GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred.

The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure. The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements.

The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization. A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.

Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.

GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden.

GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.

The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal.

AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack

AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced to temporarily close 79 of its 106 facilities while it deals with cyberattack-related disruption to its IT systems. Computer systems, phone lines, and Internet connectivity are down.

On Sunday, July 26, 2026, the health system confirmed that it had experienced “a cybersecurity disruption involving malware,” which forced it to close AnMed Medical Group offices and AnMed Imaging Services on Monday. AnMed Urgent Care locations, AnMed Kids Care, AnMed Integrated Therapy locations, and AnMed Laboratory Services will open as scheduled on Monday. While offices have been temporarily closed, AnMed said its care teams remain on site and will continue to see patients in the emergency room.

The attack has resulted in disruption to patient services, with some scheduled appointments postponed. Patients who had elective procedures scheduled for Monday are being contacted directly to advise them if their procedures will go ahead as planned or will have to be postponed. Decisions about procedures, patient transfers, diversions, and operational processes are being made with patient safety as the guiding principle.

AnMed said it is coordinating with the emergency medical services, regional hospitals, and public safety partners to ensure that patients receive the care they need in the most appropriate setting. AnMed is currently unable to provide a timeline for when computer systems will be recovered, when its offices will reopen, and when normal services will resume.

Updates will be provided via its website, including operational plans for the coming days. Cybersecurity partners are working on restoring access to systems and data as quickly as possible. An investigation has been launched to determine the nature and scope of the incident, but it is too early to tell to what extent, if any, patient data was involved. No threat group appears to have claimed responsibility for the incident.

The post AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack appeared first on The HIPAA Journal.

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the protected health information of 1,261,464 patients of its HIPAA-covered entity clients. Unauthorized network access was detected on or around September 25, 2025. Steps were immediately taken to contain the incident and investigate the unauthorized access, with third-party cybersecurity experts engaged to help with the investigation.

They confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, and confirmed that the information potentially compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical histories, mental/physician condition information, diagnosis information, medical treatment information, health plan beneficiary information, health insurance policy numbers/subscriber numbers, and other health insurance information.

MCBS said it continually assesses and enhances its security policies and procedures and will continue to do so. The following HIPAA-covered entities have been affected:

  • C&C MD PC
  • Nuclear Medicine and Pathology Associates
  • Radiation Oncology Associates, LLP
  • SkinPath Solutions, LLC
  • South Georgia Radiology Consultants PC
  • Stephen W. Brown & Radiology Associates of Augusta, LLP
  • Vascular Radiology Associates II, LLP

While the threat group behind the attack was not disclosed by MCBS in the data breach notice, the PEAR threat group claimed responsibility for the attack. PEAR, which stands for Pure Extortion and Ransom, engages in data theft and extortion and does not use ransomware to encrypt files. PEAR claimed to have exfiltrated 3 TB of data in the attack and published the stolen data on its data leak site when the ransom was not paid.

The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal.

Data Breaches Announced by Four Hospitals and Surgery Centers

Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital.

Wildwood Surgical Center

Wildwood Surgical Center in Ohio has announced a June 2025 cybersecurity incident that involved the removal of patient data from its network. Suspicious activity was identified within its network on June 26, 2025, and the forensic investigation determined that an unauthorized third party had access to its network from June 24 to June 26, 2025.

It has taken more than a year to review the affected data and issue notifications to the affected individuals. Notification letters were mailed on or around July 13, 2026, informing patients that their names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, diagnostic and treatment information, medical billing information such as bank account or debit/credit card numbers, and health insurance information were exposed or stolen in the incident.

Wildwood Surgical Center said it has implemented additional tools to enhance the security of its systems and prevent similar incidents in the future. The data breach is not currently showing on the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has not yet been publicly disclosed.

Penobscot Valley Hospital

Penobscot Valley Hospital in Lincoln, Maine, identified suspicious activity within its computer network on January 28, 2026. An investigation was launched, which revealed on February 12, 2026, that there had been unauthorized access to its network, and patient data was potentially accessed or acquired.

The review of the affected data was completed on June 4, 2026, confirming that the exposed data included names, addresses, birth dates, Social Security numbers, financial information, and medical information. Notifications are being mailed to the affected individuals, who have been offered complimentary credit monitoring and identity theft protection services. Additional technical security measures and other safeguards have been implemented to prevent similar incidents in the future.

Regulators have been notified, but the incident is yet to be added to the HHS’ Office for Civil Rights breach portal, and the number of affected individuals has yet to be publicly disclosed.

Whitfield Regional Hospital

Whitfield Regional Hospital in Demopolis, Alabama has experienced a cybersecurity incident that involved unauthorized access to parts of its network where patient information was stored. The incident was detected on June 8, 2025, and the forensic investigation confirmed unauthorized access occurred between May 15, 2025, and June 8, 2025.

A review was initiated to determine the individuals affected and types of data involved. That process took more than a year, with the review completed on June 26, 2026. Tombigbee Healthcare Authority, which operates the hospital, has confirmed that the data included first and last names, dates of birth, Social Security numbers, driver’s license numbers, medical information, financial account information, and health insurance information.

Notification letters started to be mailed to the affected individuals on July 17, 2026, and complimentary credit monitoring and identity theft protection services have been offered. The number of affected individuals has yet to be publicly disclosed.

Michigan Surgical Center

Michigan Surgical Center in East Lansing, MI, has confirmed it experienced a cybersecurity incident that impacted some of its patients. While there is currently no substitute breach notice on its website, the breach was confirmed in a notice to the Massachusetts Office of Consumer Affairs and Business Regulation. The types of information involved and the number of affected individuals have yet to be publicly disclosed. The affected individuals have been offered complimentary single-bureau credit monitoring, credit report, and credit score services for 12 months.

This appears to have been a ransomware attack by a prolific ransomware group called the Gentlemen – A group that has been aggressively targeting healthcare organizations and has grown into one of the most active ransomware groups. Michigan Surgical Center was added to the group’s dark web data leak site in early June.

The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal.