News & Analysis as of

Risk Management Breach Notification Rule

Akin Gump Strauss Hauer & Feld LLP

SEC Publishes Five C&DIs Covering Cybersecurity Incident Disclosures Pursuant to Item 1.05 of Form 8-K

On June 24, 2024, the U.S. Securities and Exchange Commission (SEC) published five new Form 8-K Compliance and Disclosure Interpretations (C&DIs) expanding the agency’s interpretations of cybersecurity incident disclosures...more

Fox Rothschild LLP

Navigating the CDK Global Ransomware Attack: Practical Guidance for Auto Dealerships

Fox Rothschild LLP on

CDK Global, a key provider of cloud-based software for auto dealerships, suffered a severe ransomware attack this week, disrupting operations for thousands of dealerships across North America. The attack has crippled vital...more

Bradley Arant Boult Cummings LLP

One Phrase, Multiple Interpretations – How Your Scope of Cyber Coverage Can Vary Depending on Your Jurisdiction

This is a deceptively simple question — risk managers rightfully expect to know the scope of their coverages when they build their insurance programs. Unfortunately, judicial interpretation of common policy terms can turn...more

Alston & Bird

The Digital Download – Alston & Bird’s Privacy & Data Security Newsletter – November 2023

Alston & Bird on

Publications and Advisories - November 13, 2023 – Kathleen Benway, Kate Hanniford, Amy Mushahwar, Kim Peretti, and Lance Taubin published “Privacy, Cyber & Data Strategy Advisory: FTC Approved New Data Breach Notification...more

Morrison & Foerster LLP

Litigation Readiness: Seven Things to Keep in Mind

Morrison & Foerster LLP on

Data breach class actions continue to rise, following almost inevitably from nearly every major security incident. Here are seven things in-house counsel can do to prepare for that anticipated litigation....more

Cozen O'Connor

Healthcare Co.’s Coding Error Allegedly PHI-cilitates PHI-shing for PHI

Cozen O'Connor on

A bipartisan coalition of 33 AGs settled with health care clearinghouse Inmediata Health Group, LLC and an affiliated entity (collectively, Inmediata) to resolve allegations that Inmediata violated state consumer protection...more

Jackson Lewis P.C.

Importance of Protecting Employee Information as Privacy and Cybersecurity Laws Proliferate

Jackson Lewis P.C. on

Most human resources professionals are concerned about the privacy and security of the vast amounts of personal information they manage. This article discusses steps to consider taking against the challenges. Deluge of...more

Dunlap Bennett & Ludwig PLLC

The Complexity Of Digital Privacy Law—Insights And Implications

The digital age has ushered in a host of transformative opportunities for businesses, from enhanced customer engagement through data analytics to streamlined operations via digital platforms. However, this digital...more

Console and Associates, P.C.

TIAA and National Student Clearinghouse Report Data Breach Affecting Students and Faculty of Trinity College

On June 30, 2023, Trinity College posted a notice on its website describing two third-party data breaches that may impact confidential information belonging to Trinity College students, faculty and staff members. Evidently,...more

ArentFox Schiff

February Privacy Report: FTC Expands Its Use of “Unfairness” Authority in GoodRx Matter

ArentFox Schiff on

GoodRx Faces Million Dollar Proposed Penalty from FTC in First Enforcement Action Under the Health Breach Notification Rule - Settlement reveals views on application of unfairness authority to sharing of sensitive...more

Foley & Lardner LLP

HIPAA Breaches and Compliance: Key Findings & Lessons Learned from OCR’s Reports to Congress

Foley & Lardner LLP on

The Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) recently submitted two annual reports to Congress setting forth a summary of complaints and breaches reported to the OCR during...more

Alston & Bird

FTC Guidance Creates New Breach Notification Obligations

Alston & Bird on

The Federal Trade Commission has issued new guidance under which consumers or companies should be notified of data breaches “regardless of whether a breach notification law applies.” Our Consumer Protection/FTC Team analyzes...more

Jackson Lewis P.C.

Healthcare Companies Seek to Manage Risk of Ransomware Attacks, According to Report

Jackson Lewis P.C. on

Healthcare companies continue to face increased risks of ransomware attacks on their operations. According to the recently released BD Cybersecurity Annual Report for 2021, such attacks are also increasingly sophisticated....more

Jackson Lewis P.C.

FTC Issues Final Rule Amending the Standards for Safeguarding Customer Information – Data Breach Notification Obligations to...

Jackson Lewis P.C. on

On October 27, 2021 the FTC issued a final rule (the “Final Rule”) amending 16 CFR Part 134, Standards for Safeguarding Customer Information (“Safeguards Rule”), after a period of notice and comment. While the existing...more

Hogan Lovells

EU seeks to bolster cybersecurity regulation with the introduction of NIS 2.0

Hogan Lovells on

On 16 December 2020, the EU released its proposed revisions to the existing Directive 2016/1148 on the security of network and information systems (NIS2)....more

Robinson+Cole Data Privacy + Security Insider

Misdirected Hospital Bills Lead to $2.175 Million HIPAA Settlement

On November 27, 2019 the U.S. Department of Health & Human Services Office for Civil Rights (OCR) announced a $2.175 million dollar settlement with a hospital system to resolve alleged violations of HIPAA’s Breach...more

Mitchell, Williams, Selig, Gates & Woodyard,...

Hospitals In The Crosshairs: Managing Cybersecurity Risk (2)

In our last article, we showed you how to evaluate where your organization sits on the landscape of readiness and preparedness. In this concluding article, we identify concrete steps you can immediately employ to move your...more

Mitchell, Williams, Selig, Gates & Woodyard,...

Hospitals In The Crosshairs: Managing Cybersecurity Risk (Part 1)

From the recent headline-grabbing attacks on hospitals and municipalities, the specter of cybersecurity threats looms large. As a result, spending on cybersecurity initiatives is expected to reach $96 billion this year....more

Seyfarth Shaw LLP

Can The Health Care Industry Protect Itself from Cyberattacks?

Seyfarth Shaw LLP on

The health care industry is racing to adopt cutting-edge technology to provide patients with the best treatment possible at the lowest possible cost. ...more

Snell & Wilmer

The EU General Data Protection Regulation

Snell & Wilmer on

This Friday is the deadline for General Data Protection Regulation (“GDPR”), yet many companies are still in the process of planning for compliance. Companies not able to meet the deadline may want to consider,...more

Nossaman LLP

GDPR COMPLIANCE DEADLINE IS MAY 25, 2018: Privacy Regulation is a Moving Target

Nossaman LLP on

Worldwide, companies are scrambling to meet the May 25th deadline to comply with the European Union’s General Data Protection Regulation (GDPR). For companies with physical operations in an EU member state, this deadline is...more

Mitchell, Williams, Selig, Gates & Woodyard,...

Are You Ready for GDPR?

Personal data is currency in the new world, and while the United States uses a sectoral approach to data privacy, the European Union (EU) treats privacy as a fundamental right of its citizens. Therefore, where U.S....more

Ladas & Parry LLP

Data Protection Impact Assessment

Ladas & Parry LLP on

Article 35 of the GDPR provides for Data Protection Impact Assessments (DPIA). According to Article 35(1) a DPIA is required when “the processing [of data] is likely to result in a high risk to the rights and freedoms of...more

Hogan Lovells

The General Data Protection Regulation (GDPR): action plan for pension scheme trustees - (revised March 2018)

Hogan Lovells on

The European General Data Protection Regulation (GDPR) will apply directly in the UK from 25 May 2018, and will make some fundamental changes to the current requirements surrounding data protection. Key areas of change...more

Ladas & Parry LLP

The European Union General Data Protection Regulation (GDPR): An Introduction

Ladas & Parry LLP on

The European Union (EU) General Data Protection Regulation (GDPR 2016/679) will take effect on May 25, 2018. This regulation provides general guidance on what is needed for compliance, however many policies and procedures are...more

35 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide