25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Health-ISAC Publishes Guidance for CISOs on Implementing Zero Trust Security Architectures

Health-ISAC has published a white paper for healthcare CISOs looking to implement zero trust security architectures to help them overcome some of the challenges commonly faced by healthcare organizations. The traditional security approach is akin to a castle and moat, where perimeter defenses are established to keep unauthorized individuals out. While this security approach has served organizations well in the past, it is not effective in the cloud where there is no perimeter to defend. Further, the threat landscape is rapidly changing, and malicious actors are successfully breaching perimeter defenses with increasing frequency. Once the perimeter defenses are breached, threat actors can move laterally within networks undetected and are free to perform a wide range of malicious activities. A zero trust security approach continues to provide protection should a malicious actor gain access to internal networks. It makes lateral movement much more difficult and can greatly reduce the harm that can be caused. Zero trust means never trust, always verify. All traffic between devices and...

Read More
House Democrats Seek Answers from Meta on its Data Sharing Policies
Sep02

House Democrats Seek Answers from Meta on its Data Sharing Policies

Democrats from the Committee on Energy and Commerce wrote to the Meta CEO, Mark Zuckerberg, on August 31, 2022, to express their concerns about the release of private communications to law enforcement and seek clarification on its data-sharing policies. The conversations had taken place on Meta platforms between a mother and her daughter about an illegal abortion. The police conducted a criminal investigation into Nebraska residents, Jessica Burgess, 41, and her daughter, Celeste Burgess, 18, over an alleged illegal abortion. The teenager is alleged to have had an illegal abortion after 20 weeks, then buried the fetus. When Roe v Wade was overturned, Nebraska was one of the states that made abortion illegal more than 20 weeks after fertilization. The police launched an investigation after learning that a 17-year-old had unexpectedly given birth to a stillborn baby. The local police issued a warrant to Meta seeking access to conversations that had taken place between the mother and daughter on its platforms, according to a Deseret News report. Celeste Burgess was charged with three...

Read More
California Legislature Passes Bill Prohibiting the Sharing of Information About Abortions
Sep02

California Legislature Passes Bill Prohibiting the Sharing of Information About Abortions

The Californian legislature has passed a bill (AB-1242) that prohibits companies in the state from complying with warrants from other states that seek access to information about individuals seeking or providing abortions. The decision of the U.S. Supreme Court to overturn Roe v. Wade removed the federal right to obtain an abortion. Several states had trigger laws in place that made abortion illegal in the event of Roe v. Wade being overturned. A dozen states have already made abortion illegal for state residents and several other states are considering implementing similar restrictions. There are fears that legal action could be taken against individuals in those states if they seek access to abortions in other states, and that attempts may be made by state attorneys general and law enforcement to obtain information about individuals seeking abortion in states where abortion remains legal. Under the existing law in California, records of individuals must be provided if a search warrant is issued upon certain grounds. The law change prohibits the issuance of such a warrant related...

Read More
Multiple Vulnerabilities Identified in Contec Health Vital Signs Patient Monitors
Sep02

Multiple Vulnerabilities Identified in Contec Health Vital Signs Patient Monitors

Five vulnerabilities have been identified in Contec Health’s CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor. Successful exploitation of the vulnerabilities could allow a threat actor to conduct a denial-of-service attack, access a root shell, make configuration changes, modify firmware, and cause the monitor to display incorrect information. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a security advisory about the vulnerabilities but said Contec Health did not respond to its requests, so healthcare providers that use the affected monitors should contact Contec Health directly for information on how to mitigate the vulnerabilities. The most serious vulnerability – CVE-2022-38100 – has a CVSS v3 severity score of 7.5 and can be exploited remotely by a threat actor with access to the network. Successful exploitation of the vulnerability would cause the device to fail. The flaw can be exploited by sending malformed network data to the device via a specially formatted UDP request. The device would crash and require a reboot. The attack could be conducted...

Read More
Can You Send Medical Records by Email?
Sep01

Can You Send Medical Records by Email?

You can send medical records by email provided the reason for sending medical records is permitted or required by the HIPAA Privacy Rule, and provided the service used to send medical records by email supports compliance with the HIPAA Security Rule. However, exceptions may apply depending on the circumstances.   Because medical records contain individually identifiable health information that is considered Protected Health Information (PHI) under HIPAA, members of a covered entity’s or business associate’s workforce can only send medical records by email when the reason for sending medical records by any means is permitted or required by the HIPAA Privacy Rule. Permitted reasons include uses and disclosures of PHI for treatment, payment, and healthcare operations, for public health activities, to employers (for purposes permitted by §164.512(b)), to report child abuse, elder neglect, or domestic violence, for law enforcement purposes, and for judicial or administrative proceedings. (Note: Some disclosures are “required” in some states). Required reasons include when a patient’s...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist