25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Only 30% of Healthcare Organizations Have Taken Out Cybersecurity Insurance

A recent survey conducted by Ovum on behalf of analytics firm FICO has revealed there has been a major increase in companies taking out cybersecurity insurance, but the healthcare industry has been slow on the uptake. In 2017 when the survey was last conducted, 50% of U.S. firms reported that they had not taken out a cybersecurity insurance policy. That percentage has fallen to 24% in 2018. While many businesses see the value in paying insurance premiums to cover the cost of mitigating cyberattacks and data breaches, that does not appear to be the case for healthcare companies. Only 30% of healthcare organizations have taken out cybersecurity insurance policies. 70% have no cybersecurity insurance cover whatsoever, even though the industry is targeted by hackers. The financial services industry, which is also heavily targeted by hackers, has been quick to take advantage of cybersecurity cover. Only 10% of surveyed financial firms had no coverage for cyberattacks. The survey was conducted on 500 companies in 11 countries including the U.S., Canada, India, and the UK. The figures for...

Read More

Survey Reveals Lack of Anti-Phishing Measures at U.S. Businesses

Phishing is now the number one cyber threat faced by businesses but in spite of a high risk of phishing attacks occurring, businesses have been slow to respond to the threat and implement cybersecurity solutions to reduce the risk of email-related data breaches. A recent Valimail sponsored survey has shown that anti-phishing defenses are lacking at many U.S. businesses. The survey was conducted on 650 IT/IT security professionals by the Ponemon Institute. The companies had an average of 1,000 employees with average annual email security and fraud prevention budget of $2.5 million. The high risk of email-based attacks was made abundantly clear. 79% of respondents said that they had experienced a data breach or cyberattack in the past 12 months that certainly or likely involved email, such as a business email compromise attack or a phishing incident. 80% of respondents said they were very concerned about their organization’s ability to prevent or reduce email-based attacks and 53% of respondents admitted that preventing phishing attacks was very difficult. Even though the risk of...

Read More

Central Colorado Dermatology Ransomware Attack Potentially Resulted in PHI Access

Central Colorado Dermatology (CCD) has notified more than 4,000 patients that some of their protected health information (PHI) has potentially been accessed by hackers during a ransomware attack on its computer network. An unauthorized individual gained access to CCD’s computer network and deployed ransomware on a server. Medical records and patients’ medical charts were not accessed, although certain files and scanned fax communications were encrypted. Some of those files contained PHI. An investigation was launched to determine whether protected health information was accessed or stolen although it was not possible to determine with a high degree of certainty whether any PHI was viewed or copied. CCD did not uncover any evidence to suggest that PHI had been accessed or stolen, although some of the software that had been installed on its network could have allowed files to be downloaded. The files that could have been accessed including the following information: Names, addresses, contact telephone numbers, dates of birth, email addresses, Insurance information, Social Security...

Read More

Phishing Attack on Legacy Health Results In Exposure of 38,000 Patients’ PHI

Legacy Health has discovered an unauthorized individual has gained access to its email system and the protected health information (PHI) of approximately 38,000 patients. The Portland, OR-based health system operates two regional hospitals, four community hospitals, and 70 clinics in Oregon, Southwest Washington, and the and the Mid-Willamette Valley and is the second largest health system in the Portland Metro Area. The data breach was discovered on June 21, 2018, although the email accounts were first accessed by an unauthorized individual in May. Legacy Health determined that access was gained to the email accounts as a result of employees being duped by phishing emails. Email breaches can take a considerable amount of time to investigate. While tools are available to scan email accounts for protected health information, many of the emails in compromised accounts need to be individually checked, which can involve manual checks of hundreds of thousands of messages.  According to Legacy Health Spokesperson Kelly Love, “We’ve been moving at as fast a pace as we can to...

Read More

9,350 Patients of Gordon Schanzlin New Vision Institute Notified of Data Breach

The Gordon Schanzlin New Vision Institute in La Jolla, CA, is alerting thousands of patients that their medical records may have been stolen after files containing protected health information were discovered in the possession of an individual unauthorized to hold the information. The data breach came to light following an investigation conducted by the U.S. Postal Inspection Service. A raid was conducted on a property in Southern California and a box of medical records was discovered in the property. The files contained information such as names, dates of service, addresses, health insurance information, Social Security numbers, and health and clinical information. Gordon Schanzlin was notified of the discovery on June 15, 2018, and an internal investigation was immediately launched to determine the nature and scope of the breach and how the medical records had been stolen. While it could not be confirmed with 100% certainty, Gordon Schanzlin believes the medical records were part of a batch of files that were stolen from a storage unit that was broken into in October 2017. The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist