Latest Publications

Share:

NAIC Privacy Protections Working Group Meets to Discuss New Model Privacy Law

On June 5-6, 2023, the NAIC Privacy Protections (H) Working Group (“PPWG”) held an in-person interim meeting (“session”) to continue its work on drafting a new model privacy law, the Insurance Consumer Privacy Protection...more

HIPAA Regulation of Online Tracking Technologies

In a December 2022 bulletin published by the Office for Civil Rights at the U.S. Department of Health and Human Services (HHS), HHS made clear that the use of third-party tracking technologies by covered entities and business...more

NYDFS Releases Pre-Proposed Second Amendment to its Cybersecurity Regulations, 23 NYCRR 500

On July 29, 2022, the New York Department of Financial Services (NYDFS) published the pre-proposed second amendment to its Cybersecurity Regulations, 23 NYCRR 500 (Part 500), that if adopted, would likely require numerous...more

Ransomware Payments Become an Even Riskier Choice Amidst the Ever-Growing Sanctions List

In February 2022, Executive Order 14024 highlighted that Russia’s invasion of Ukraine threatened not only Ukraine but also the national security and foreign policy of the United States. Pursuant to this executive order, and...more

Insurance Privacy, Cybersecurity and Data Strategy: Mid-2022 Updates

The first half of 2022 brought plenty of activity in the data privacy and cybersecurity space, much of which is applicable to or of interest to the insurance industry. We outline some of this activity below. Revisions to...more

New York Department of Financial Services Announces $5 Million Penalty in Most Recent Cybersecurity Enforcement Action

On June 23, 2022, the New York State Department of Financial Services (NYDFS) announced the entry of a Consent Order in connection with its most recent cybersecurity enforcement action, which included a $5 million monetary...more

Artificial Intelligence Briefing: Feds Take Aim at Algorithmic Bias

Our latest briefing examines the latest signal that the Federal Trade Commission is considering rulemaking, a groundbreaking settlement between the Justice Department and Meta over allegedly discriminatory algorithms,...more

HHS Ransomware Report Details Revival of Dangerous LOTL Cyberattack

On May 5, 2022, the U.S. Department of Health and Human Services (HHS) issued a report entitled “Ransomware Trends in the HPH Sector” (HHS Report) that reviewed key cybersecurity threats and trends affecting the U.S....more

A Cyber Hygiene Strategy: Cyber Insurance Endorsements

In the insurance industry, an “endorsement” is used to amend an insurance policy. Endorsements can be used to add items to a policy, amend policy provisions, or update an insured’s coverage. Endorsements also can be used to...more

Congress Passes New Cyber Incident and Ransomware Payment Reporting Legislation

The United States Congress recently passed legislation that includes new cybersecurity provisions requiring critical infrastructure providers to report cyber security incidents, including the payment of ransom, to the...more

Capping Cyber Casualties: Steps to Avoid Cyberattacks Flowing From Hostilities in Ukraine

The televised “thud” of explosions in Ukraine has an ominous but deceptively distant tone. For many organizations the hostilities are closer at hand, in the form of cyberattacks that could spread beyond the Russian-Ukrainian...more

New York DFS Broadens the Permissible Use of Electronic Communication for Property/Casualty Insurance Notices

On December 22, 2021, Gov. Kathy Hochul signed Senate Bill S653A, relating to electronic delivery of property/casualty insurance notices. This bill amends the New York Insurance Law by adding section 3458, which takes effect...more

New York Department of Financial Services Issues New Guidance on Multi-Factor Authentication and Cybersecurity Frameworks

With cyberattacks continuing to plague the financial services industry, the New York Department of Financial Services (NYDFS) recently released new guidance for regulated entities related to the use of Multi-Factor...more

Feds Hope to Tighten Timeline for Agency Reporting of Cyberattacks as Congress Debates Federal Data Breach Notification Law

On December 6, 2021, in the Memorandum for the Heads of Executive Departments and Agencies, the Office of Management and Budget took a more aggressive position on strengthening the nation’s cybersecurity posture. Under this...more

NIST Releases New “Cybersecurity Framework Profile for Ransomware Risk Management” to Battle Growing Threat of Ransomware Attacks

Ransomware incidents continue to be on the rise, wreaking havoc for organizations globally. Ransomware attacks target an organization’s data or infrastructure, and, in exchange for releasing the captured data or...more

Senators Introduce Bipartisan Legislation To Require Federal Contractors and Operators of Critical Infrastructure to Disclose...

A bipartisan group of 14 United States senators recently introduced proposed legislation that would require federal contractors and operators of critical infrastructure to disclose any cyber intrusion within 24 hours...more

Updates to the Long-Term Care Insurance NAIC Model Act and Model Regulation

As part of its effort to revamp and modernize the Model Laws, the NAIC is updating the Long-Term Care Insurance Model Act, Model 640-1, and the Long-Term Care Insurance Model Regulation, Model 641-1 (combined, the Models)....more

ERISA Litigation Roundup: A Ninth Circuit Ruling Reminds ERISA Plans of the Importance of Administrative Accuracy

The Ninth Circuit’s recent decision in Bafford v. Northrop Grumman (April 15, 2021) affirmed the district court’s dismissal of the plaintiffs’ breach of fiduciary duty claims under ERISA but vacated the district court’s...more

Kaseya: The Latest High-Profile Ransomware Attack

On July 2, 2021, Kaseya Ltd., a Florida-based firm that provides software tools to thousands of primarily small and mid-sized businesses, became the latest victim of a high-profile ransomware attack. The attack is believed to...more

Federal Legislation Considers Banning Ransom Payments to Hackers

The year 2021 continues to reveal an alarming rise in ransomware attacks. Two of the most notable of such attacks include the ransomware attack on CNA Financial Corp., with resulting payment of $40 million in ransom, and the...more

“Zero Trust Architecture” Is Officially Here: NIST Publishes New Cybersecurity Framework

The National Institute of Standards and Technology, commonly referred to as NIST, recently published a new computer framework for users to consider as a cyber-framework security model — the Zero Trust Architecture Model...more

New Bill Proposes that Americans Should Be Able to Sue Foreign Hackers

The Homeland and Cyber Threat Act (HACT) was introduced in the U.S. House on March 12, 2021. This bill would allow U.S. citizens to sue foreign governments, agents and officials and to collect monetary damages for personal...more

New MHPAEA FAQs On Comparative Analyses Requirements

On April 2, the U.S. Department of Labor released highly anticipated new Mental Health Parity and Addiction Equity Act (MHPAEA) FAQs on comparative analyses requirements. These FAQs follow the February 10, 2021, effective...more

ERISA Litigation Roundup: Forum Selection Clause in Plan Recognized as Valid

Denying a petition for a writ of mandamus, a Ninth Circuit panel has held that the district court properly enforced a forum selection clause contained in an ERISA-sponsored 401(k) plan in litigation regarding the alleged...more

New State and Federal Privacy Developments Add Complexity to Privacy Landscape

As insurance companies continue to examine their compliance with current privacy and cybersecurity regulations, new state laws and proposed federal bills add another level of complexity to the landscape. Federal - The...more

25 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide