25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

October 2022 Healthcare Data Breach Report
Nov22

October 2022 Healthcare Data Breach Report

October was the worst month of the year to date for healthcare data breaches, with 71 breaches reported and more than 6 million records breached. The first half of the year was looking like 2022 would see a reduction in healthcare data breaches; however, that is looking increasingly unlikely. In 2021, 714 data breaches of 500 or more records were reported to the HHS’ Office for Civil Rights. 594 data breaches were reported between January 1 and October 31, and with an average of 60 data breaches being reported each month, 2022 looks set to end with a similarly high number. Across the 71 reported HIPAA compliance breaches, the protected health information of 6,242,589 individuals was exposed or impermissibly disclosed, with around half of that total coming from a single breach. So far this year, the records of 37,948,207 individuals have been exposed or impermissibly disclosed. Largest Healthcare Data Breaches Reported in October In October, 28 data breaches of 10,000 or more records were reported by HIPAA-regulated entities. The largest healthcare data breach reported in October –...

Read More
10 Charged Over BEC Scams Targeting Medicare, Medicaid, and Private Insurance Programs
Nov21

10 Charged Over BEC Scams Targeting Medicare, Medicaid, and Private Insurance Programs

The U.S. Department of Justice has charged 10 individuals over business email compromise scams that have resulted in more than $11.1 million being defrauded from Medicaid, Medicare, and private health insurance programs. The payments were intended for hospitals for providing covered medical services. Business email compromise (BEC) scams involve gaining access to legitimate email accounts and using them to trick individuals responsible for wire transfers into making fraudulent payments to attacker-controlled accounts and these scams are the biggest cause of losses to cybercrime. According to the FBI, more than $43 billion was lost to these scams between June 2016 and December 2021, and in 2021 alone, the FBI Internet Crime Complaint Center received reports of losses of $2,395,953,296 to BEC scams. The arrests were related to a series of scams that spoofed hospital email accounts. The individuals allegedly involved in these attacks sent emails requesting changes be made to the bank account details on file for all future payments. The accounts had been recently set up by money mules,...

Read More
Are Email Addresses Protected by HIPAA?
Nov21

Are Email Addresses Protected by HIPAA?

Email addresses are protected by HIPAA when they are maintained by or on behalf of a HIPAA covered entity in designated record sets containing individually identifiable health information and the email addresses could identify – or be used to identify – the subject of the individually identifiable health information. However, there are many scenarios in which email addresses are not protected by HIPAA. To understand when are email addresses protected by HIPAA, it is important to understand what is considered Protected Health Information (PHI) under HIPAA. This is because HIPAA only protects by default individually identifiable health information relating to an individual’s health condition, treatment for the health condition, and payment for the treatment. Information of this nature is maintained in one or more designated record sets by a HIPAA covered entity. Any other information that could identity – or be used to identify – the subject of the health, treatment, or payment information assumes the same protected status as individually identifiable health information when it...

Read More

Forefront Dermatology Proposes $3.75 Million Settlement to Resolve Ransomware Lawsuit

The Wisconsin-based dermatology practice, Forefront Dermatology, has agreed to settle a class action lawsuit filed on behalf of patients whose protected health information (PHI) was compromised in a ransomware attack in late May 2021. Forefront Dermatology has affiliated practices in 21 states and Washington D.C. In May 2021, the practice was targeted by the Cuba ransomware gang, which gained access to its network and exfiltrated files from the network before encrypting data. The gang then dumped some of the stolen data on its dark web data leak site to pressure the practice into paying the ransom. According to Forefront Dermatology’s data breach notice, the attack was detected on June 4. The forensic investigation confirmed the attackers potentially accessed and stole files containing the PHI of up to 2.4 million employees and patients. That information included names, dates of birth, account numbers, health insurance information, Social Security numbers, medical record numbers, medical and treatment information, and other sensitive data. A class action lawsuit was filed in the...

Read More

Feds Issue Warning to HPH Sector About Aggressive Hive Ransomware Group

The Hive ransomware-as-a-service (RaaS) operation first emerged in June 2021 and has aggressively targeted the health and public health sector (HPH) and continues to do so. From June 2021 until November 2022, the group conducted attacks on more than 1,300 organizations worldwide, generating more than $100 million in ransom payments. Victims in the HPH sector include the public health system in Costa Rica, Partnership HealthPlan of California, Memorial Health System, Missouri Delta Medical Center, Southwell, Hendry Regional Medical Center, and Lake Charles Memorial Health System, with the latter currently recovering from the attack that occurred this month. The attacks put patient safety at risk and have forced hospitals to divert ambulances, cancel surgeries, postpone appointments, and close urgent care units. On November 17, 2022, the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) issued a joint alert to the HPH sector warning about the risk of attacks and shared Indicators...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist