House Committee Advances Bill Preventing OSHA From Implementing Heat Standard
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced by the House Education and Workforce Committee and will now face a full vote in the House of Representatives. OSHA was seeking to implement a new standard, Heat Injury and Illness Prevention in Outdoor and Indoor Work Settings, that would require employers to evaluate and control heat hazards in both indoor and outdoor workplaces. If passed, employers would be required to have a site-specific heat injury and illness prevention plan and implement control measures if temperatures exceeded an initial 80°F threshold, with more robust measures required if temperatures exceeded 90°F. The requirements included providing employees with cool drinking water, rest breaks in the shade, fans to control indoor heat, and easing new workers into hot environments over a period of days to help them acclimatize. The standard also requires regular training for workers and supervisors on the signs of heat...
Florida SUD Treatment Provider Announces 145,700-record Data Breach
Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have also been announced by Vanderbilt Health in Tennessee, Averhealth Holdings in Virginia, and the Texas-based nationwide optical and optometric service provider Eyemart Express. Operation PAR, Florida Operation PAR, Inc., a Pinellas Park, Florida-based addiction treatment and mental health service provider, has identified unauthorized access to its computer network and the exposure of the protected health information of 145,714 current and former clients. Suspicious activity was identified within its computer network on June 10, 2025. Immediate steps were taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity. A year to the day after the incident was identified, Operation PAR confirmed that the impacted files contained personal and protected health information. Data compromised in the incident included first and last names, dates of birth, Social Security numbers, driver’s license...
GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred. The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements. The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential...
AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 79 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down. On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room. The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be...
MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals
MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation. They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber...



