Latest Publications

Share:

California Finalizes Privacy Rules on Automated Technology, Risk, and Cybersecurity

On July 24, 2025, the California Privacy Protection Agency (CPPA) Board approved a new set of regulations aimed at governing the use of automated decision-making technology (ADMT), risk assessments, and cybersecurity audits...more

Texas Enacts New Law on Electronic Health Records Including Requirements on Local Data Storage in the U.S. and AI Usage

A new Texas law governing electronic health records (“EHR"), Senate Bill 1188 (“S.B. 1188”), is going into effect September 1, 2025. The bill sets out a number of new requirements and additions to the Texas Health and Safety...more

Connecticut Attorney General Announces First Settlement under the Connecticut Data Privacy Act

On July 8, Connecticut Attorney General William Tong (“CT AG ”) announced an $85,000 settlement with TicketNetwork, Inc., following an investigation into alleged violations of the Connecticut Data Privacy Act (CTDPA). In this...more

CPPA Revises Draft Rules on Automated Decisionmaking Technology, Cybersecurity Audits, and Risk Assessments

On May 1, 2025, the California Privacy Protection Agency (CPPA) released a revised draft of its regulations. These modifications, issued in response to public comments on earlier drafts, aim to clarify and simplify key...more

Seven States Form Consortium for Privacy Enforcement

On April 16, regulators from California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon announced the creation of the Consortium of Privacy Regulators, a new collaborative effort focused on the...more

Going for Broker: California’s CPPA Issues First Ban of Data Vendor Under Registration Statute

Late in February, the California Privacy Protection Agency (CPPA) ordered the shutdown of Background Alert under the state’s Data Broker Registration Law. Background Alert aggregated public records to create detailed profiles...more

DEA Appears Likely to Extend Ryan Haight Waiver with New Rule

On October 10, 2024, the Drug Enforcement Administration (the DEA) submitted a new rule to the White House Office of Management and Budget titled, “Third Temporary Extension of COVID-19 Telemedicine Flexibilities for...more

FTC Announces Final Rule Sweeping Consumer Digital Health Tech Under the Health Breach Notification Rule

On April 26, the Federal Trade Commission (FTC) approved its Final Rule revising the Health Breach Notification Rule (HBNR) (“Final Rule”) by a 3-2 vote. The HBNR requires vendors of personal health records (PHR) and related...more

Colorado Legislature Enacts First U.S. Privacy Law Protecting Neural Data

Colorado has just become the first state to extend its comprehensive privacy law, the Colorado Privacy Act (“CPA”), to “neural data.” After passing unanimously in the Colorado Senate earlier this spring, bipartisan House Bill...more

Colorado Passes Law Requiring Governance Measures for High-Risk AI

Colorado became the first state to comprehensively address artificial intelligence (“AI”), passing Senate Bill 24-205, or the Colorado Artificial Intelligence Act, on May 17, 2024 (“Act”). The Act establishes the nation’s...more

OCR Updates Guidance on Use of Online Tracking Technologies by HIPAA-Regulated Entities

On March 18, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a Bulletin revising its December 1, 2022 Guidance concerning the HIPAA obligations of covered entities and...more

Proposed FAR Revisions Aim to Standardize Cybersecurity Requirements Across Agencies and Add Incident Reporting Obligations for...

On October 3, the Department of Defense, General Services Administration, and the National Aeronautics and Space Administration published two sets of proposed revisions to the Federal Acquisition Regulation (“FAR”) pertaining...more

FDA Finalizes Premarket Cybersecurity Guidance for Medical Devices

On September 27, 2023, FDA finalized its guidance entitled “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” (the “2023 Final Guidance”). The Final Guidance replaces...more

FTC Announces First Enforcement of the Health Breach Notification Rule

On February 1, the Federal Trade Commission (“FTC”) announced its first enforcement action under the Health Breach Notification Rule (“HBNR” or “Rule”) against GoodRx, a direct-to-consumer digital healthcare and prescription...more

FTC Proposes Enforcement Action Prohibiting GoodRx from Disclosing Users’ Health Information for Advertising

On February 1, 2023, the Federal Trade Commission (FTC) announced that it has taken enforcement action for the first time under its Health Breach Notification Rule (HBNR) against GoodRx Holdings Inc. (GoodRx), for allegedly...more

HHS Office for Civil Rights Issues Guidance Regarding HIPAA Requirements for Online Tracking Technologies

On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services provided guidance on the intersection of the Health Insurance Portability and Accountability Act (HIPAA) and the use of...more

Colorado and California Release New Draft Privacy Regulations

On October 10, the Colorado Attorney General (“AG”) released its draft regulations outlining businesses’ obligations under the Colorado Privacy Act (“CPA”). The 38-page set of draft regulations flesh out several novel privacy...more

First CCPA Settlement Announced

On August 24, the California Attorney General (“AG”) announced its first enforcement settlement under the California Consumer Privacy Act (“CCPA”). The $1.2M fine with an international retailer settled claims that the...more

FBI Sounds Alarm on Cyber Attacks Against Healthcare Payment Processors

On September 14, 2022, the Federal Bureau of Investigation (FBI) issued a Private Industry Notification (Notification) warning the industry regarding increasing cyber-attack activity against healthcare providers and payment...more

HHS Requests FCC Opinion on Whether Certain Telephonic Communications are Permissible Under the Telephone Consumer Protection Act

On April 28, 2022, in a joint letter written by the HHS Secretary, Xavier Becerra, and CMS Administrator, Chiquita Brooks-LaSure, to the Chairwoman of the Federal Communications Commission (FCC), HHS requested an opinion...more

Department of Health and Human Services Seeks Input on HIPAA “Safe Harbor”

On April 6, 2022, the Department of Health and Human Services Office for Civil Rights (OCR) issued a Request for Information (RFI) to solicit public comments on the implementation of the “safe harbor” under the Health...more

HHS Seeks Input on HIPAA “Safe Harbor”

On April 6, 2022, HHS Office for Civil Rights (OCR) issued a Request for Information (RFI) to solicit public comment on the implementation of the newly-enacted “safe harbor” under the Health Insurance Portability and...more

FTC Warns Health Apps and Connected Device Companies to Comply with the Health Breach Notification Rule

On September 15, 2021, the Federal Trade Commission (“FTC”) issued a Policy Statement instructing health app and connected device companies to comply with the Health Breach Notification Rule (“the Rule”). The Rule, codified...more

Colorado Enacts Sweeping Privacy Law

On July 7, 2021, Colorado enacted a new privacy law, titled the Colorado Privacy Act (CPA). The CPA is the third state-level omnibus data privacy law, similar in scope to the California Consumer Privacy Act (CCPA) and the...more

Supreme Court Accepts Narrow Definition of Autodialer, Limiting Reach of TCPA

On April 1, in a highly anticipated decision that likely will have a significant effect on litigation under the Telephone Consumer Protection Act (TCPA), the Supreme Court ruled on what qualifies as an “automatic telephone...more

53 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide