NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Six Data Breaches Reported by Healthcare Providers and Business Associates

Work Health Solutions, a San Jose, CA-based occupational health services provider, has confirmed that the protected health information of 13,157 individuals has been exposed and potentially obtained by unauthorized individuals who had access to an employee email account between February 16, 2-022 and March 24, 2022. Following an investigation by third-party cybersecurity professionals, Work Health Solutions determined that the email account contained files that included the information of individuals who had received services from the company. The manual review of those files concluded on October 11, 2022. Work Health Solutions then verified contact information and sent notifications on November 9, 2022. The exposed files contained names, Social Security numbers, driver’s license numbers, health insurance information, and/or medical information. Complimentary credit monitoring services have been offered to individuals whose Social Security numbers were potentially compromised. Work Health Solutions said it continuously evaluates and modifies its practices to improve privacy and...

Read More
Critical Citrix ADC and Gateway Vulnerability Exploited in Attacks on Healthcare Organizations
Dec20

Critical Citrix ADC and Gateway Vulnerability Exploited in Attacks on Healthcare Organizations

Citrix Application Delivery Controller (ADC) and Citrix Gateway users have been urged to check to make sure that their systems are not vulnerable to a critical unauthenticated remote code execution vulnerability, which is being actively exploited by a highly capable Chinese advanced persistent threat (APT) actor and potentially other state-sponsored hacking groups. Citrix ADC is a comprehensive application delivery and load-balancing solution that is used by healthcare organizations to ensure the constant availability of critical clinical applications, including electronic medical records. Citrix Gateway is used by healthcare organizations for remote access and for providing single sign-on across all applications. The Citrix ADC and Gateway authentication bypass vulnerability is tracked as CVE-2022-27518 and has been assigned a CVSS v3 severity score of 9.8 out of 10. The flaw can be exploited remotely by an unauthenticated actor to execute code and completely compromise the system. Mandiant has observed a Chinese state-sponsored hacking group exploiting the flaw. The APT actor is...

Read More
HHS Proposes New Rule to Implement HIPAA Standards for Healthcare Attachments and Electronic Signatures
Dec19

HHS Proposes New Rule to Implement HIPAA Standards for Healthcare Attachments and Electronic Signatures

The Secretary of the Department of Health and Human Services (HHS) has proposed a new rule that will require the adoption of standards for healthcare attachments transactions and electronic signatures used in conjunction with those transactions to support healthcare claims and prior authorization transactions. The new rule will implement the requirements of the Administrative Simplification Requirements of HIPAA and the Affordable Care Act and will apply to all health plans, healthcare clearinghouses, and healthcare providers that currently lack an efficient, uniform method of sending attachments. Currently, when making coverage decisions about healthcare services, health plans often require additional information that cannot be added to the specified fields or data elements of the adopted prior authorization request or healthcare claims transaction. Currently, this information is sent through the mail or by fax and is subject to manual processes that consume considerable time and resources. At present, there are no adopted HIPAA standards, implementation guides, or operating rules...

Read More

Avem Health Partners and Emory Healthcare Notify Patients About Data Breaches

Avem Health Partners, an Oklahoma City-based provider of administrative and technology services to healthcare organizations, has recently started notifying its healthcare clients about a data breach that occurred at one of its vendors, 365 Data Centers. On September 9, 2022, 365 Data Centers notified Avem Health Partners that an unauthorized third party had gained access to its servers. The breach was detected on May 16, 2022, with the investigation confirming there may have been unauthorized access to data stored on those servers prior to May 14, 2022. Avem Health Partners did disclose in its website substitute breach notice when its vendor’s servers were first breached. A review of the files on the compromised servers confirmed that HIPAA protected health information such as patient names, dates of birth, Social Security numbers, driver’s license numbers, health insurance information, and diagnosis and treatment information had been exposed. Avem Health Partners is issuing breach notification letters to affected individuals on behalf of its vendor and complimentary credit...

Read More

Improper Use of Password Managers Is Increasing

Passwords can provide a good level of security, but all too often users choose weak passwords that present no challenge to hackers. Many of the most commonly used passwords can be cracked almost instantly. A recent study by NordPass involved an analysis of a 3TB database of passwords and found ‘password’ to have been used to secure 4.9 million accounts, with the next weakest password – 123456 – used on 1.5 million accounts. Security awareness is improving, but many users still set weak passwords for convenience despite the risk of accounts being compromised. It is also common for users to set the same password for multiple accounts. This bad practice puts users at risk of credential stuffing attacks. If the password is compromised on one platform, all other accounts with the same username and password combination can also be accessed. One of the most cost-effective and easiest ways to improve password security is to provide employees with a password manager. Password managers suggest strong, unique passwords, auto-fill them when they are needed, and store the passwords...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist