NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

IL, KY, and TN Healthcare Orgs Recovering from Recent Cyberattacks

Morris Hospital & Healthcare Centers Investigating Royal Ransomware Attack Morris Hospital & Healthcare Centers in Illinois has launched an investigation into a cyberattack that the Royal ransomware group has claimed responsibility for. Third-party forensics experts have been engaged to investigate the breach and determine the extent to which patient information was involved. While the investigation is still in the early stages, Morris Hospital & Healthcare Centers has confirmed that its electronic medical record system was unaffected; however, patient data was stored in the network that was compromised in the attack. Morris Hospital & Healthcare Centers said it had implemented multiple security measures prior to the attack and that these were instrumental in limiting the severity of the incident. Further information will be released as the investigation progresses, and notification letters will be issued if it is determined that patient data has been compromised. On May 22, 2023, the Royal ransomware group added Morris Hospital & Healthcare Centers to its data...

Read More
Ohio Hospital Exposed Nurses and Other Staff to Workplace Violence
May30

Ohio Hospital Exposed Nurses and Other Staff to Workplace Violence

The Occupational Safety and Health Administration (OSHA) has determined a children’s hospital in Columbus, Ohio failed to adequately protect healthcare employees from workplace violence. Patients attacked nurses and other healthcare professionals and their bites, kicks, punches, and other assaults resulted in staff members sustaining serious injuries. An investigation was launched by OSHA in November 2022 following complaints from nurses and mental health staff at the Big Lots Behavioral Health Pavilion at Nationwide Children’s Hospital who had suffered serious injuries due to violent patient incidents, including lacerations, concussions, and sprains. Nationwide Children’s Hospital is the second-largest pediatric hospital in the United States and operates 68 facilities throughout Ohio and accepted over 1.5 million patient visits a year. The Big Lots Behavioral Health Pavilion provides acute behavioral healthcare services through intensive outpatient programs. OSHA determined that employees at the facility were exposed to the hazard of workplace violence due to insufficient safety...

Read More
Managed Care of North America Hacking Incident Impacts 8.9 Million Individuals
May30

Managed Care of North America Hacking Incident Impacts 8.9 Million Individuals

Managed Care of North America, Inc. (MCNA), which also does business as MCNA Dental –  a provider of dental benefits and services for state Medicaid and Children’s Health Insurance Programs – has recently reported a major HIPAA compliance data breach to the Maine Attorney General and HHS Office for Civil Rights that has affected 8,923,662 individuals. This is the largest healthcare data breach to be reported by a single covered entity so far this year, and the second 5 million record+ healthcare data breach to be reported this month. On March 6, 2023, MCNA discovered an unauthorized third party was able to access certain systems within its IT network. The threat was immediately contained and a third-party cybersecurity firm was engaged to investigate the intrusion and determine the nature and scope of the incident. The forensic investigation determined that the network had been compromised and infected with malicious code and that the attackers removed some copies of personal and protected health information from its systems between February 26, 2023, and March 7, 2023....

Read More

Ransomware Gangs Claim Three Healthcare Victims

There has been a growing breach notification trend where the exact nature of a cyberattack is not disclosed in breach notification letters, including whether there has been confirmed theft of patient data. The failure to provide this information makes it difficult for victims of data breaches to assess the level of risk they face. That appears to be the case with two recent cyberattacks, neither of which mention ransomware or confirm that data theft occurred. Albany ENT & Allergy Services Earlier this month, two ransomware groups – BianLian and RansomHouse – added Albany ENT & Allergy Services (AENT) to their data leak sites, along with claims that 1TB of data was stolen from its network before files were encrypted. Evidence of data theft was published on the RansomHouse data leak site. Albany ENT & Allergy Services has now confirmed in a notification to the Maine Attorney General that unauthorized individuals gained access to its network, which contained the protected health information of 224,486 individuals, including 61 Maine residents. AENT explained in the...

Read More

CISA & Partners Release Updated StopRansomware Guide

An updated version of the StopRansomware Guide has been published that includes further recommendations on actions that can be taken to reduce the risk of ransomware attacks. The StopRansomware Guide is a one-stop resource developed by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) that details best practices for detecting, preventing, responding to, and recovering from ransomware attacks and provides step-by-step approaches for addressing potential attacks. The updated guide was produced through the Joint Ransomware Task Force (JRTF), which was set up by Congress in 2022 to deal with the growing threat of ransomware attacks. The StopRansomware Guide can be used by government agencies and organizations and businesses of all sizes to ensure appropriate defenses are in place to block attacks and can help with the development, implementation, and maintenance of incident response plans to ensure the fastest possible recovery in the event...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist