25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

FBI Issues Warning About E-Skimming Threats and Tips for Reducing Risk
Oct25

FBI Issues Warning About E-Skimming Threats and Tips for Reducing Risk

The Federal Bureau of Investigation has issued a warning about e-skimming threats, following an increase in attacks on small and medium sized businesses and government agencies. E-skimming is the introduction of malicious code on websites that process online payments. The code captures debit and credit card information when it is entered into payment portals and the information is silently transmitted to an attacker-controlled domain in real-time. Attacks can be performed on any company that has an online payment system, most commonly on companies in the retail, travel, and entertainment industries and utility companies. Attacks are also conducted on third-party vendors, such as those that provide web analytics and online advertisements. Recently, an e-skimming attack was reported by a healthcare organization – Mission Health in Western North Carolina. Code had been loaded onto its e-commerce websites which allowed the attackers to obtain the credit card information of individuals when they purchased health products. The malicious code was active on the websites for three...

Read More
Vulnerability Identified in Philips IntelliSpace Perinatal Information Management System
Oct25

Vulnerability Identified in Philips IntelliSpace Perinatal Information Management System

A vulnerability has been identified in the Philips IntelliSpace Perinatal obstetrics information management system. The vulnerability – CVE-2019-13546 – could be exploited remotely by an authorized remote desktop session host application user or by an individual with physical access to a locked application screen. The vulnerability affects IntelliSpace Perinatal Versions K and earlier and requires a low level of skill to exploit. The flaw has been assigned a CVSS v3 base score of 6.1 out of 10 (medium severity). Exploitation of the vulnerability would allow an attacker to break out of the containment of the application and access resources from the Windows operating system as the limited-access Windows user. If an attacker used exploits for vulnerabilities in Windows once access to the operating system had been achieved, the attacker could potentially elevate operating system privileges to administrator level. Once access to the operating system has been achieved, an attacker could execute software and view, update or delete files, directories, and alter the system...

Read More

39% of Cybersecurity Professionals Say Their Company is Under Prepared for a Data Breach

A survey of cybersecurity and IT executives in the United States has revealed 39% of companies are under prepared to handle a data breach. The survey was commissioned by the cybersecurity consulting firm Avertium for the firm’s 2019 Cybersecurity and Threat Preparedness report. The survey was conducted on 223 respondents in the United States at companies with 50 or more employees. When asked about the main problems they experienced in relation to cybersecurity, the two biggest issues were the increasing complexity of cybersecurity tech stacks, which was rated as a major pain point by 76% of respondents. Added to that is the increasing sophistication of cyberattacks, which was a pain point for 75% of cybersecurity professionals. 66% of respondents said third-party or partner vulnerabilities were a major problem area, and 65% said their jobs have been made much more difficult due to vulnerabilities introduced by their company’s digital transformation. The cost and complexity of regulatory compliance was also rated as a pain point by 65% of respondents. The types of cyberattack that...

Read More

Geisinger Health Plan Notifies Members About Business Associate Phishing Attack

Danville, PA-based Geisinger Health Plan has discovered the protected health information (PHI) of some of its members has been exposed as a result of a suspected phishing attack on one of its business associates, Magellan NIA. Magellan NIA provides radiology benefits management services to the health plan, which requires access to plan members’ PHI. Magellan NIA discovered the breach on July 5, 2019 when suspicious activity was detected in the email account of one of its employees. The account was immediately secured to prevent further unauthorized access and misuse and an investigation was launched to determine the extent of the breach. The investigation revealed the account was breached on May 28, and there had been several connections to the account between up until July 5. Those connections were made from a location outside the United States. Geisinger Health Plan believes the sole purpose of the attack was to gain access to email accounts for the purpose of spamming, rather than to steal sensitive plan member data. However, it was not possible to rule out unauthorized data...

Read More

Slew of HIPAA Violations Leads to $2.15 Million Civil Monetary Penalty for Jackson Health System

The Department of Health and Human Services’ Office for Civil Rights has imposed a $2.15 million civil monetary penalty against the Miami, FL-based nonprofit academic medical system, Jackson Health System (JHS), for a slew of violations of the HIPAA Privacy, Security, and Breach Notification Rules. In July 2015, OCR became aware of several media reports in which the PHI of a patient was impermissibly disclosed. The individual was a well-known NFL football player. Photographs of an operating room display board and schedule had also been shared on social media by a reporter. OCR launched an investigation in October 2015 and opened a compliance review in relation to the impermissible disclosure. JHS investigated and submitted a report confirming that a photograph was taken in which two patients’ PHI was visible, including the PHI of a well-known person in the community. The internal investigation revealed that an employee had been accessing patient information without authorization since 2011. During that time, the employee had accessed the records of 24,188 patients without any...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist