25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Critical Citrix ADC and Gateway Vulnerability Exploited in Attacks on Healthcare Organizations
Dec20

Critical Citrix ADC and Gateway Vulnerability Exploited in Attacks on Healthcare Organizations

Citrix Application Delivery Controller (ADC) and Citrix Gateway users have been urged to check to make sure that their systems are not vulnerable to a critical unauthenticated remote code execution vulnerability, which is being actively exploited by a highly capable Chinese advanced persistent threat (APT) actor and potentially other state-sponsored hacking groups. Citrix ADC is a comprehensive application delivery and load-balancing solution that is used by healthcare organizations to ensure the constant availability of critical clinical applications, including electronic medical records. Citrix Gateway is used by healthcare organizations for remote access and for providing single sign-on across all applications. The Citrix ADC and Gateway authentication bypass vulnerability is tracked as CVE-2022-27518 and has been assigned a CVSS v3 severity score of 9.8 out of 10. The flaw can be exploited remotely by an unauthenticated actor to execute code and completely compromise the system. Mandiant has observed a Chinese state-sponsored hacking group exploiting the flaw. The APT actor is...

Read More
HHS Proposes New Rule to Implement HIPAA Standards for Healthcare Attachments and Electronic Signatures
Dec19

HHS Proposes New Rule to Implement HIPAA Standards for Healthcare Attachments and Electronic Signatures

The Secretary of the Department of Health and Human Services (HHS) has proposed a new rule that will require the adoption of standards for healthcare attachments transactions and electronic signatures used in conjunction with those transactions to support healthcare claims and prior authorization transactions. The new rule will implement the requirements of the Administrative Simplification Requirements of HIPAA and the Affordable Care Act and will apply to all health plans, healthcare clearinghouses, and healthcare providers that currently lack an efficient, uniform method of sending attachments. Currently, when making coverage decisions about healthcare services, health plans often require additional information that cannot be added to the specified fields or data elements of the adopted prior authorization request or healthcare claims transaction. Currently, this information is sent through the mail or by fax and is subject to manual processes that consume considerable time and resources. At present, there are no adopted HIPAA standards, implementation guides, or operating rules...

Read More

Avem Health Partners and Emory Healthcare Notify Patients About Data Breaches

Avem Health Partners, an Oklahoma City-based provider of administrative and technology services to healthcare organizations, has recently started notifying its healthcare clients about a data breach that occurred at one of its vendors, 365 Data Centers. On September 9, 2022, 365 Data Centers notified Avem Health Partners that an unauthorized third party had gained access to its servers. The breach was detected on May 16, 2022, with the investigation confirming there may have been unauthorized access to data stored on those servers prior to May 14, 2022. Avem Health Partners did disclose in its website substitute breach notice when its vendor’s servers were first breached. A review of the files on the compromised servers confirmed that HIPAA protected health information such as patient names, dates of birth, Social Security numbers, driver’s license numbers, health insurance information, and diagnosis and treatment information had been exposed. Avem Health Partners is issuing breach notification letters to affected individuals on behalf of its vendor and complimentary credit...

Read More

Improper Use of Password Managers Is Increasing

Passwords can provide a good level of security, but all too often users choose weak passwords that present no challenge to hackers. Many of the most commonly used passwords can be cracked almost instantly. A recent study by NordPass involved an analysis of a 3TB database of passwords and found ‘password’ to have been used to secure 4.9 million accounts, with the next weakest password – 123456 – used on 1.5 million accounts. Security awareness is improving, but many users still set weak passwords for convenience despite the risk of accounts being compromised. It is also common for users to set the same password for multiple accounts. This bad practice puts users at risk of credential stuffing attacks. If the password is compromised on one platform, all other accounts with the same username and password combination can also be accessed. One of the most cost-effective and easiest ways to improve password security is to provide employees with a password manager. Password managers suggest strong, unique passwords, auto-fill them when they are needed, and store the passwords...

Read More

Most Important Factors for Improving Cyber Resilience

Cyberattacks have increased in volume and sophistication to the point where it is inevitable that a successful attack will be experienced by all healthcare organizations at some point in their lifespan. Healthcare organizations can hope for the best, but it is vital to plan for the worst and take steps to ensure that the damage caused is kept to a minimum. A major focus for security teams, in addition to reducing risks, is improving cyber resilience. Cyber resilience is the ability of an organization to continue to operate in the event of a cyberattack and to recover quickly. A recent survey by Cisco indicates executives are aware of the importance of cyber resilience, with 96% of respondents saying cyber resilience is a high priority, and deservedly so, since 62% of respondents said their organization had experienced a security breach in the past two years – a combination of data breaches (51.5%), network/system outages (51.1%), ransomware attacks (46.7%), and DDoS attacks (46.4%). These attacks had severe repercussions for the breached entities, causing disruption to IT systems,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist