NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Novant Health Notifies 1.36 Million Patients About Unauthorized Disclosure of PHI via Meta Pixel Code on Patient Portal

Novant Health has recently notified 1,362,296 patients about a breach of their protected health information due to the incorrect configuration of Meta Pixel code on its patient portal. Code Snippet Sending Sensitive Patient Data to Meta Earlier this year, an investigation conducted by The Markup into the use of Meta Pixel code on healthcare providers’ websites revealed 33 of the top 100 hospitals in the United States had included Meta Pixel code on their websites, and 7 of those hospitals had added the code to their password-protected patient portals. The 7 hospitals discovered by The Markup to have installed Meta Pixel on their patient portals were Community Health Network, FastMed, Edward-Elmhurst Health, Piedmont, Renown Health, WakeMed, and Novant Health. Meta Pixel is a snippet of JavaScript code that is used to track website visitors, and the information gathered is sent to Meta (Facebook), which may be used to serve targeted ads. Meta claims that organizations that use Meta Pixel are not supposed to send sensitive data. If Meta discovers it has been sent sensitive data by...

Read More
How the FIDO Alliance Aims to Make Logging In More Secure
Aug16

How the FIDO Alliance Aims to Make Logging In More Secure

The Fido Alliance is an association of businesses from many different industries with a shared vision – to make logging in to online services more secure. The Alliance aims to achieve its vision by developing standards for user authentication and device attestation that will – it is hoped – replace the world´s “over-reliance on passwords”. The failure to use strong, unique passwords for each account – and the failure to keep the passwords secure – is the leading cause of data breaches; and while technologies exist that can prevent password-related data breaches, they are not as widely adopted as they should be because end users would rather sacrifice security for convenience. Acknowledging that poor online security is an issue that´s not going to go away, the FIDO Alliance evolved from an idea initiated by PayPal and Validity Sensors to replace passwords with biometric logins. The idea gained traction, and the Alliance was  launched in 2013 with the support of companies such as Google, Lenovo, Samsung, and Yubico. Since its launch, the FIDO Alliance has published three sets of...

Read More
Is Cloud Computing HIPAA Compliant?
Aug15

Is Cloud Computing HIPAA Compliant?

Cloud computing has revolutionized the way healthcare organizations operate, but ensuring cloud computing is HIPAA compliant can be a challenge. Many healthcare organizations have already embraced cloud technologies, but as with any technology, care must be taken as there is considerable potential for HIPAA violations in the cloud. Here we consider how healthcare organizations can use cloud computing in a HIPAA-compliant manner. There is an extensive range of Cloud Service Providers (CSPs) and their products differ in terms of storage limits, accessibility, and security configurations, Covered Entities are advised to research CSPs and ensure that a product supports HIPAA compliance. They should establish how they will use the cloud computing technologies, conduct a risk assessment, and ensure all staff members are trained on how to use a CSP’s products and services. All CEs are required to obtain a signed business associate agreement (BAA) from their chosen CSP prior to using that service in connection with any protected health information (PHI). BAAs outline the responsibilities...

Read More
Cyberspace Solarium Commission Co-Chairs Call for HHS to Improve Threat Information Sharing with HPH Sector
Aug15

Cyberspace Solarium Commission Co-Chairs Call for HHS to Improve Threat Information Sharing with HPH Sector

Senator Angus S. King Jr. (I-ME) and Congressman Mike Gallagher (R-WI), Co-Chairs of the Cyberspace Solarium Commission, have written to HHS Secretary, Xavier Becerra, to voice their concerns about the lack of sharing of actionable threat information with industry partners to help the health and public health sector (HPH) address current cybersecurity gaps. In the letter, the lawmakers explained that the COVID-19 pandemic revealed some of the systemic challenges facing the HPH sector, and during that time when healthcare workers were dealing with exacerbated workforce challenges, cybercriminals and nation-state threat actors targeted the HPH sector and ransomware attacks skyrocketed. They suggest cyber threat actors recognized that the HPH sector was more likely than other victims to pay the ransom demands to protect patient safety and the large amounts of sensitive patient data stored by healthcare providers have made them targets for criminals and nation-state hackers. The lawmakers praised the efforts the White House and the HHS have put into improving cybersecurity in the HPH...

Read More

Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access

Multiple ransomware groups have adopted the BazarCall callback phishing technique to gain initial access to victims’ networks, including threat actors that have targeted the healthcare sector. BazarCall is a type of callback phishing, where organizations are targeted and sent ‘phishing’ emails that request a call to a telephone number to resolve an important issue. As with standard phishing campaigns, there is urgency – If no action is taken, there will be bad consequences. The telephone number provided is manned by the threat actor, who is well versed in social engineering techniques and will attempt to trick the caller into taking actions that will give the threat actor access to the victims’ network. That action could be to visit a malicious website or download a malicious file. According to cybersecurity firm Agari, phishing attacks have increased by 6% since Q1, 2021; however, hybrid phishing attacks, including callback phishing, increased 625% over the same period. In the BazarCall campaign, the targeted individual is told in the email that a subscription or free trial is...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist