Latest Publications

Share:

2024 Privacy, AI & Cybersecurity Year in Review

2024 was a pivotal year in the regulation of data practices, with increased scrutiny of artificial intelligence (AI), data brokers, and the ecosystem of commercial data, and the continued proliferation of comprehensive United...more

HIPAA Security Rule Revamp Is on the Horizon

On January 6, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published significant proposed amendments (proposed rule) to the Security Rule under the Health Insurance Portability and...more

Preventative Medicine: Health Care AI Privacy and Cybersecurity – Part 2 — The Good Bot Podcast [Audio]

Join Troutman Pepper Partner Brett Mason for a podcast series analyzing the intersection of artificial intelligence (AI), health care, and the law. In this installment, Brett is joined by Partner Brent Hoard and Andrea...more

Texas AG Challenges HHS Privacy Rules

On September 4, Texas Attorney General (AG) Ken Paxton filed a lawsuit against the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), challenging two key Health Insurance Portability and...more

Preventative Medicine: Health Care AI Privacy and Cybersecurity – Part 1 — The Good Bot Podcast [Audio]

Join Troutman Pepper Partner Brett Mason for a podcast series analyzing the intersection of artificial intelligence (AI), health care, and the law. In this installment, Brett Mason is joined by Partner Brent Hoard and...more

Checking the Pulse: An Approach to Telehealth Privacy and Cybersecurity Due Diligence

In the rapidly evolving landscape of health care, the surge in telehealth has been nothing short of revolutionary. This digital transformation, while offering unprecedented access to health care services, also introduces a...more

Cybersecurity: The New PE Firm Team Sport

Historically, many private equity firms have let their portfolio companies independently manage cybersecurity. Given the increase in data and cyber risks, sophistication of threat actors, and impact and cost of breaches,...more

Great Expectations: HIPAA-Regulated Entities Asked to Know Users' Intent on Unauthenticated Webpages

On March 18, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued an updated bulletin to "increase clarity for regulated entities and the public" with respect to the use of online tracking...more

Final Rule Aligns 42 CFR Part 2 with HIPAA and HITECH

On February 8, 2024, the Department of Health and Human Services (HHS) posted a final rule that aims to align 42 CFR Part 2 (Part 2) — which protects certain substance abuse disorder (SUD) records — with the Health Insurance...more

New California Law Imposes Significant Data Management Requirements for Sensitive Health Data

On January 1, California's Assembly Bill No. 352 (AB 352) went into effect, introducing significant changes to the handling and sharing of sensitive health information — particularly information related to reproductive health...more

Storm Clouds Form Offshore Under Updated Florida Electronic Health Records Exchange Act

Background - On July 1, an amendment to the Florida Electronic Health Records Exchange Act (the Act) will go into effect. The Act focuses on information safety and sets forth stringent requirements that prohibit health...more

Cookies and Online Tracking of Health Signals: An OCR Prescription for Potential Peril

Online Tracking Technologies and HIPAA. In December 2022, the Department of Health and Human Services Office for Civil Rights (OCR) published a bulletin on the use of online tracking technologies (e.g., cookies or web...more

Washington Legislature Goes Big With "My Health My Data Act"

On April 27, the state of Washington enacted the My Health My Data Act (MHMDA), a comprehensive health privacy law that imposes broad restrictions on how “consumer health data” can be used by companies doing business in the...more

Iowa on Cusp of Enacting Privacy Legislation

Recently, the Iowa Legislature sent a bill to Iowa Governor Kim Reynolds for her signature that would make Iowa the sixth state to enact a comprehensive privacy law. The Iowa Senate unanimously passed Senate File 262 (SF 262)...more

Deadline for New UK Contract Requirements for Personal Data Transfers Is Here (EU and California Deadlines Looming)!

Don't Hyperventilate. There are new United Kingdom (UK), European Union (EU), U.S., and global regulatory requirements that just went into effect or will be effective before or soon after year-end that will impact contracts...more

CCPA/CPRA Will Apply to Employee AND B2B Data — Five Steps to Prepare for the January 1, 2023 Effective Date

Exemption Extensions Failed. On August 31, California's legislature ended its 2022 session without adopting legislation to extend the California Consumer Privacy Act (CCPA) employee and business-to-business (B2B) personal...more

Not So Pretty: Top Takeaways From First CCPA Settlement With Sephora and Updated Enforcement Case Examples

With the notice and cure set to expire on January 1, 2023, California Attorney General Rob Bonta (CA AG) provided a glimpse at what to expect with its first settlement of alleged violations of the California Consumer Privacy...more

Simplifying a Complicated Process — Four Steps to Comply with China’s PIPL New Security Assessment Requirements for Cross-Border...

Background on the PIPL Security Assessment. On July 7, China’s top regulator, the Cyberspace Administration of China (CAC), released the final version of the Measures for Security Assessment of Data Exports (Security...more

California Privacy Protection Agency Publishes Draft Rules

The California Privacy Rights Act (CPRA) established the California Privacy Protection Agency (CPPA), and requires the CPPA to adopt, amend, and rescind regulations on 22 topics — including, among other things, definitions,...more

19 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide