Latest Publications

Share:

FTC Announces Final Rule Sweeping Consumer Digital Health Tech Under the Health Breach Notification Rule

On April 26, the Federal Trade Commission (FTC) approved its Final Rule revising the Health Breach Notification Rule (HBNR) (“Final Rule”) by a 3-2 vote. The HBNR requires vendors of personal health records (PHR) and related...more

Colorado Legislature Enacts First U.S. Privacy Law Protecting Neural Data

Colorado has just become the first state to extend its comprehensive privacy law, the Colorado Privacy Act (“CPA”), to “neural data.” After passing unanimously in the Colorado Senate earlier this spring, bipartisan House Bill...more

Colorado Passes Law Requiring Governance Measures for High-Risk AI

Colorado became the first state to comprehensively address artificial intelligence (“AI”), passing Senate Bill 24-205, or the Colorado Artificial Intelligence Act, on May 17, 2024 (“Act”). The Act establishes the nation’s...more

OCR Updates Guidance on Use of Online Tracking Technologies by HIPAA-Regulated Entities

On March 18, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a Bulletin revising its December 1, 2022 Guidance concerning the HIPAA obligations of covered entities and...more

Proposed FAR Revisions Aim to Standardize Cybersecurity Requirements Across Agencies and Add Incident Reporting Obligations for...

On October 3, the Department of Defense, General Services Administration, and the National Aeronautics and Space Administration published two sets of proposed revisions to the Federal Acquisition Regulation (“FAR”) pertaining...more

FDA Finalizes Premarket Cybersecurity Guidance for Medical Devices

On September 27, 2023, FDA finalized its guidance entitled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” (the “2023 Final Guidance”). The Final Guidance replaces...more

FTC Announces First Enforcement of the Health Breach Notification Rule

On February 1, the Federal Trade Commission (“FTC”) announced its first enforcement action under the Health Breach Notification Rule (“HBNR” or “Rule”) against GoodRx, a direct-to-consumer digital healthcare and prescription...more

FTC Proposes Enforcement Action Prohibiting GoodRx from Disclosing Users’ Health Information for Advertising

On February 1, 2023, the Federal Trade Commission (FTC) announced that it has taken enforcement action for the first time under its Health Breach Notification Rule (HBNR) against GoodRx Holdings Inc. (GoodRx), for allegedly...more

HHS Office for Civil Rights Issues Guidance Regarding HIPAA Requirements for Online Tracking Technologies

On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services provided guidance on the intersection of the Health Insurance Portability and Accountability Act (HIPAA) and the use of...more

Colorado and California Release New Draft Privacy Regulations

On October 10, the Colorado Attorney General (“AG”) released its draft regulations outlining businesses’ obligations under the Colorado Privacy Act (“CPA”). The 38-page set of draft regulations flesh out several novel privacy...more

First CCPA Settlement Announced

On August 24, the California Attorney General (“AG”) announced its first enforcement settlement under the California Consumer Privacy Act (“CCPA”). The $1.2M fine with an international retailer settled claims that the...more

FBI Sounds Alarm on Cyber Attacks Against Healthcare Payment Processors

On September 14, 2022, the Federal Bureau of Investigation (FBI) issued a Private Industry Notification (Notification) warning the industry regarding increasing cyber-attack activity against healthcare providers and payment...more

HHS Requests FCC Opinion on Whether Certain Telephonic Communications are Permissible Under the Telephone Consumer Protection Act

On April 28, 2022, in a joint letter written by the HHS Secretary, Xavier Becerra, and CMS Administrator, Chiquita Brooks-LaSure, to the Chairwoman of the Federal Communications Commission (FCC), HHS requested an opinion...more

Department of Health and Human Services Seeks Input on HIPAA “Safe Harbor”

On April 6, 2022, the Department of Health and Human Services Office for Civil Rights (OCR) issued a Request for Information (RFI) to solicit public comments on the implementation of the “safe harbor” under the Health...more

HHS Seeks Input on HIPAA “Safe Harbor”

On April 6, 2022, HHS Office for Civil Rights (OCR) issued a Request for Information (RFI) to solicit public comment on the implementation of the newly-enacted “safe harbor” under the Health Insurance Portability and...more

FTC Warns Health Apps and Connected Device Companies to Comply with the Health Breach Notification Rule

On September 15, 2021, the Federal Trade Commission (“FTC”) issued a Policy Statement instructing health app and connected device companies to comply with the Health Breach Notification Rule (“the Rule”). The Rule, codified...more

Colorado Enacts Sweeping Privacy Law

On July 7, 2021, Colorado enacted a new privacy law, titled the Colorado Privacy Act (CPA). The CPA is the third state-level omnibus data privacy law, similar in scope to the California Consumer Privacy Act (CCPA) and the...more

Supreme Court Accepts Narrow Definition of Autodialer, Limiting Reach of TCPA

On April 1, in a highly anticipated decision that likely will have a significant effect on litigation under the Telephone Consumer Protection Act (TCPA), the Supreme Court ruled on what qualifies as an “automatic telephone...more

CMS Proposes New DMEPOS Coverage Policies and Payment Rates, and Seeks to Codify HCPCS Application, Benefit Category and Payment...

On November 4, 2020, the Centers for Medicare & Medicaid Services (CMS) published a proposed rule (the Proposed Rule) outlining proposals for the coverage and payment for durable medical equipment, prosthetics, orthotics, and...more

HRSA Implements Administrative Dispute Resolution Process for 340B Program

On December 10, 2020, HRSA issued a final rule (the Final Rule) implementing the 340B Drug Pricing Program administrative dispute resolution (ADR) process–an overdue mandate from the Affordable Care Act. Under the Final...more

ONC Interim Final Rule Delays Information Blocking Requirements

On October 30, 2020, the Office of the National Coordinator for Health Information Technology (ONC) issued an interim final rule (IFR) with comment period delaying the compliance dates for certain regulatory requirements set...more

Manufacturers Push Back on the Use of Contract Pharmacies by 340B Covered Entities

Manufacturers and providers participating in the 340B Drug Pricing Program have entered into a new phase of tensions this summer, as manufacturers push back on the use of contract pharmacies by providers. At least one major...more

CMS Announces New Funding, Training, and Staff Testing Requirements for Nursing Homes

On July 22, 2020, CMS announced four new policies pertaining to nursing homes during the COVID-19 public health emergency. First, CMS allocated to nursing homes an additional $5 billion from the Provider Relief Fund...more

Sixth Circuit Upholds Validity of Medicare Audit Despite Lack of Notice, Citing Lack of Substantial Prejudice

On June 24, 2020, the U.S. Court of Appeals for the Sixth Circuit issued an opinion addressing whether an overpayment assessment should be invalidated when the Medicare contractor fails to provide notice of a post-payment...more

HHS Announces $4.9 Billion Distribution to Nursing Facilities Affected by COVID-19

On May 22, 2020, HHS announced that it has begun distributing $4.9 billion in additional relief funds to skilled nursing facilities (SNFs) to assist SNFs in weathering significant expenses or lost revenue attributable to the...more

46 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide