25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

FBI and CISA Issue Warning About BianLian Ransomware and Extortion Group

A joint cybersecurity alert has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) about the BianLian ransomware and data extortion group. The BianLian group has been conducting attacks in the United States since at least June 2022 and has actively targeted critical infrastructure organizations, including the healthcare and public health sector. The BianLian group is a ransomware actor that develops and uses ransomware in its attacks, typically engaging in double extortion tactics, where sensitive private data is exfiltrated from victims’ networks before files are encrypted. The group threatens to leak the stolen data if the ransom is not paid. This year, the group has largely switched to extortion-only attacks where files are not encrypted after exfiltration. These attacks have proven to be effective as the release of stolen data can cause significant damage to an organization’s reputation and legal complications. The BianLian group primarily gains access to victims’...

Read More
What is a HIPAA Compliant Phone Number?
May17

What is a HIPAA Compliant Phone Number?

A HIPAA-compliant phone number is most often a secondary phone number used by healthcare providers for communications in which Protected Health Information (PHI) may be disclosed. In many cases, the HIPAA-compliant phone number is a virtual phone number used by systems with secure voice, messaging, and video capabilities that are configured to comply with HIPAA. What is a HIPAA-compliant phone number? Why have a secondary phone number? What is a virtual phone number? Which HIPAA-compliant systems use virtual phone numbers? How do secondary phone numbers support HIPAA compliance? What else may healthcare providers need to consider? What is a HIPAA Compliant Phone Number? A HIPAA-compliant phone number is a number linked to a communication system that complies with the administrative, physical, and technical safeguards of the Security Rule. Because the system complies with HIPAA, it can be used to make calls, send secure messages, conduct telemedicine consultations, and much more without risking the confidentiality of PHI. This article explains why a HIPAA-compliant phone number is...

Read More
Almost 6 Million Individuals Affected by PharMerica Data Breach
May17

Almost 6 Million Individuals Affected by PharMerica Data Breach

In late March 2023, the Money Message ransomware group announced it had breached the systems of PharMerica and its parent company, BrightSpring Health Services, and added both to its data leak site. The group claimed to have exfiltrated databases containing 4.7 terabytes of data which included the records of more than 2 million individuals. PharMerica has now confirmed the extent of the data breach. PharMerica is one of the largest providers of pharmacy services in the United States, operating more than 2,500 facilities and over 3,100 pharmacy and healthcare programs. PharMerica and BrightSpring have now completed their investigation and have confirmed that there was unauthorized accessing of sensitive patient information and reported the data breach to the Maine Attorney General and HHS’ Office for Civil Rights as affecting 5,815,591 individuals. That makes it the largest healthcare data breach to be reported by a single HIPAA-covered entity so far in 2023. PharMerica explained in its notification letters that suspicious activity was detected within its computer network on...

Read More
EyeMed Vision Care Settles Multistate Data Breach Investigation for $2.5 Million
May17

EyeMed Vision Care Settles Multistate Data Breach Investigation for $2.5 Million

In June 2020, the Luxottica Group PIVA-owned vision insurance company, EyeMed Vision Care, experienced a data breach involving the protected health information (PHI) of 2.1 million patients. An unauthorized individual gained access to an employee email account that contained approximately 6 years of personal and medical information including names, contact information, dates of birth, Social Security numbers, vision insurance account/identification numbers, medical diagnoses and conditions, and treatment information. The unauthorized third party then used the email account to distribute around 2,000 phishing emails. State attorneys general have the authority to investigate data breaches and can fine organizations for HIPAA violations. A multi-state investigation was launched by state attorneys general in Oregon, New Jersey, and Florida into the EyeMed data breach, and Pennsylvania later joined the multistate action. The state attorneys general sought to establish whether the data breach was preventable and if it was the result of a failure to comply with the HIPAA Security Rule and...

Read More
OCR Fines Arkansas Business Associate $350,000 for Impermissibly Disclosing ePHI
May16

OCR Fines Arkansas Business Associate $350,000 for Impermissibly Disclosing ePHI

The HHS’ Office for Civil Rights (OCR) has agreed to settle a HIPAA investigation of an Arkansas business associate that impermissibly disclosed the electronic protected health information (ePHI) of more than 230,000 individuals after failing to secure a File Transfer Protocol (FTP) server. MedEvolve, Inc. is a Little Rock, AR-based HIPAA business associate that provides practice management, revenue cycle management, and practice analytics software to HIPAA-regulated entities. The nature of MedEvolve’s business means it has access to ePHI from its HIPAA-regulated entity clients. Under HIPAA, MedEvolve is required to ensure that information is safeguarded at all times. In July 2018, MedEvolve informed OCR that an error had been made configuring an FTP server. MedEvolve’s investigation revealed the server contained the ePHI of 230,572 individuals, which could be freely accessed over the Internet without authentication. The breach affected two HIPAA-regulated entities: Premier Immediate Medical Care, LLC (204,607 individuals) and Dr. Beverly Held (25,965 individuals). The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist