25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Study Confirms Increase in Mortality Rate and Poorer Patient Outcomes After Cyberattacks

A recent study has revealed that more than 20% of healthcare organizations experienced an increase in mortality rate after a significant cyberattack and more than half of surveyed healthcare organizations (57%) said they experienced poorer patient outcomes, with almost half reporting an increase in medical complications.  The most common consequences of the attacks that contributed to poorer patient outcomes were delays to procedures and tests. The study was conducted by the Ponemon Institute on behalf of cybersecurity firm Proofpoint on 641 healthcare IT and security practitioners in the United States, with the findings detailed in the report, Cyber Insecurity in Healthcare; The Cost and Impact on Patient Safety and Care.  The findings mirror those of a previous study conducted by the Ponemon Institute in 2021 on behalf of Censinet. That study was conducted on 597 healthcare respondents and one-fifth (22%) said they experienced an increase in their mortality rates following a ransomware attack. The latest study used a broader definition of cyberattack, which includes the four most...

Read More

Bitwarden’s $100 Million Investment will Accelerate Addition of Passwordless Authentication and Developers Secrets

The open source password manager provider, Bitwarden, has raised $100 million in funding which will be used to provide greater support for its user community and accelerate product development to help the firm achieve its long-term goals more rapidly. This is the first funding round to be publicly disclosed by the company. The funding round was led by the private equity firm PSG, with previous Bitwarden investor, Battery Ventures, also participating. Bitwarden has developed a popular password manager that is used by tens of thousands of businesses worldwide and millions of users, with the platform offering a wide range of functions to meet the needs of businesses and consumers. The platform is available in more than 50 languages, with around half of the company’s business coming from outside North America. The company is planning to use some of the funding to accelerate growth in the Asian and European markets, as well as South America and Australia, which are currently served through channel partners in those regions. Bitwarden’s goal is to empower individuals by providing...

Read More

Lamoille Health Partners Facing Class Action Lawsuit Over 58K-Record Data Breach

The Morristown, VT-based healthcare provider, Lamoille Health Partners, is facing a class action lawsuit over a June 2022 ransomware attack that affected almost 60,000 of its patients. The attack was detected on June 13, 2022, with the investigation confirming the attackers gained access to its network the previous day. Before file encryption, the attackers potentially accessed or acquired documents from its systems that contained names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. On or around August 11, 2022, notification letters were sent to affected individuals, and complimentary identity protection and credit monitoring services were offered to patients whose Social Security numbers were potentially stolen. Lamoille Health Partners said the delay in issuing notification letters was due to the length of the investigation to establish which individuals had been affected and the types of information involved. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting 59,381 patients. As is...

Read More

ADPPA’s Preemption of State Laws is A Major Sticking Point

The ADPPA is now awaiting a House vote but there are doubts about whether the federal data privacy and protection bill will pass that vote. While there is strong support for the ADPPA, that support is far from universal and several House members have stated that they would not vote in favor of the ADPPA in its current form and would require tweaks to be made before they would give their support. One of the biggest sticking points is the preemption of state laws. The ADPPA would override state laws, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights and Enforcement Act (CPRA), which provide greater protection for state residents in some key areas. The Health Insurance Portability and Accountability Act (HIPAA) preempts state laws; however, it sets minimum standards for healthcare data privacy and security, but states are permitted to implement their own laws that go further than HIPAA. The ADPPA in its current form does not permit that and sets a floor and a ceiling for data privacy. House Speaker Nancy Pelosi has recently criticized some...

Read More
OIG Calls for Greater Oversight of the Cybersecurity of the Organ Procurement and Transplantation Network
Sep06

OIG Calls for Greater Oversight of the Cybersecurity of the Organ Procurement and Transplantation Network

The HHS’ Office of Inspector General (OIG) has called for the Health Resources and Services Administration (HRSA) to improve oversight of the cybersecurity of the Organ Procurement and Transplantation Network (OPTN). The OPTN is a national system for allocating and distributing donor organs to individuals in need of organ transplants. The OPTN is a public-private partnership that links all professionals that are involved in the donation and transplantation system which is administered by the United Network for Organ Sharing (UNOS). UNOS is a nonprofit that is responsible for managing systems that contain the personal and medical information of organ donors, candidates for transplants, and transplant recipients. The IT systems supporting the OPTN ensure the rapid matching of donated organs with patients awaiting organ donation. There is a very short window of opportunity for providing donated organizations to recipients, which can be just a matter of hours or days. The IT systems that support the OPTN are essential for ensuring that process is efficient, and require the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist