25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Lurie Children’s Hospital Proposes Settlement to End Insider Breach Lawsuit

Ann & Robert H. Lurie Children’s Hospital has proposed a settlement to resolve a class action lawsuit filed in response to two privacy breaches involving unauthorized medical record access by employees. On November 15, 2019, the Chicago hospital discovered an employee had been impermissibly accessing patient records. The investigation determined the unauthorized access occurred between Sept. 10, 2018, and Sept. 22, 2019. The employee, a nursing assistant, viewed patient records that included names, addresses, dates of birth, and medical information, including diagnoses, medications, appointments, and procedures. Once the unauthorized access was confirmed, the employee was terminated. Lurie Children’s Hospital notified affected patients in December 2019 and said there was no reason to suggest the information had been further discovered or misused. A similar breach was detected by the hospital in 2020. A nursing assistant was discovered to have accessed patient records without authorization between November 1, 2018, and February 29, 2020, and was also terminated. Patients were...

Read More

Security Awareness Training Does Not Appear to Improve Password Hygiene

Security awareness training is a vital part of any security strategy; however, one area where it appears to be having little effect is improving password hygiene. Employees can be taught what a strong password is and how passwords should be created, but even though the theory is understood it is not being put into practice. Employees may be made aware of the importance of practicing good cyber hygiene when it comes to passwords, but creating complex, unique passwords for every account is difficult, and remembering those passwords is almost impossible. Each year, LastPass conducts its Psychology of Passwords survey, which this year was conducted on 3,750 professionals. Respondents were probed about their password practices for their personal and work accounts. The survey revealed there was a high level of confidence in current password management practices, but in many cases, there was a false sense of safety, as good password hygiene was not always practiced. The biggest disconnect was with Gen Z, which had the highest level of confidence in their password management practices, yet...

Read More
Healthcare Sector Warned About Cyberattacks by Iranian State-Sponsored Threat Actors
Nov09

Healthcare Sector Warned About Cyberattacks by Iranian State-Sponsored Threat Actors

The federal government has issued a warning to the healthcare sector about the threat of cyberattacks by Iranian threat actors. Iranian state-sponsored actors lack the sophisticated technical capabilities of Russian and Chinese threat actors, but still pose a significant threat to the sector. The threat actors mostly use social engineering in their attacks to gain access to healthcare networks and are known to conduct sophisticated spear-phishing campaigns. Spear phishing campaigns often involve healthcare-related lures with the threat actors using fake personas and social media platforms to interact with their targets, often impersonating doctors, researchers, and think tanks to trick targets into disclosing their credentials or downloading and installing malware. The Tortoiseshell Facebook campaign saw threat actors claim to be recruiters in hospitality, medicine, journalism, NGOs, and aviation. Fake accounts were used to trick targets into opening malware-infected files or to lure them onto phishing URLs to steal credentials. The threat actors often use LinkedIn for contacting...

Read More

Feds Issue Guidance on Responding to and Reducing the Impact of DDoS Attacks

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have recently issued guidance for federal and private agencies on the prevention and mitigation of Distributed Denial of Service (DDoS) attacks. These attacks are conducted to overload applications and websites with traffic, thus rendering them inaccessible and preventing legitimate users from accessing that service. A Denial of Service (DoS) attack causes a network resource overload that consumes all hardware, software, and bandwidth, protocol resource overloads consume the available session or connection resources, and application resource overloads use all compute or storage resources. DDoS attacks are DoS attacks where the traffic comes from multiple devices that are acting together. They can involve huge amounts of traffic and have the potential to cause hardware damage. Botnets – slave armies of malware-infected devices – are commonly used to perform DDoS attacks at scale, and they have become far more common...

Read More

U.S. Vision Subsidiary and Florida Addiction Treatment Center Announce 2021 Data Breaches

USV Optical, a subsidiary of U.S. Vision, has recently confirmed that the information of patients at several entities within its network has been exposed. Suspicious activity was detected within its network on May 12, 2021, with the forensic investigation confirming unauthorized individuals had access to its network for a month between April 20, 2021, and May 17, 2021. During that time, the attackers may have viewed or acquired sensitive patient data. The breach was reported to U.S. Vision shortly after it was detected; however, at the time it was unclear which entities and patients had been affected. Nationwide Optical Group acquired or became affiliated with several U.S. Vision entities in September 2019, including Nationwide Optometry and SightCare. USV Optical started to provide administrative services to those entities around that time. Nationwide Optical Group was informed about the breach and requested U.S. Vision investigate the incident further to find out more information and recommended monitoring the dark web to determine if any sensitive data had been released. No...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist