25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Three Healthcare Providers Report Phishing Attacks

Livonia, MI-based Trinity Health has confirmed that an unauthorized individual gained access to an employee email account and potentially viewed or obtained patient information. Suspicious account activity was detected in the employee’s email account on January 5, 2023. The investigation confirmed unauthorized access to the email account occurred between December 16, 2022, and December 18, 2022. A review of the contents of the account was completed on February 14, 2023. The types of information in the account varied from patient to patient and may have included names, medical record numbers, patient ID numbers, encounter numbers, location(s) of service, provider names and specialties, procedure name(s), insurance name/type, billing balances, and dates of birth. A limited number of individuals had their address, phone number, email address, and prescription information exposed. Trinity Health changed the account password to prevent further unauthorized access and has reviewed its policies and procedures. Due to the nature of the exposed information, Trinity Health believes the...

Read More

Protected Health Information Exposed in 5 Recent Hacking Incidents

Florida Medical Clinic, NorthStar Emergency Medical Services, Denver Public Schools, Wichita Urology Group, and The Bone & Joint Clinic have recently reported hacking incidents and the exposure and potential theft of protected health information. Florida Medical Clinic Florida Medical Clinic has recently announced that it was the victim of a ransomware attack. The attack was detected on January 9, 2023, and prompt action was taken to contain the attack, which limited data exposure, although files were encrypted. The third-party forensic investigation confirmed the attacker accessed files that contained patients’ protected health information; however, its electronic medical record system was not affected. In a refreshingly detailed breach notice, Florida Medical Clinic explained that 94,132 files had been exposed, each of which only contained limited patient information. 95% of the compromised files only included an individual’s name. The remaining files included names, phone numbers, email addresses, birth dates, and addresses. No financial information was compromised,...

Read More
How Much Does Cisco Umbrella Cost?
Mar16

How Much Does Cisco Umbrella Cost?

Cisco Umbrella costs less than $2 per user per month according to some reseller sites, but this price only applies if subscribe to a feature-limited plan for more than a thousand users and you are willing to pay for three years’ service in advance. If you want a higher level of protection, have a smaller user base, or want to subscribe for less than three years, expect to pay three or four times as much. The Internet is a great place to find answers to questions unless you are looking for an accurate and up-to-date answer to the question how much does Cisco Umbrella cost. Very few websites mention Cisco Umbrella pricing; and, of those that do, some claim prices are available on request, some quote prices from several years ago, and others rely on hearsay. The tell-tale sign that some sources may have accurate and up-to-date information about Cisco Umbrella pricing is that they acknowledge there is more than one Cisco Umbrella plan. There are currently four Cisco Umbrella tiers, ranging from the feature-limited DNS Essentials tier to the SIG Advantage tier – which is an advanced...

Read More
HSCC Issues Guidance for Healthcare Organizations on Managing Legacy Technology Security
Mar15

HSCC Issues Guidance for Healthcare Organizations on Managing Legacy Technology Security

This month, the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) published guidance to help healthcare delivery organizations effectively manage cyber risks associated with legacy technology. In healthcare, a great deal of attention has been focused on addressing cybersecurity risks associated with legacy medical devices, but they are not the only type of legacy technology in use in healthcare environments. Many different technologies are used that similarly become more vulnerable as they age, and continue to be used after end-of-life has been reached and support is withdrawn. Technologies include FDA-regulated devices, non-FDA-regulated devices, laboratory equipment, building and facilities technology, and a host of other technologies. While the obvious solution from a security perspective is to upgrade to modern, supported systems ahead of the technologies reaching end-of-life, that is often not practical or possible. Instead, healthcare delivery organizations need to effectively manage risks associated with these technologies....

Read More

Settlement Agreed with Florida Children’s Health Insurance Website Contractor to Resolve False Claims Act Allegations

The United States Department of Justice has agreed to settle alleged False Claims Act violations with Jelly Bean Communications Design LLC and manager Jeremy Spinks related to the failure to protect HIPAA-covered data. Jelly Bean Communications Design is a Tallahassee, FL-based company co-owned by Jeremy Spinks, who is the company’s manager and sole employee. The company provides web hosting functions and services for its clients, one of which was the Florida Healthy Kids Corporation (FHKC). FHKC is a state-created entity that offers health and dental insurance to children in Florida between the ages of 5 and 18. FHKC receives Medicaid funds and state funds for providing health insurance programs for children in Florida. On July 1, 2012, the Agency for Health Care Administration (AHCA) in Florida contracted with FHKC to provide services for the State Children’s Health Insurance Plan (SCHIP) Program, which included implementing technical safeguards to ensure the confidentiality, integrity, and availability of the electronic protected health information that was received, maintained,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist