News & Analysis as of

Data Security Regulatory Reform Data Breach

Seward & Kissel LLP

SEC Adopts Data Privacy Rule Amendments to Regulation S-P

Seward & Kissel LLP on

Who may be interested: Investment Companies; Investment Advisers; Broker-Dealers; Transfer Agents - The SEC adopted amendments to Regulation S-P imposing new data privacy and security requirements on broker-dealers,...more

Gray Reed

Unpacking the Texas Data Privacy & Security Act: A Company’s Guide for Navigating Compliance

Gray Reed on

As businesses grapple with the evolving, regulatory landscape for data privacy, the Texas Data Privacy & Security Act (TDPSA) emerges as a pivotal law. This comprehensive legislation, effective July 1, 2024, established...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - May 2024 #3

Robinson & Cole LLP on

CYBERSECURITY - Health Care Entities Continue to Get Pummeled by Cybersecurity Attacks - The newest health care entity to be hit by a cyberattack is Ascension Health, which operates 140 hospitals and 40 assisted living...more

Hinckley Allen

Connecticut Attorney General Issues Report on Data Privacy Act Enforcement; Offers Legislative Recommendations

Hinckley Allen on

On February 1, 2024, the Connecticut Office of the Attorney General (the “OAG”) issued a report mandated by the Connecticut Data Privacy Act (the “CTDPA”), Conn. Gen. Stat. § 42-515 et seq. (the “Report”), which Report is...more

Troutman Pepper

That’s a Wrap…or Not? Regulatory Data Incident Investigation Resolutions and the Path Forward

Troutman Pepper on

As we discussed in part three of this series, “Navigating the Complexities of Regulatory Data Incident Investigations,” when an organization is the subject of regulatory data incident investigations, it must navigate a...more

Health Care Compliance Association (HCCA)

Privacy Briefs: January 2024

New York has released proposed cybersecurity regulations for hospitals. The regulations, which were published in The State Register on Dec. 6 and will undergo a 60-day public comment period ending on Feb. 5, are designed to...more

Faegre Drinker Biddle & Reath LLP

Cybersecurity Enforcement Update: NYDFS Adopts Final Amendments to its Cybersecurity Regulations and SEC Sues SolarWinds Executive

Recent activity by the New York Department of Financial Services (NYDFS) and the Securities and Exchange Commission (SEC) highlight the continued focus by government regulators on cybersecurity. As these and other regulators...more

Perkins Coie

2023 Breach Notification Law Update: Changes to Notification and Security Requirements Continue at State and Federal Levels

Perkins Coie on

A flurry of legislative activity over the past year has brought meaningful changes to a variety of privacy and security provisions in state and federal law. At the state level, as in 2022, we have seen a handful of changes to...more

Nelson Mullins Riley & Scarborough LLP

SEC Adopts New Cybersecurity Disclosure Requirements

The Securities and Exchange Commission (“SEC”) adopted the final rules (the “Final Rules”) on July 26, 2023 that will require disclosure of material cybersecurity incidents, cybersecurity risk management, strategy, and...more

Polsinelli

SEC Adopts Cybersecurity Incident and Risk Management Disclosure Rules

Polsinelli on

On July 26, 2023, the Securities and Exchange Commission (the “SEC”) adopted new rules requiring public companies to disclose within four business days material cybersecurity incidents they experience and to disclose annually...more

Thomas Fox - Compliance Evangelist

SEC Formalizes New Rules on Cyber Breach Disclosures

The SEC has recently voted on new rules that will require companies to disclose material cybersecurity incidents within four days and to make disclosures about their broad cybersecurity risks in their annual report. Tom Fox...more

Robinson+Cole Data Privacy + Security Insider

SEC Adopts New Cybersecurity Rules for Public Companies

In a 3-2 vote, the Securities and Exchange Commission (SEC) adopted new cybersecurity rules yesterday (July 26, 2023) applicable to public companies. The rules, which will become effective thirty days after publication in...more

Bilzin Sumberg

SEC’s New Cyber Incident Disclosure Requirements Will Go Into Effect in December

Bilzin Sumberg on

Come December 2023, public companies will have a very narrow window to report cybersecurity incidents that materially affect their companies. Companies will also have to report annually how they assess and manage...more

Nelson Mullins Riley & Scarborough LLP

FTC Proposes to Vastly Expand the Health Breach Notification Rule

The Federal Trade Commission (FTC) recently proposed changes to the Health Breach Notification Rule (Rule), enacted in 2009, to clarify that the Rule applies directly to an estimated 170,000 health and wellness mobile...more

Polsinelli

Leveraging “Public-Private Collaboration” for Critical Infrastructure Cybersecurity

Polsinelli on

In March, the White House issued its long-awaited National Cybersecurity Strategy.  The strategy includes five pillars, Pillar One being “Defend Critical Instructure” with its first and second subparts focusing on (1)...more

Troutman Pepper

More Privacy, Please – June 2023

Troutman Pepper on

Editor’s Note: Montana became the latest state to pass a comprehensive privacy bill, joining California, Virginia, Colorado, Connecticut, Utah, and Tennessee. Florida, too, passed a privacy bill, but with a much narrower...more

Polsinelli

Cyber Incident Reporting for Critical Infrastructure Act: Significant Changes to Incident Reporting Are on the Horizon

Polsinelli on

In May 2021, Colonial Pipeline, a privately held oil pipeline responsible for nearly half of the oil supply for the U.S. East Coast, was crippled by a DarkSide ransomware attack. DarkSide is widely believed to be a...more

Wyrick Robbins Yates & Ponton LLP

Abracadabra! The FTC Pulls a New Federal Breach Notice Standard out of its Hat

On May 20, 2022, with little fanfare and just five short paragraphs, the Federal Trade Commission announced that businesses must publicly report security incidents to prevent potential harms, even if no other applicable law...more

Jones Day

Utah Becomes Fourth State to Enact a Comprehensive Data Privacy Law

Jones Day on

On March 24, 2022, Utah followed California, Virginia, and Colorado in adopting a comprehensive consumer data privacy law. On March 24, 2022, Utah Governor Spencer Cox signed the Consumer Privacy Act ("Act"), making Utah...more

Bilzin Sumberg

Is Reporting Cyber Breaches to the Federal Government Required or Encouraged?

Bilzin Sumberg on

President Joe Biden signed the Strengthening American Cybersecurity Act into law on March 15.  Among other requirements, companies that are “covered entities” must report data breaches promptly to federal regulators.  For...more

Jones Day

President Biden Signs Cyber Incident Reporting for Critical Infrastructure Act

Jones Day on

On March 15, 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (the "Act"), creating new requirements for organizations operating in critical infrastructure sectors to...more

Stinson - Corporate & Securities Law Blog

SEC Issues Proposed Rules on Disclosure of Cybersecurity Incidents

The SEC has issued proposed rules on disclosure of cybersecurity incidents.  Specifically, the SEC is proposing to: Amend Form 8-K to add Item 1.05 to require registrants to disclose information about a cybersecurity...more

Wyrick Robbins Yates & Ponton LLP

A Prelude to Enforcement: Colorado AG Issues Remarks Opining on What Constitutes Reasonable Security Measures

Last month, on Data Privacy Day, Colorado’s Attorney General Philip Weiser released prepared remarks entitled “The Way Forward on Data Privacy and Data Security” that shed some light on his approach to enforcing Colorado’s...more

Bilzin Sumberg

FCC Calls for Changes to Telecommunications Carriers’ Reporting of Data Breaches

Bilzin Sumberg on

The Federal Communications Commission (“FCC”) circulated internally a Notice of Proposed Rulemaking (“NPRM”) last week that would, among other things, enable telecommunications carriers to report breaches to their customers...more

Ballard Spahr LLP

HIPAA 2019 Year in Review: OCR’s Enforcement of HIPAA Security Rule

Ballard Spahr LLP on

Although the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) may yet announce one or two year-end settlements, it appears that 2019 will be known more for the implementation of changes in...more

25 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide