE-2023-27351 – which are authentication bypass vulnerabilities in the widely used print management software,...

Read More

90 Degree Benefits Facing Class Action Lawsuit Over 181,500-Record Data Breach

A lawsuit has been filed against 90 Degree Benefits over a breach of the HIPAA protected health information of 181,543 individuals. Unauthorized system activity was detected on or around December 10, 2022, and the forensic investigation determined its systems had been accessed by unauthorized individuals between December 5, 2022, and December 10, 2022. During that time, the attackers had access to parts of its network that contained patients’ and health plan members’ names, addresses, dates of birth, Social Security numbers, health information, and payment information. Affected individuals were notified about the breach by mail on or around April 7, 2023. The lawsuit alleges 90 Degree Benefits knew or should have been aware that it was a target for hackers, given the extent to which the healthcare industry has been targeted in recent years, especially considering 90 Degree Benefits experienced a similar data breach in February 2022. The February data breach should have made it clear that its data security measures were not sufficient and needed to be improved, yet despite that...

Read More
House Democrats Reintroduce Protecting America’s Workers Act on Worker’s Memorial Day
May01

House Democrats Reintroduce Protecting America’s Workers Act on Worker’s Memorial Day

The Protecting America’s Workers Act was reintroduced by Reps. Joe Courtney (D-CT) and Bobby Scott (D-VA) on Worker’s Memorial Day and seeks to expand the coverage of the Occupational Safety and Health (OSH) Act to include the estimated 8 million state and local government workers in 24 states that are not currently covered by the act and increase the financial penalties for “high gravity” OSHA violations. The Protecting America’s Workers Act also seeks to reinstate the Volks Rule, which was repealed from OSHA by President Trump in 2017. The Volks Rule gave OSHA the authority to enforce recordkeeping requirements for work-related injuries and illnesses for five-and-a-half years rather than the 6-month statute of limitations established by OSHA. The Protecting America’s Workers Act has 12 co-sponsors and seeks to improve safety and health in the workplace by addressing the current shortfalls in OSHA. “Millions of workers still fall outside the law’s protections, weak sanctions fail to provide meaningful incentives for those employers tempted to cut corners on compliance with safety...

Read More

Organizations Face Increased Scrutiny of Health Data Breaches

Healthcare hacking incidents are increasing, there are new regulatory requirements and compliance initiatives due to Dobbs and Pixel use, and lawsuits against healthcare organizations over privacy violations are soaring. HIPAA-regulated entities and other organizations that operate in the healthcare space are now facing increased scrutiny of their data security practices and compliance programs, and the coming 12 months will likely see an increase in enforcement actions and lawsuits over privacy violations. The recently published BakerHostetler Data Security Incident Response Report (DSIR) draws attention to these issues and provides insights into the threat landscape to help organizations determine how to prioritize their efforts and investments. The report, now in its 9th year, was based on 1,160 security incidents managed by BakerHostetler’s Digital Assets and Data Management Practice Group in 2022. After a surge in ransomware attacks in 2021, 2022 saw a reduction in attacks; however, there was a surge in ransomware activity toward the end of the year and that surge has...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist