25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Medtronic Alerts InPen App Users About Disclosures of Personal Data to Google

The medical device manufacturer Medtronic – dba Medtronic MiniMed and MiniMed Distribution Corp (Medtronic Diabetes) – has recently confirmed that the personal information of users of its InPen Diabetes Management App on iOS and Android have had some of their personal information disclosed to Google due to the use of tracking and authentication code within the InPen App. The app utilized Google Analytics for Firebase, Crashlytics for Firebase, and Firebase Authentication. These tools disclosed certain information about app users to Google, especially when users were logged into their Google accounts at the same time that they used the InPen App. As a result, their identities and information about online activities were shared with Google. The tools were used by Medtronic Diabetes to gather information about the use of the app, identify technical issues, assess app performance, and understand user needs to provide care to customers and improve services. Medtronic Diabetes said the data collected by these tools is analyzed at a consolidated rather than individual level...

Read More
Veterans’ Healthcare Facility in Arizona Exposed Employees to Potentially Deadly Hazards
Apr19

Veterans’ Healthcare Facility in Arizona Exposed Employees to Potentially Deadly Hazards

A U.S. Department of Labor investigation of an Arizona Department of Veteran Affairs (VA) healthcare facility found workers had been put at risk by exposing them to potentially deadly hazards on steam lines. Employees were allowed to work on the steam lines without ensuring they followed the required safety procedures. Federal agencies such as the VA are required to comply with the same safety and health standards as private sector employers that are covered by the Occupational Safety and Health (OSH) Act and must ensure that employees conduct their work duties safely and are not exposed to grave danger from hazards. Federal safety inspectors visited the VA’s Prescott facility, operated by the Northern Arizona Veterans Affairs Health Care System, in October 2022 to assess compliance and determined that the facility lacked energy-isolating procedures known as lockout/tagout, which prevents the release of hazardous energy during the maintenance and servicing of steam lines. Employees were found to be using ad-hoc methods that did not meet Occupational Safety and Health...

Read More
DC Health Link Data Breach Caused by Human Error
Apr19

DC Health Link Data Breach Caused by Human Error

Further information has been released on the data breach at the Washington DC health insurance exchange, DC Health Link, ahead of a House Oversight Committee’s subcommittee on cybersecurity, information technology, and government innovation hearing today. The HIPAA data breach was detected by DC Health Link on March 6, 2023, Mandiant was engaged to investigate the data breach, and by March 8 the source of the breach had been identified, and it was immediately shut down; however, files were stolen and some of the compromised information was listed for sale on an online hacking forum. DC Health Link has offered complimentary credit monitoring and identity theft protection services to affected individuals. Mila Kofman, executive director of DC Health Link, said the internal investigation into the data breach is ongoing; however, she was able to share further information about the security incident and data breach and will be discussing the findings of Mandiant’s investigation at today’s hearing. Last week, the two chairs of the subcommittee, Reps. Nancy Mace (R-South Carolina)...

Read More

Lawsuit Filed Against Conifer & Tenet Healthcare Over Email Account Breach

A class action lawsuit has been filed against Conifer and Tenet Healthcare over a breach of the protected health information of thousands of individuals. The lawsuit names Conifer Value-Based Care, Conifer Health Solutions, Conifer Revenue Cycle Solutions, and Tenet Healthcare Corporation as defendants. Conifer provides revenue cycle management and value-based care services and all Conifer entities are subsidiaries of, and therefore under the control of, Tenet Healthcare. The lawsuit was filed in the U.S. District Court Northern District of Texas, Dallas Division, on behalf of plaintiff Nicole Kolb, and similarly situated individuals. The plaintiff and class are represented by Joe Kendall of Kendall Law Group, Samuel J. Strauss and Raina Borrelli of Turke & Strauss, and Gary. M. Klinger of Milberg Coleman Bryson Phillips Grossman. The lawsuit was filed in response to a breach of a Microsoft 365-hosted business email account that was detected on April 14, 2022. The investigation concluded the account was compromised on January 20, 2023. The information in the compromised email...

Read More

Mandiant Shares Threat Intelligence from 2022 Cyber Incident Investigations

The Google-owned cybersecurity firm Mandiant has released its M-Trends 2023 report. The report provides insights into the rapidly evolving cyber threat landscape and can help network defenders better protect their systems and data from malicious actors. The data for the report came from Mandiant’s investigations and remediation of cyberattacks worldwide, including some of the most high-impact attacks in the past 12 months. The data suggests that organizations have managed to strengthen their defenses; however, cybercriminals have been conducting increasingly sophisticated attacks and in many cases have managed to stay one step ahead. One of the key findings from this year’s report is malicious actors are spending far less time in victims’ environments, with 2022 seeing another year-over-year drop in dwell time from 21 days in 2021 to just 16 days, which is the shortest average dwell time in any of the 14 years that Mandiant has been producing its M-Trends reports. Victims have even less time to detect a compromise and they are already struggling to identify these intrusions....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist