Texas Enacts Law Governing Security and Storage of Electronic Health Records
The Governor of Texas has added his signature to a bill regulating the storage and security of electronic health records and the use of artificial intelligence in healthcare for diagnostic purposes. The bill also introduces a new definition of “biological sex” and sets rules concerning the amendment of biological sex in electronic health records. S.B. 1188 applies to HIPAA-covered entities and healthcare practitioners. The new law requires the electronic medical records of all Texas patients to be physically maintained in the United States, including if the medical records are stored by a third-party or subcontracted computing facility that provides cloud computing services. In such cases, the data center where the records are stored must be in the United States. The law also applies to electronic health records stored using technology that allows patient information to be electronically retrieved, accessed, or transmitted. Covered entities must implement reasonable and appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and...
High Severity Vulnerability Identified in Panoramic Dental Imaging Software
A high-severity vulnerability has been identified in Panoramic Dental Imaging Software that could allow a standard user to elevate privileges to NT Authority/SYSTEM. The vulnerability, identified by Damian Semon Jr. of Blue Team Alpha LLC, affects Panoramic Corporation Dental Imaging Software v.9.1.2.7600, and is due to an uncontrolled search path element (CWE-427), which makes the product vulnerable to DLL hijacking. The vulnerability is tracked as CVE-2024-22774 and has been assigned a CVSS v4 base score of 8.5 (CVSS v3.1: 7.8). The vulnerability affects an SDK component owned by Oy Ajat Ltd, which is no longer supported. A patch has not been released by Panoramic to correct the vulnerability, as it does not affect a component owned by Panoramic Corporation. No recommended mitigations have been released. Any users should contact Panoramic Corporation for further information via email at [email protected] The vulnerability has been reported to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) which recommends users take defensive measures, including minimizing...
Data Breaches Up 10% Although Victim Count Falls Sharply
This year is set to become another record-breaking year for data breaches, according to the Identity Theft Resource Center (ITRC). The ITRC H1 2025 Data Breach Report shows an 11% year-over-year increase in reported data breaches, with 1,732 data compromises tracked by ITRC between January 1, 2025, and June 30, 2025. That’s 54.9% of the full year total for 2024. The increase in data breaches has largely been driven by cyberattacks, which account for 77.83% of all confirmed data compromises in H1 – 1,348 incidents. Across those incidents, the personal data of 114,582,621 individuals was compromised – 69.13% of the total number of victims across all data compromise incidents. The second main cause of data breaches was phishing/smishing/BEC attacks, with 251 confirmed incidents, followed by 73 confirmed ransomware attacks. The number of ransomware attacks is likely to be substantially higher, as ransomware is often not mentioned in breach notifications. There were 129 data compromises attributed to system or human error, impacting more than 6 million individuals. In total,...
OSH Act Penalty Reductions Expanded to Support Small Businesses
The Occupational Health and Safety Administration has issued updated guidance on the penalty structure in Section 7 of the Occupational Safety and Health (OSH) Act. The OSH Act was signed into law in 1970 to ensure safe and healthful working conditions for employees in the United States. In addition to setting workplace safety and health standards, it established the Occupational Health and Safety Administration (OSHA). OSHA is authorized to enforce compliance with the OSH Act and can issue penalties for violations. The penalties imposed by OSHA are intended to deter future violations and ensure that employers maintain a safe and healthful working environment. To ease the burden on small businesses and to promote the swift resolution of workplace hazards, OSHA has previously applied a 70% reduction in penalties for very small businesses with 10 or fewer employees. The new policy, detailed in the Penalties and Debt Collection section of OSHA’s Field Operations Manual, expands the penalty reductions for small employers to include businesses that employ up to 25 employees. The aim is...
Fake Claim from Ransomware Group About Theft of Patient Data
A ransomware group called Stormous claims to have stolen the personal and health information of 600,000 patients from North Country HealthCare. North Country HealthCare is a federally qualified community health center that provides comprehensive healthcare services to 11 communities in northern Arizona at 14 locations. Stormous is a pro-Russia ransomware group that has been in operation since early 2022. The group engages in double extortion, stealing data and encrypting files, and demanding payment to obtain the decryption keys and prevent the publication of the stolen data on its dark web data leak site. The group is known to have attacked at least 150 companies, generally conducting fewer than 10 attacks per month, although in May 2025, the group conducted more than 15 attacks. The sectors most targeted by the group are hospitality and tourism, technology, business services, healthcare, and government. The top five countries attacked are Spain, the United States, the United Arab Emirates, France, and Brazil. North Country HealthCare was listed on the group’s data leak site on...



