NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

NationsBenefits Holdings Confirms 3 Million Record Data Breach

NationsBenefits Holdings, LLC, a provider of supplemental benefits, flex cards, and member engagement solutions to health plans and managed care organizations, has confirmed that it has been affected by a HIPAA security breach involving Fortra’s GoAnywhere MFT file transfer solution. The hackers behind the attack – the Clop ransomware group – gained access to NationsBenefits data on January 30, 2023, and exfiltrated that information from the GoAnywhere MFT solution. A ransom demand was issued, payment of which was required to prevent the publication of the stolen data. NationsBenefits was one of 130 organizations to have data stolen in the attacks. The Clop group exploited a previously unknown (zero-day) vulnerability in the GoAnywhere MFT solution, which allowed them to access and steal data from vulnerable on-premises MFT servers. NationsBenefits Holdings said the Clop group was only able to access two MFT servers; however, a review of the files on those servers revealed they contained the protected health information of 3,037,303 health plan members, including, but not limited...

Read More
Brightline: At Least 964,300 Individuals Affected by Fortra GoAnywhere Hack
May08

Brightline: At Least 964,300 Individuals Affected by Fortra GoAnywhere Hack

Brightline, a provider of virtual behavioral and mental services to families, has confirmed it was affected by the cyberattack on Fortra’s GoAnywhere MFT file transfer solution, which saw a zero-day vulnerability exploited in attacks on 130 organizations over a 10-day period starting on January 18, 2023. While the Clop threat group conducts ransomware attacks, ransomware was not used in these attacks. Like the attacks that exploited a vulnerability in the Accellion File Transfer Appliance (FTA) in 2021, the group opted for data theft and extortion with no file encryption. Brightline explained in its website breach notification that the attack occurred on January 30, 2023, and said Fortra’s investigation confirmed that files had been downloaded that contained protected health information. Brightline was notified about the attack by Fortra on February 4, 2023. Brightline’s internal investigation confirmed that the attack was limited to data within the GoAnywhere solution and that its systems had not been compromised. After determining the extent of the breach and the individuals...

Read More

Ransomware Attack Results in 2 Week Shutdown of Operations at TN Medical Clinic

A cyberattack on Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee forced the healthcare provider to completely shut down operations for around two weeks to contain to attack and restore its IT systems. It is common for healthcare organizations to perform an emergency shutdown of the network to contain a cyberattack and limit the harm caused, and to operate under emergency procedures with staff recording patient information manually while systems are out of action. Some attacks see ambulances diverted and some appointments canceled for patient safety reasons, but the disruption caused by this attack was much more extensive. The cyberattack occurred on April 22, 2023, and the network was rapidly shut down to contain the attack. Third-party cybersecurity experts were engaged to assist with the investigation and recovery from the attack. MMC said the rapid action taken in response to the security breach limited the damage caused, and work has continued round the clock to safely bring systems back online and enhance security controls. MMC has been working with...

Read More
Illumina Sequencing Instruments Affected by Maximum Severity Vulnerability
May05

Illumina Sequencing Instruments Affected by Maximum Severity Vulnerability

Healthcare providers and laboratory personnel have been warned about a maximum severity vulnerability in Illumina Universal Copy Service software used by its DNA sequencing instruments. The vulnerability affects Illumina products with Illumina Universal Copy Service (UCS) v2.x installed: iScan Controls Software (v4.0.0 and v4.0.5) iSeq 100 (all versions) MiniSeq Control Software (v2.0 and later) MiSeq Control Software (v4.0 RUO Mode) MiSeqDx Operating Software (v4.0.1 and later) NextSeq 500/550 Control Software (v4.0) NextSeq 550Dx Control Software (v4.0 RUO Mode) NextSeq 550Dx Operating Software (v1.0.0 to 1.3.1) NextSeq 550Dx Operating Software (v1.3.3 and later) NextSeq 1000/2000 Control Software (v1.4.1 and prior) NovaSeq 6000 Control Software (v1.7 and prior) NovaSeq Control Software (v1.8) Affected devices are vulnerable to two flaws, the most serious of which – CVE-2023-1699 – allows binding to an unrestricted IP address. If exploited, a malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remove communications,...

Read More

Patient No Longer Seeking Injunction to Force Healthcare Provider to Pay Ransom

There has been an update to a lawsuit filed against Lehigh Valley Health Network over a ransomware attack that involved the theft of sensitive patient data and the publication of naked images of patients on the Internet. Lehigh Valley Health Network detected the ransomware attack on February 6, 2023, and was issued with a ransom demand. The BlackCat group threatened to release the stolen data online if the ransom was not paid. While it is common for ransomware gangs to steal sensitive data and publish files if the victim fails to cooperate, the BlackCat ransomware group took the extortion a step further and published naked images of patients to pressure Lehigh Valley Health Network into paying the ransom. The images in question were clinically appropriate for radiation oncology treatment and showed patients naked from the waist up. The ransomware group was seeking payment of approximately $5 million. Lehigh Valley Health Network chose not to pay the ransom. A lawsuit was filed in the Court of Common Pleas of Lackawanna County in Pennsylvania, which alleged Lehigh Valley Health...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist