Latest Publications

Share:

The Supreme Court Enters the Discussion About Meta Pixel and Google Analytics: How to Define What is a “Consumer” Under the Video...

Key Takeaways - The Supreme Court’s agreeing to hear the appeal in Salazar v. Paramount Global will affect how your business can use website tracking tools: A broad interpretation of who is a “consumer” could create new...more

42 C.F.R. Part 2 Civil Enforcement is Here: What Substance Use Disorder Providers Need to Know

February 16, 2026 marks a significant milestone for substance use disorder (SUD) treatment providers across the country. The HHS Office for Civil Rights (OCR) has announced that, effective on February 16, 2026, it will begin...more

HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points

The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes. Regulators spent 2025 refining the tools they use, broadening...more

System Hardening, HIPAA, and the Practical Path to Protecting ePHI

The January 2026 OCR Cybersecurity Newsletter is the U.S. Department of Health and Human Services Office for Civil Rights’ latest installment in its periodic series translating HIPAA Security Rule expectations into practical,...more

Lessons on Protecting Your Company’s Crown Jewels – Do a Better Job than the Louvre Did Protecting Its Crown Jewels

The Louvre is synonymous with cultural excellence. That’s what makes the recent heist of crown jewels—and the subsequent state audit—so jarring. This wasn’t a Hollywood caper. It was a case study in how predictable,...more

Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and...

42 CFR Part 2: What Changed, Why It Matters, and What to Do Now - On November, 7, 2025, I spoke to the Massachusetts Health Information Management Association about the federal government’s sweeping updates to 42 CFR Part...more

Sound Judgment: Navigating the Legal Frontier of Ambient AI

BEST PRACTICES FOR USING AI NOTETAKERS IN SENSITIVE MEETINGS - AI notetakers are rapidly becoming staples of corporate meetings—bringing efficiency alongside new questions about confidentiality and compliance. This tip...more

HHS Unveils Version 3.6 of the Security Risk Assessment Tool: What Covered Entities and Business Associates Need to Know

Anyone who has wrestled with the HIPAA Security Rule’s risk‐analysis requirement knows that the government’s free Security Risk Assessment (“SRA”) Tool can be a practical starting point—particularly for resource-constrained...more

FTC to App Developers: Your Vendors’ COPPA Missteps Are Your Own

The Federal Trade Commission has once again reminded the mobile ecosystem that compliance obligations under the Children’s Online Privacy Protection Act (“COPPA”) do not stop at an app developer’s door. In a recent...more

Expanded Protections for Reproductive Health and Gender-Affirming Care: What Massachusetts Providers Need to Know

On August 7, 2025, Massachusetts Governor Maura Healey signed into law an Act Strengthening Healthcare Protections in the Commonwealth (the “Act”), which amends the state’s existing “Shield Law” protections for providers of...more

23andMe Bankruptcy Update: How the Proceedings Highlight Best Practices for Handling and Transferring Genetic Data and Personal...

After Foley Hoag’s prior updates regarding the chapter 11 bankruptcy cases of 23andMe Holding Co and its affiliated debtors (collectively, “23andMe”), the United States Bankruptcy Court for the Eastern District of Missouri...more

DOJ’s “Bulk Sensitive Data Rule” is in Effect, and May Require Significant Compliance Obligations as Enforcement is Set to Begin

Pursuant to a newly effective U.S. Department of Justice (DOJ) regulation, the transfer and storage of certain sensitive U.S. government and personal data may be prohibited or restricted, depending on the intended recipient,...more

The FTC Addresses 23andMe's Bankruptcy

In a March 31, 2025 letter, the Chair of the FTC, Andrew Ferguson, wrote to the Acting U.S. Bankruptcy Trustee and set out the FTC’s expectations for the protection of consumer information held by 23andMe. As we noted...more

23andMe’s Bankruptcy Doesn’t Mean Genetic Data Will Be Improperly Disclosed

The chapter 11 bankruptcy cases of 23andMe Holding Co. and its affiliated debtors (collectively, “23andMe”), the company that provides direct-to-consumer genetic testing and ancestry services, has prompted a wave of panicked...more

HHS OCR Settles HIPAA Security Rule Investigation with Health Fitness Corporation

On March 21, 2025, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement of HIPAA security rule claims involving Health Fitness Corporation (Health Fitness). Health Fitness...more

FTC Finalizes Update to Children’s Privacy Rules Under COPPA

The Federal Trade Commission's first update in over a decade to its rules under the Children’s Online Privacy Protection Act (“COPPA”) did not bring the dramatic updates that some privacy advocates had requested. Instead, the...more

U.S. House Report Addresses AI Concerns, Including Privacy and Data Security

Overall, the Report recognized the complex interplay between AI advancement and privacy/security concerns, advocating for a balanced approach that promotes innovation while protecting individual rights and national interests....more

HHS Office for Civil Rights Proposes Measures to Strengthen Cybersecurity in Health Care Under HIPAA

The Department of Health and Human Services (HHS) has proposed significant modifications to the HIPAA Security Rule and the HITECH Act in an attempt to strengthen cybersecurity protections for electronic protected health...more

Holiday Cyber Security Scams: Protecting Your Business During the Festive Season Without Being a Grinch

As the holiday season is upon us, businesses must remain vigilant against the increased threat of cybersecurity hacks and scams. Cybercriminals often exploit the festive atmosphere and increased online activity to target...more

The Health Sector Cybersecurity Coordination Center’s September 19 Threat Briefing on Healthcare Technology Security

As healthcare technology continues to evolve, so does the need for robust compliance strategies to safeguard patient information and ensure the integrity of medical devices. In a joint September 19, 2024 presentation, the...more

Massachusetts Attorney General Announces Breach Resources for Consumers Impacted by Change Healthcare Breach

The Massachusetts Attorney General’s Office (AGO) issued an announcement last week to inform consumers who may have had their personal information breached in Change Healthcare’s cyberattack this past February. The AGO was...more

AT&T/Snowflake Breach Hits Most of US - Vendor Exposure Strikes Again

AT&T Inc. announced in a July 12, 2024, SEC filing that hackers stole a cache of six months’ worth of mobile phone customer data, illegally downloading the records from a workspace account at the cloud-service provider...more

Recent Trends of State Attorneys General in Healthcare Regulation

State Attorneys General play a significant role in shaping health care policy across the country. While the national debates over health care policy in Congress and the federal government receive significant media attention,...more

201 Results
 / 
View per page
Page: of 9

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide