House Committee Advances Bill Preventing OSHA From Implementing Heat Standard

A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced by the House Education and Workforce Committee and will now face a full vote in the House of Representatives.

OSHA was seeking to implement a new standard, Heat Injury and Illness Prevention in Outdoor and Indoor Work Settings, that would require employers to evaluate and control heat hazards in both indoor and outdoor workplaces. If passed, employers would be required to have a site-specific heat injury and illness prevention plan and implement control measures if temperatures exceeded an initial 80°F threshold, with more robust measures required if temperatures exceeded 90°F.

The requirements included providing employees with cool drinking water, rest breaks in the shade, fans to control indoor heat, and easing new workers into hot environments over a period of days to help them acclimatize. The standard also requires regular training for workers and supervisors on the signs of heat stress, reporting, and emergency response.

If passed, the standard will apply to general industry, construction, maritime, and agriculture sectors where OSHA has jurisdiction. OSHA published its proposed rule in the Federal Register on August 30, 2024; the comment period closed on January 14, 2025; and following a public hearing in July 2025, the post-hearing comment period ended in late October 2025. OSHA has yet to provide a timeline for when a final rule will be issued.

In November 2025, Representative Mark Messmer (R-IN) introduced the Heat Workforce Standards Act of 2025, which seeks to prohibit OSHA from implementing a Heat Injury and Illness Prevention in Outdoor and Indoor Work Settings final rule, or any substantially similar heat standard in the future. Critics of the standard claim that the standard preempts local and state governments from developing targeted rules to meet their specific regional climates, that the standard will place a significant financial strain on small businesses, and that some of the required measures are impractical for certain industry sectors and jobs.

“It’s not fair to propose a one-size-fits-all federal mandate that applies to very disparate industries, climates and workplace environments,” Messmer said. The bill was advanced to a full House vote after the Committee on Education and Workforce voted 18-15 in favor, along party lines.

“The committee is marking up legislation that actively makes workers less safe on the job while exposed to extreme heat,” Rep. John Mannion (D-NY) said. Mannion also stressed that the bill not only seeks to prohibit the current proposed standard but also prevents OSHA from implementing any similar standard in the future.  “Let’s be clear on exactly what we’re talking about here and what the majority objects to: Simply, that employers have a plan in place to protect workers from excessive heat, and that includes things like drinking water, rest breaks in the shade and fans to control indoor heat. Basic standards around occupational heat exposure are just commonsense measures to keep workers safe.”

The post House Committee Advances Bill Preventing OSHA From Implementing Heat Standard appeared first on The HIPAA Journal.

Florida SUD Treatment Provider Announces 145,700-record Data Breach

Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have also been announced by Vanderbilt Health in Tennessee, Averhealth Holdings in Virginia, and the Texas-based nationwide optical and optometric service provider Eyemart Express.

Operation PAR, Florida

Operation PAR, Inc., a Pinellas Park, Florida-based addiction treatment and mental health service provider, has identified unauthorized access to its computer network and the exposure of the protected health information of 145,714 current and former clients. Suspicious activity was identified within its computer network on June 10, 2025. Immediate steps were taken to secure its systems, and an investigation was launched to determine the nature and scope of the activity.

A year to the day after the incident was identified, Operation PAR confirmed that the impacted files contained personal and protected health information. Data compromised in the incident included first and last names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. Steps have since been taken to augment security and prevent similar incidents in the future.

Notification letters started to be mailed to the affected individuals on June 25, 2026, who were provided with information on best practices to protect their information and prevent fraud and misuse. Credit monitoring and identity theft protection services do not appear to have been offered. While not stated in the notification letters, this appears to have been an attack by the Worldleaks threat group, which added Operation PAR to its dark web data leak site in July 2025. The group proceeded to leak the stolen data.

Eyemart Express, Texas

Farmers Branch, Texas-based Eyemart Express, a nationwide provider of optical and optometric services, has disclosed further information about a data breach reported to the HHS’ Office for Civil Rights on May 18, 2026. Unauthorized access to parts of the Eyemart Express network was discovered on February 13, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity.

The investigation confirmed that an unauthorized third party breached its network the previous day (February 12, 2026), and gained access to files containing names, addresses, dates of birth, Social Security numbers, prescription information, insurance information, and information about eyeglass purchases. Eyemart Express has reviewed its policies and procedures related to data security and is implementing additional measures to reduce the risk of similar incidents in the future. The protected health information of up to 25,000 individuals was potentially compromised in the incident. Individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring and identity theft protection services.

While not stated in the breach notice, this was a cyberattack by the PayoutsKing threat group. The threat group claimed to have exfiltrated 435 GB of data in the attack, including customer and employee information. The group proceeded to leak the stolen data when the ransom was not paid.

Vanderbilt Health, Tennessee

Nashville, Tennessee-based Vanderbilt Health, the operator of 8 hospitals and more than 180 ambulatory, primary care, and specialty clinics in the state, has identified unauthorized access to an employee’s email account. An employee was tricked by a phishing attempt into clicking a malicious link, resulting in the theft of their credentials. Unauthorized account access was detected on March 27, 2026, and the forensic investigation confirmed that the account was compromised on March 23, 2026. An unauthorized individual had access to emails and associated documents containing patient information such as names, medical record numbers, diagnoses, procedure information, provider/facility names, and admission, discharge, and visit dates.

The breach was confined to the email account. There was no unauthorized access to electronic medical records, and financial information and Social Security numbers were not involved. In response to the incident, Vanderbilt Health is enhancing its email and digital security measures and has provided additional security awareness training to the workforce. The number of affected individuals has yet to be publicly disclosed.

Averhealth Holdings, Virginia

Averhealth Holdings, the parent company of Avertest, a provider of drug testing services for substance use monitoring, diagnostic laboratory testing, and random drug-testing programs, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 9,909 individuals.

Suspicious activity was identified within its email environment on January 20, 2026. Steps were taken to contain the incident, and an investigation was launched to determine the nature and scope of the activity, with assistance provided by third-party cybersecurity professionals. The investigation determined that there had been unauthorized access to parts of its network between December 19, 2025, and January 21, 2026. On May 6, 2026, Averhealth Holdings discovered that the threat actor behind the attack had obtained files containing personal information and protected health information.

The types of information varied from individual to individual and included names in combination with one or more of the following: clinical information, diagnosis, digital/electronic signature, date of birth, driver’s license number, health insurance policy-related number, medical cost, medical dates of service, medical history, medical provider name, medical record number, medical treatment/procedure information, mental or physical condition, minor, patient account number, and/or Social Security number.

Notification letters were mailed to the affected individuals on July 2, 2026. At the time of issuing notifications, Averhealth Holdings was unaware of any misuse of the impacted information. As a precaution against data misuse, complimentary credit monitoring services have been offered to individuals who had their Social Security numbers exposed or stolen.

The post Florida SUD Treatment Provider Announces 145,700-record Data Breach appeared first on The HIPAA Journal.

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred.

The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements.

The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization. A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.

Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.

GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden.

GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.

The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal.