25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Reventics Facing Class Action Lawsuit Over Royal Ransomware Attack and Data Breach

Revenetics is facing a class action lawsuit over its December 2022 cyberattack and data breach that affected more than 250,000 individuals. Revenetics is a revenue cycle management company that provides its software solutions to many healthcare providers. On December 15, 2023, Revenetics detected a system intrusion and confirmed on December 27, 2022, that the attackers exfiltrated files that included names, dates of birth, clinical information, financial information, procedure and service codes, and healthcare provider and health plan names. The Royal ransomware group claimed responsibility for the attack and issued a ransom demand to prevent the publication of the 16GB of data allegedly stolen in the attack. The Royal ransomware group is known to target healthcare organizations and typically exfiltrates data and then issues ransom demands of between $250,000 and $2 million to prevent the publication of the stolen data. When ransoms are not paid, the group published the stolen data on its data leak site. In February 2023, Royal started to publish Revenetics data on its data leak...

Read More
ZOLL Medical Says 1 Million Patients Affected by January Cyberattack and Data Breach
Mar13

ZOLL Medical Says 1 Million Patients Affected by January Cyberattack and Data Breach

ZOLL Medical has recently announced that it has suffered a cyberattack in which the protected health information of more than one million patients was exposed. ZOLL Medical develops and markets emergency care medical devices such as resuscitation, ventilation, oxygen therapy, and cardiac monitoring products and associated software solutions. According to the notification letter sent to the Maine Attorney General, unusual activity was detected within its internal network on January 28, 2023. The forensic investigation revealed on February 2, 2023, that unauthorized individuals had gained access to parts of the network that included patient information such as names, addresses, dates of birth, and Social Security numbers. The individuals affected either used or were previously considered for use of the ZOLL LifeVest wearable cardioverter defibrillator (WCD). ZOLL Medical did not provide details of the exact nature of the cyberattack, such as whether malware or ransomware was involved, nor if any data was exfiltrated, but did state that no evidence of actual or attempted misuse of...

Read More

Maternal & Family Health Services Sued Over Ransomware Attack and Data Breach

A lawsuit has been filed against Maternal & Family Health Services (MFHS) in Pennsylvania which alleges the healthcare provider failed to protect patient data and did not send timely breach notifications. In January 2023, MFHS, one of the largest healthcare providers in the state, notified approximately 461,000 current and former patients about a security breach. According to the notifications, unauthorized individuals gained access to its network and used ransomware to encrypt files. MFHS said the sophisticated ransomware attack was discovered in April 2022. The forensic investigation confirmed the attackers had access to its network between August 2021 and April 2022, during which time they had access to, and potentially stole, patient data such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account/payment card information, medical information, and health insurance information. At the time of issuing notifications, misuse of patient data had not been detected; however, as a precaution, complimentary credit monitoring and...

Read More
HC3 Sheds Light on Data Exfiltration Trends in Healthcare Cyberattacks
Mar10

HC3 Sheds Light on Data Exfiltration Trends in Healthcare Cyberattacks

The Health Sector Cybersecurity Coordination Center has issued a security advisory warning about data exfiltration in healthcare cyberattacks, highlighting the extent of the practice and sharing several recommended mitigations. Data exfiltration typically occurs once a threat actor has gained access to a network, elevated privileges, and moved laterally. Data exfiltration is one of the last stages of the cyber kill-chain and the primary objective in many cyberattacks. There are several reasons for data theft. Nation-state actors often steal data for espionage purposes, cybercriminal groups steal healthcare data as it can be easily monetized and as leverage for extortion, and insiders steal data for financial gain, competitive advantage, and blackmail. When ransomware first started to be used by cybercriminal groups, files were simply encrypted; however, data exfiltration is now common. Data theft allows ransomware actors to profit from attacks when ransoms are not paid, and oftentimes it is the threat of publication of stolen data that prompts victims to pay up. Such is the...

Read More

Ransomware Attack Announced by Codman Square Health Center

Codman Square Health Center in Boston, MA, has confirmed that it was the victim of a ransomware attack in November 2022 in which hackers gained access to the protected health information of 10,161 current and former patients. The incident was detected on November 28, 2022, and third-party digital forensics experts were engaged to investigate the security breach and determine the nature and scope of the attack. The investigation confirmed that unauthorized individuals gained access to parts of its network between November 23 and November 28, and during which time they may have viewed or acquired files containing patient data. Codman Square Health Center said it was confirmed on January 25, 2023, that a folder on the compromised part of its network contained patient data, although it was not possible to tell if that folder was accessed. The files in that folder included names, addresses, birth dates, medical record numbers, diagnoses, treatment information, and claims information. Notifications are being sent to affected individuals and steps have been taken to improve privacy and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist