NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Vulnerability Management and Remediation Deficiencies Identified at Alabama VA Medical Center
Jan20

Vulnerability Management and Remediation Deficiencies Identified at Alabama VA Medical Center

An inspection of information security at Tuscaloosa VA Medical Center in Alabama by the VA Office of Inspector General (OIG) uncovered deficiencies in three of the four assessed security control areas. The OIG inspection covered configuration management, contingency planning, security management, and access controls, with deficiencies identified in configuration management, security management, and access controls. Configuration management controls are required to identify and manage security features for all hardware and software components of an information system. OIG found deficiencies in vulnerability management, flaw remediation, and database scans. The Office of Information and Technology (OIT) routinely scans for vulnerabilities, and while OIG and OIT used the same vulnerability-scanning tools, OIT failed to identify all vulnerabilities. OIG identified 119 critical-risk vulnerabilities that OIT failed to detect. OIG also identified 301 vulnerabilities that had not been mitigated within the required 30- or 60-day windows, with 134 critical-risk vulnerabilities identified on...

Read More

Phishing Attack on Washington Therapist Exposes Patients’ PHI

A Washington therapist, Robert S. Miller LICSW, ACSW (RSM), has recently notified 640 current and former clients about a phishing incident that resulted in the exposure of some of their protected health information. State laws require notifications to be sent to state attorneys general when there has been a breach of the private information of state residents. The notifications typically provide the minimum information about privacy breaches, but in this case, the therapist explained exactly how the phishing attack played out. RSM had purchased an antivirus solution from the Iolo Software Company, and subsequently purchased an additional encryption program, which had disappeared from his computer. RSM was contacted by a person who claimed to be an Iolo employee who said he was aware that RSM’s computer had been hacked and requested access to clean the computer of viruses and malware. Access to the device was granted. RSM said he discovered this was a scam when the employee requested eBay cards worth $300. As a result of this incident, that individual had access to the computer from...

Read More

Tracking Code Privacy Incident Affects 29,000 Insulet Corporation Customers

The Massachusetts-based medical device company, Insulet Corporation, has recently notified 29,000 of its Omnipod DASH customers about a recent privacy breach. A Medical Device Correction letter was recently sent to customers. Due to the importance of applying the update, a follow-up receipt acknowledgment request was sent via email on December 1, 2022. The emails included a clickable link that directed customers to a webpage that was used for receipt verification; however, an error was made configuring that website which resulted in an impermissible disclosure of customers’ protected health information. Each customer was sent a unique URL that included their IP address, whether the customer was an Omnipod DASH user, and if they had a Personal Diabetes Manager. Cookies and trackers embedded in the MDC acknowledgment pages transferred details of the URLs to third-party website performance and marketing partners. Insulet said the privacy violation was discovered on December 6, 2022, and all tracking technologies on the web pages were disabled to prevent further PHI exposure, and...

Read More

NortonLifeLock Warns Customers About Potential Password Manager Breach

Just a few weeks after LastPass confirmed hackers had stolen a copy of users’ encrypted password vaults comes the news of another password manager data breach. NortonLifeLock has recently notified approximately 6,450 individuals that their accounts have been accessed by unauthorized individuals and that their Password Manager accounts are at risk. Gen Digital, which owns NortonLifeLock, started detecting account compromises on December 12, 2021, when its intrusion detection system started generating alerts in response to a high volume of failed login attempts. The investigation confirmed that LifeLock customers were being targeted in a credential stuffing attack, which commenced on or around December 1, 2022. NortonLifeLock confirmed that its systems remain secure and have not been hacked, but customer accounts had been subjected to unauthorized access. NortonLifeLock said the compromised accounts contained information such as first names, last names, phone numbers, and mailing addresses. NortonLifeLock was unable to confirm if customers’ Password Manager accounts had been...

Read More

Mayo Clinic Settles Lawsuit Alleging Former Employee Viewed Nude Patient Images

Mayo Clinic has settled another lawsuit that stemmed from a data breach involving a former employee, who was discovered to have accessed the records of patients without authorization, including nude images. In October 2020, Mayo Clinic notified 1,614 patients that some of their protected health information had been viewed by a former employee. That information included demographic information, birth dates, medical record numbers, and clinical notes. The employee was also discovered to have viewed photographs of patients that had been taken for medical purposes, which included nude images. The employee in question, Ahmad Maher Abdel-Munim Alsughayer, 28, of Saginaw, MI, was a doctor at Mayo Clinic, and terminated his employment in August 2022 around the time that the privacy violations were discovered. The Olmsted County Attorney’s Office opened a criminal investigation into Alsughayer over the privacy violations after a complaint was received from a patient who obtained a copy of her records and discovered they included three nude images that were in her medical records at the time...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist