GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred.
The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements.
The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization. A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.
Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.
GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden.
GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.
The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal.
Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities – The HIPAA Journal
AnMed Faces Continued Ransomware as Attacker Ramps Up Pressure
AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating.
According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating.
In addition to adding AnMed to its dark web data leak site, the group posted a message on AnMed’s Facebook page on August 11, 2026, ramping up pressure on AnMed to negotiate a ransom payment. “Gentlemen, your confidential data has been exfiltrated. 6TB: HIV+ patients, suicide registries, sexual assault & rape victims, mental health, abortions, genetic data, patient SSN/DOB, autopsy & police evidence. Deletion on payment.” The post has since been deleted.
“Earlier today, AnMed identified unauthorized posts on its social media accounts,” explained AnMed in an August 11, 2026, statement about the unauthorized activity. “The claims in the unauthorized posts have not been verified and are under investigation.” AnMed previously stated that its main priority has been ensuring patient safety as it investigates the attack and works to safely and securely restore the affected systems. AnMed continues to make progress in its recovery and has reopened most of its facilities, with only 11 remaining closed.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The patient portal has been partially restored. Patients with an active MyChart account and a mobile number on file can now log in to access their health information, although some MyChart features are still unavailable. “Restoring patient access to health information is another important step forward in bringing services back online,” explained AnMed. An additional security text message verification step has been added, which must be completed before patients can log in. Phone lines have also been restored so patients are able to call their physicians and other departments directly, and read/write access to patients’ electronic health records has been restored, so care teams can view and update patient medical records.
It is likely to take some time to determine the full extent of any data theft. If it is established that the attacker’s claims are correct, AnMed said it will provide appropriate notifications and will release additional information as it becomes available.
August 3, 2026: Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities
The Anderson, South Carolina-based nonprofit health system AnMed said it is continuing to make progress restoring its systems after a malware-related cyberattack on July 26, 2026. The health system is operating under established downtime procedures and is continuing to provide care at its locations, although some patients are facing delays. Ten AnMed facilities remain closed a week after the attack; outpatient medical imaging services continue to be affected; and there is only limited patient portal access.
The health system is keeping patients up to date on its recovery and available services via its website. AnMed has confirmed that its doctors have access to medical records and the provision of safe care is the highest priority. In some cases, appointments have been rescheduled, and some transfers and diversions remain in place, with decisions guided by patient safety.
On July 30, 2026, AnMed issued a warning about communications that appear to have been sent by AnMed, such as MyChart appointment reminders. According to the warning, “During our response to the cybersecurity incident, certain appointment reminders generated outside of our internal systems may continue to be delivered by text message. Patients are not required to confirm appointments electronically at this time.”
AnMed said it has not found any evidence to suggest that patients are being targeted with malicious intent as a result of the security incident, although patients have been advised to remain cautious with any electronic messages that appear to originate from AnMed.
AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen has claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months.
July 27, 2026: AnMed Closes 83 Facilities While It Grapples with Cyberattack
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 83 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down.
On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room.
The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be postponed. Decisions about procedures, patient transfers, diversions, and operational processes are being made with patient safety as the guiding principle.
AnMed said it is coordinating with the emergency medical services, regional hospitals, and public safety partners to ensure that patients receive the care they need in the most appropriate setting. AnMed is currently unable to provide a timeline for when computer systems will be recovered, when its offices will reopen, and when normal services will resume.
Updates will be provided via its website, including operational plans for the coming days. Cybersecurity partners are working on restoring access to systems and data as quickly as possible. An investigation has been launched to determine the nature and scope of the incident, but it is too early to tell to what extent, if any, patient data was involved. No threat group appears to have claimed responsibility for the incident.
The post AnMed Faces Continued Ransomware as Attacker Ramps Up Pressure appeared first on The HIPAA Journal.
MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals
MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation.
They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber numbers, and other health insurance information.
MCBS said it continually assesses and enhances its security policies and procedures and will continue to do so. The following HIPAA-covered entities have been affected:
- C&C MD PC
- Nuclear Medicine and Pathology Associates
- Radiation Oncology Associates, LLP
- SkinPath Solutions, LLC
- South Georgia Radiology Consultants PC
- Stephen W. Brown & Radiology Associates of Augusta, LLP
- Vascular Radiology Associates II, LLP
While the threat group behind the attack was not disclosed by MCBS in the data breach notice, the PEAR threat group claimed responsibility for the attack. PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not use ransomware to encrypt files. PEAR claimed to have exfiltrated 3 TB of data in the attack and published the stolen data on its data leak site when the ransom was not paid.
The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal.
Data Breaches Announced by Four Hospitals and Surgery Centers – The HIPAA Journal
Data Breaches Announced by Four Hospitals and Surgery Centers
Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital.
Wildwood Surgical Center
Wildwood Surgical Center in Ohio has announced a June 2025 cybersecurity incident that involved the removal of patient data from its network. Suspicious activity was identified within its network on June 26, 2025, and the forensic investigation determined that an unauthorized third party had access to its network from June 24 to June 26, 2025.
It has taken more than a year to review the affected data and issue notifications to the affected individuals. Notification letters were mailed on or around July 13, 2026, informing patients that their names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, diagnostic and treatment information, medical billing information such as bank account or debit/credit card numbers, and health insurance information were exposed or stolen in the incident.
Wildwood Surgical Center said it has implemented additional tools to enhance the security of its systems and prevent similar incidents in the future. The data breach is not currently showing on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has not yet been publicly disclosed.
Penobscot Valley Hospital
Penobscot Valley Hospital in Lincoln, Maine, identified suspicious activity within its computer network on January 28, 2026. An investigation was launched, which revealed on February 12, 2026, that there had been unauthorized access to its network, and patient data was potentially accessed or acquired.
The review of the affected data was completed on June 4, 2026, confirming that the exposed data included names, addresses, birth dates, Social Security numbers, financial information, and medical information. Notifications are being mailed to the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services. Additional technical security measures and other safeguards have been implemented to prevent similar incidents in the future.
Regulators have been notified, but the incident is yet to be added to the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.
Whitfield Regional Hospital
Whitfield Regional Hospital in Demopolis, Alabama has experienced a cybersecurity incident that involved unauthorized access to parts of its network where patient information was stored. The incident was detected on June 8, 2025, and the forensic investigation confirmed unauthorized access occurred between May 15, 2025, and June 8, 2025.
A review was initiated to determine the individuals affected and types of data involved. That process took more than a year, with the review completed on June 26, 2026. Tombigbee Healthcare Authority, which operates the hospital, has confirmed that the data included first and last names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account information, and health insurance information.
Notification letters started to be mailed to the affected individuals on July 17, 2026, and complimentary credit monitoring and identity theft protection services have been offered. The number of affected individuals has yet to be publicly disclosed.
Michigan Surgical Center
Michigan Surgical Center in East Lansing, MI, has confirmed it experienced a cybersecurity incident that impacted some of its patients. While there is currently no substitute breach notice on its website, the breach was confirmed in a notice to the Massachusetts Office of Consumer Affairs and Business Regulation. The types of information involved and the number of affected individuals have yet to be publicly disclosed. The affected individuals have been offered complimentary single-bureau credit monitoring, credit report, and credit score services for 12 months.
This appears to have been a ransomware attack by a prolific ransomware group called the Gentlemen – A group that has been aggressively targeting healthcare organizations and has grown into one of the most active ransomware groups. Michigan Surgical Center was added to the group’s dark web data leak site in early June.
The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal.
