Latest Publications

Share:

DOJ Issues Additional Guidance and Clarification on the Bulk Data Transfer Rule: What U.S. Businesses Need to Know

On April 11, 2025, the Department of Justice's National Security Division (NSD) issued additional guidance to assist U.S. organizations in understanding and complying with the Data Security Program (DSP). As discussed in our...more

DOJ Final Rule Targets Cross-Border Data Transfers: Key Implications for U.S. and Foreign-Owned Companies Operating in the U.S.

In the final days of the Biden administration the U.S. Department of Justice (DOJ) issued a sweeping set of regulations which are in effect as of yesterday, April 8, 2025. The regulations focus on cross-border data transfers...more

Location Data Practices Targeted by California Lawmakers and Regulators

In late February, California lawmakers introduced new legislation that would impose sweeping restrictions on the use of location and tracking data. Known as the California Location Data Act (CLDA), this legislation goes a...more

OCR Issues "Dear Colleagues" Letter Regarding AI in Medicine

On May 6, 2024, OCR published the final rule interpreting and implementing Section 1557 at 45 C.F.R. § 92 (the Final Rule). The Final Rule regulates the use of patient care decision support tools, including AI algorithms for...more

Proposed HIPAA Security Rule Updates

The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) on December 27, 2024, to update the Health Insurance Portability and Accountability Act...more

Texas Court Issues Injunction on 2024 HIPAA Reproductive Privacy Rule

The HIPAA Privacy Rule to Support Reproductive Health Care Privacy went into effect on June 24, 2024. The 2024 Final Rule strengthens privacy protections for medical records and other health information related to...more

The Office for Civil Rights Recently Settled Two Ransomware Related Investigations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently settled two ransomware cases with covered entities. These cases signal the government's growing concern with health care...more

Medical Records Scams: What You Need to Know

In today's digital age, the health care industry faces a growing threat from scammers who don't have to use sophisticated cyberattacks; they can use the most routine task to steal information from unwitting and...more

HIPAA Updates: The Obligations Continue to Unfold

There has been a notable emphasis on proactive enforcement of the privacy and security of protected health information in recent weeks as evidenced by multiple developments regarding compliance with the Health Insurance...more

OCR Enforcement Action Likely: Reminder of Steps to Take Now

Are you a health care provider, business associate, or other entity subject to the requirements of the Health Insurance Portability and Accountability Act (HIPAA) regarding the use and disclosure of protected health...more

New SEC Rules: Public Companies Must Report Material Cybersecurity Incidents Within Four Business Days

It is official. On July 26, 2023, the Securities and Exchange Commission (SEC) passed rules regarding reporting "material cybersecurity incidents" within four business days of the determination, which will surely vex...more

MOVEit Transfer Zero-Day Vulnerability: What Companies Need to Know

On May 31, 2023, renowned managed file transfer solution provider Ipswitch, Inc. revealed a zero-day vulnerability in its flagship solution, MOVEit Transfer, that can enable mass data theft from thousands of organizations....more

FTC Proposes Rulemaking to the Health Breach Notification Rule to Include Information Disclosures by Health Apps and Other...

On Thursday, May 19, 2023, the Federal Trade Commission (FTC) issued a notice of proposed rulemaking and a request for public comment on proposed changes to the Health Breach Notification Rule (HBNR or, the Rule) that would...more

A Baker's Dozen: Top Questions In-House Legal Counsel Should Consider Asking to Better Understand AI including ChatGPT

Artificial Intelligence (AI), including ChatGPT, has now ushered its way regularly into management conversations. How can AI benefit an organization, provide it with a competitive advantage, or make it more efficient? At the...more

Reproductive Privacy Rights: Changes Coming for Health Care Organizations

On April 17, 2023, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) published a Proposed Rule to support reproductive health care privacy in the Federal Register. Through the...more

Initiative to Modernize National Organ Transplant System

On March 22, 2023, the Health Resources and Services Administration (HRSA), an agency of the U.S. Department of Health and Human Services, launched the Organ Procurement and Transplantation Network Modernization Initiative...more

The LastPass Lesson: Why Your Company Needs to Care About Password Manager Breaches

In August 2022, LastPass – one of the largest password managers in the world – suffered a cyber breach resulting in the theft of thousands of password vaults of both individual and corporate users. Password managers are an...more

U.S. Department of Veterans Affairs Overhauls Cybersecurity Rules for Government Contractors

On January 25, the Department of Veterans Affairs (VA) published a new final rule amending contractual provisions in the VA Acquisition Regulation (VAAR) to address data privacy, protection, and cybersecurity. The aim of the...more

Privacy in 2023: Management and Officer Liability for Privacy and Data Security Programs

If your management team and board of directors are not talking often about cyber liability and risk management, they will be soon. As a matter of both corporate and individual liability, recent enforcement makes it clear...more

Privacy Reset in 2023: Effective January 1: What Employers Need to Know About Additional Rights in the California Privacy Rights...

For most companies, human resource departments handle one of their most valuable and sensitive information assets: the personal data of their employees and job candidates. While this dataset provides employers a goldmine of...more

New Executive Order Aims to Restore U.S.-EU Data Privacy Agreement

On October 7, President Biden signed an Executive Order directing the federal government to implement U.S. commitments under the European Union-U.S. Data Privacy Framework (EU-U.S. DPF). The new Executive Order enhances...more

Software Developers With Federal Government Customers Must Provide Confirmation of NIST Standards

In mid-September, the Office of Management and Budget (OMB) released a memorandum requiring federal agencies to obtain attestation from software developers before running third-party software on government networks. Under...more

Mitigating Cyber Vulnerabilities in Medical Devices

Earlier this week, the Federal Bureau of Investigation (FBI) published another notification alerting health care providers of increasing cyber threats to medical devices operating on unpatched or outdated devices. In its...more

HHS Issues Post-Dobbs HIPAA Privacy Guidance for Employer Health Plans, Other Covered Entities

In the wake of the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization and the evolving legal patchwork now confronting both patients accessing reproductive health care and their health care providers,...more

Cybersecurity: A Whistleblower's Paradise

Cyber whistleblowing is the newest and hottest area of exposure for organizations. All government contractors and grant recipients must develop an understanding of the use of the False Claims Act (FCA) to address...more

78 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide