OSHA to Hold Public Hearing on Proposed Heat Injury and Illness Standard
The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) is hosting a virtual public hearing on June 16, 2025, on its Notice of Proposed Rulemaking (NPRM) on Health Injury and Illness Prevention in Outdoor and Indoor Work Settings. The heat injury and illness NPRM was published in the Federal Register on August 30, 2024, and requires employers in all general industry, construction, maritime, and agriculture sectors to create a plan to evaluate and control heat hazards in the workplace and ensure that workers are adequately protected from hazardous heat levels in indoor and outdoor work settings. In the United States, heat is the leading cause of death out of all weather-related phenomena, yet prior to the heat injury and illness NPRM, there was no federal OSHA standard regulating heat stress hazards in the workplace, only guidance from governmental and non-governmental organizations on measures to protect workers. Exposure to excessive heat poses a significant risk of illness and injury. In many industries, workers are required to work through shifts with...
Horizon Behavioral Health Falls Victim to Ransomware Attack
Data breaches have been announced by Horizon Behavioral Health, BayMark Health Services, Carlton County Public Health and Human Services, the City of Bristol in Tennessee, and Schewitz Psychological Services (Couples Learn). Horizon Behavioral Health Horizon Behavioral Health, a Lynchburg, VA-based provider of mental health, substance use, and intellectual disability services in Central Virginia, has fallen victim to a ransomware attack. The attack was detected on March 16, 2025, when computer systems were disrupted. Immediate action was taken to try to contain the attack and prevent further unauthorized access, and a forensic investigation was launched to determine the extent of the compromise. Horizon Behavioral Health determined that a ransomware group had access to its network between March 13, 2025, and March 16, 2025, during which time sensitive data may have been viewed or acquired by the ransomware group. The file review confirmed that the affected data included names, Social Security numbers, addresses, ZIP codes, driver’s license numbers, dates of birth,...
Federal Judge Vacates FDA’s Final Rule Reclassifying Laboratory-Developed Tests as Medical Devices
A Federal judge recently vacated a Final Rule proposed by the U.S. Food and Drug Administration (FDA) that sought to reclassify laboratory-developed tests (LDTs) as medical devices, thus regulating the LDTs under the Federal Food, Drug, and Cosmetic Act (FDCA). The rule was first proposed by the FDA on October 3, 2024, and a final rule was added to the Federal Register on May 6, 2024. Prior to the Final Rule, the FDA exercised general enforcement discretion for LDTs, with action only taken against an LDT if it was thought to have resulted in inaccurate diagnoses. LDTs are generally not sold to other laboratories and are used internally to help provide diagnoses from samples sent to the laboratory by a healthcare provider. LDTs are subjected to robust testing to ensure they are accurate and reliable before they are used for diagnostic purposes, and laboratories were already regulated by the Centers for Medicare and Medicaid Services (CMS) under the Clinical Laboratory Improvement Amendments of 1988 (CLIA). The Final Rule reclassified LDTs as medical devices, which means that they...
Is JotForm HIPAA Compliant?
JotForm is HIPAA compliant and can be used to collect, store, and share Protected Health Information (PHI) provided businesses subscribe to a Gold or Enterprise plan and agree to the terms of JotForm’s Business Associate Agreement. Existing subscribers with a Starter, Bronze, or Silver plan must upgrade their plan to use JotForm in compliance with HIPAA. JotForm is a software solution for creating online forms that can be used in the healthcare industry to simplify the collection and documentation of PHI. Use cases include collecting PHI during the patient intake process, documenting patient consent and authorizations, soliciting patient feedback, and scheduling appointments via forms embedded into a web page or patient portal. JotForm integrates with multiple HIPAA compliant productivity and collaboration tools (i.e., OneDrive, Google Workspace, Salesforce, etc.) to streamline workflows and increase efficiency. Through these integrations, it is also possible to transmit PHI to EHRs or other systems to improve the patient experience. However, in order to use the software solution...
SonicWall SMA Vulnerabilities Actively Exploited in Attacks
Users of SonicWall Secure Mobile Access (SMA) appliances have been warned about three vulnerabilities that are potentially being targeted by threat actors in attacks. The vulnerabilities are not zero-days, having been previously disclosed and patched by SonicWall in December 2023 and April 2025. Evidence has emerged that threat actors are actively targeting the flaws to attack unpatched SMA appliances. The vulnerabilities are tracked as CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475, and all three have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability (KEV) Catalog. SonicWall issued a warning about exploitation of the CVE-2021-20035 vulnerability in mid-April, with a further announcement made about potential exploitation of the other two vulnerabilities at the end of last month. CVE-2021-20035 is a high-severity flaw from 2021 that affects SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices running versions 9.0.0.10-28sv and earlier, 10.2.0.7-34sv and earlier, and 10.2.1.0-17sv and earlier. The vulnerability is thought...



