OSHA was Created in What Year?
There are two answers to the question OSHA was created in what year because the acronym OSHA has two meanings – the Occupational Safety and Health Act and the Occupational Safety and Health Administration – and each were “created” in different years. Strictly speaking, both the Occupational Safety and Health Act and the Occupational Safety and Health Administration evolved in different years – rather than were created. This is because although Congress passed the Act in 1970, and the Administration started enforcing the Act the following year, the regulation of occupational safety and health started almost 200 years earlier. The History of Safety and Health Legislation The earliest recorded safety and health legislation was passed by the First Congress of the United States in 1790. The legislation gave a ship´s crew the authority to order a vessel into the nearest port if the majority of the crew and the first mate believed the ship was unseaworthy. Although the legislation was unenforceable, it demonstrated some federal responsibility towards workers´ safety. Further...
Anesthesia, Eye Care, and Telehealth Providers Announce Third-Party Data Breaches
Several more providers of anesthesia services have confirmed they have been affected by a data breach at their management services organization (MSO). Last month, HIPAA Journal reported that 13 providers of anesthesia services to hospitals had been affected by the breach. At least nine more healthcare providers are now known to have been affected, bringing the total to at least 22. The latest announcements bring the breach total up to 433,826 records. Somnia Pain Mgt of Kentucky – 10,849 individuals Primary Anesthesia Services – 9,517 individuals Saddlebrook Anesthesia Services PC – 8,861 individuals Resource Anesthesiology Associates Of KY PSC – 8,980 individuals Resource Anesthesiology Associates of NM Inc – 7,054 individuals Resource Anesthesiology Associates of VA LLC – 3,305 individuals Resource Anesthesiology Associates of CT PC – 3,123 individuals Somnia, Inc. – 1,326 individuals Mid-Westchester Anesthesia Services – 707 individuals The breach was detected by the MSO on July 11, 2022, with the forensic investigation determining information...
President Biden Declares November as Critical Infrastructure Security and Resilience Month
The White House has issued a proclamation from President Biden declaring November as Critical Infrastructure Security and Resilience Month – A month dedicated to raising awareness of the need to improve critical infrastructure and strengthening the resilience of critical infrastructure against physical and cyber threats. President Biden has recommitted to improving and fortifying critical infrastructure, “by building better roads, bridges, and ports; fortifying our information technology and cybersecurity across sectors, including election systems; safeguarding our food and water sources; moving to clean energy; and strengthening all other critical infrastructure sectors,” and by doing so will lay the foundation for long-term security and prosperity. One of the main focus areas is improving defenses and shielding critical infrastructure against malicious cyber activity. President Biden has confirmed his administration will be establishing clear international rules of the road as they relate to cyberspace. In the United States, most critical infrastructure is owned and operated by...
CISA Urges Organizations to Implement Phishing-Resistant Multifactor Authentication
MFA is one of the most important measures to take to prevent unauthorized account access; however, it does not provide complete protection and some forms of MFA can be circumvented. Any form of MFA is better than none at all, but for maximum protection, organizations should implement phishing-resistant MFA, especially in industries such as healthcare that are extensively targeted by malicious cyber actors. Multifactor authentication requires more than just a password to be provided before account access is granted, with the additional authentication being something a person has (physical device, one-time code) or something they are (fingerprint, voice print, etc.). In the event of a password being stolen in a phishing attack or being guessed using brute force tactics, it makes it much harder for a threat actor to access the account. Phishing campaigns are now being conducted that use phishing kits with reverse proxies that allow threat actors to steal login credentials, MFA codes, and session cookies to circumvent MFA protection. Some forms of MFA are also susceptible to push...
OpenSSL Downgrades Bug Severity to High and Releases Patches
Last week, the OpenSSL Project announced a patch would be released on November 1, 2022, to address a critical OpenSSL vulnerability, the details of which were being kept secret to prevent exploitation of the flaw ahead of the patch being released. The news of the vulnerability caused considerable concern amongst the open source community and beyond due to the extent to which OpenSSL is used – It is extensively used to encrypt communication channels and HTTPS connections, so the implications of such a flaw are enormous. The news of a critical flaw existing brought back memories of the Heartbleed Bug (CVE-2014-0160) which was exploited to read the memory of systems including servers and routers to eavesdrop on communications. It is now 8 years since that patch was released and there are still 240, 000 publicly accessible servers that remain vulnerable to Heartbleed. The latest vulnerability affects versions 3.0 to 3.06 of OpenSSL. Version 3 was only released a year ago, so usage of the latest version is limited; however, the vulnerability still has the potential to be extremely...



