ERISA-covered health and welfare plans operating in Puerto Rico must follow cybersecurity rules implemented by the US Department of Labor, and evaluate the cybersecurity measures of their service providers. Regulations including HIPAA and the HITECH Act apply to Puerto Rico, giving covered entities and their partners the same obligations to safeguard private health data as they have in the US. Businesses sponsoring health plans on the island must confirm providers’ HIPAA compliance and obtain written confirmation of cybersecurity audit results.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered