25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

More Than 4 Million Individuals Affected by Cyberattack on Independent Living Systems
Mar15

More Than 4 Million Individuals Affected by Cyberattack on Independent Living Systems

Independent Living Systems, LLC (ILS), a Miami, FL-based provider of third-party administrative services to managed care organizations, has recently informed the Maine Attorney General that it suffered a data breach that has affected up to 4,226,508 individuals – the largest healthcare data breach to be reported so far this year. According to the breach notification, ILS identified suspicious activity within its computer systems on July 5, 2022. Assisted by third-party cybersecurity experts, ILS determined that unauthorized individuals accessed its network between June 30, 2022, and July 5, 2022, and acquired files containing sensitive data. ILS conducted a comprehensive review of all affected files and was provided with the results of the review on January 17, 2023. ILS then worked to validate those results and obtain up-to-date contact information for the affected individuals to allow HIPAA notification letters to be sent. The information compromised included names, addresses, dates of birth, state ID numbers, Social Security numbers, taxpayer ID numbers, financial account...

Read More

HHS Requests Additional $38 Million in Funding for OCR in Fiscal Year 2024

The Department of Health and Human Services has requested an additional $38 million in federal funding for the Office for Civil Rights (OCR), almost doubling the appropriations OCR currently 3receives. OCR enforces 55 privacy, security, civil rights, and religious freedoms statutes and its caseload continues to increase, but its budget has remained flat for many years, only increasing in line with inflation. The years of flat budget have seen its resources and staff become increasingly strained. Ahead of the funding request, the HHS announced that it has restructured OCR to improve efficiency and get more out of its limited resources. The restructuring will help OCR to reduce the current backlog of investigations, but restructuring alone is not enough. “Since FY 2017, OCR has received a 28 percent increase in HIPAA complaints, and a 100 percent increase in HIPAA large breach reports, while OCR’s enforcement staff decreased by 45 percent due to flat budgets and inflationary increases,” explained the HHS in the report. OCR has also seen declining civil monetary collections since 2019...

Read More
$3 Million Settlement with Blackbaud Resolves SEC Allegations of Misleading Disclosures About Ransomware Attack
Mar13

$3 Million Settlement with Blackbaud Resolves SEC Allegations of Misleading Disclosures About Ransomware Attack

The Securities and Exchange Commission (SEC) has agreed to a $3 million settlement with Blackbaud Inc. to resolve charges that the company issued misleading statements about the impact of its 2020 ransomware attack. Blackbaud is a Charleston, SC-based cloud computing provider that serves the social good community. In May 2020, malicious actors gained access to its self-hosted private cloud environment and used ransomware to encrypt files. The forensic investigation confirmed the hackers gained access to files that included donor information such as names, addresses, phone numbers, email addresses, and birth dates. According to Blackbaud, approximately 13,000 customers were affected. In July 2020, Blackbaud confirmed that the attack was blocked before the attackers were able to encrypt its systems fully, but not in time to prevent a copy of certain data from being stolen from its cloud environment. Blackbaud paid the ransom to ensure the stolen information was deleted and received proof that the stolen data had been deleted. Blackbaud initially said no financial information or...

Read More

Reventics Facing Class Action Lawsuit Over Royal Ransomware Attack and Data Breach

Revenetics is facing a class action lawsuit over its December 2022 cyberattack and data breach that affected more than 250,000 individuals. Revenetics is a revenue cycle management company that provides its software solutions to many healthcare providers. On December 15, 2023, Revenetics detected a system intrusion and confirmed on December 27, 2022, that the attackers exfiltrated files that included names, dates of birth, clinical information, financial information, procedure and service codes, and healthcare provider and health plan names. The Royal ransomware group claimed responsibility for the attack and issued a ransom demand to prevent the publication of the 16GB of data allegedly stolen in the attack. The Royal ransomware group is known to target healthcare organizations and typically exfiltrates data and then issues ransom demands of between $250,000 and $2 million to prevent the publication of the stolen data. When ransoms are not paid, the group published the stolen data on its data leak site. In February 2023, Royal started to publish Revenetics data on its data leak...

Read More
ZOLL Medical Says 1 Million Patients Affected by January Cyberattack and Data Breach
Mar13

ZOLL Medical Says 1 Million Patients Affected by January Cyberattack and Data Breach

ZOLL Medical has recently announced that it has suffered a cyberattack in which the protected health information of more than one million patients was exposed. ZOLL Medical develops and markets emergency care medical devices such as resuscitation, ventilation, oxygen therapy, and cardiac monitoring products and associated software solutions. According to the notification letter sent to the Maine Attorney General, unusual activity was detected within its internal network on January 28, 2023. The forensic investigation revealed on February 2, 2023, that unauthorized individuals had gained access to parts of the network that included patient information such as names, addresses, dates of birth, and Social Security numbers. The individuals affected either used or were previously considered for use of the ZOLL LifeVest wearable cardioverter defibrillator (WCD). ZOLL Medical did not provide details of the exact nature of the cyberattack, such as whether malware or ransomware was involved, nor if any data was exfiltrated, but did state that no evidence of actual or attempted misuse of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist