Latest Publications

Share:

New Jersey Requires Employers to Make a Retirement Savings Vehicle Available to Employees

In an effort to close the gap in retirement savings across the state, Governor Phil Murphy signed the New Jersey Secure Choice Savings Program Act (Act) in March of 2019. The Act created the Secure Choice Savings Program...more

Construction Industry: Data Security Considerations

No industry is immune to privacy and cybersecurity risks, and the construction industry is no exception. Those in the construction industry can protect against a potential cyberattack by understanding the risks and...more

“Get a Life” – Another Dentist Responds to Patient’s Online Review, This Time Faces a $50,000 OCR Penalty

It can be cathartic responding to a negative online review. It can also backfire, as can failing to cooperate with an OCR investigation as required under HIPAA. The Office for Civil Rights (OCR) recently announced four...more

Utah Becomes Fourth State to Enact A Comprehensive Privacy Law

Just as businesses are preparing to ensure compliance with similar laws in California, Colorado, and Virginia, they soon will need to consider a fourth jurisdiction, Utah. On March 24, 2022, Governor Spencer Cox signed a...more

FTC Settles Privacy and Security Allegations with Online Merchant for $500K and Agreement to Extensive Compliance Program

The FTC recently settled its enforcement action involving data privacy and security allegations against an online seller of customized merchandise. In addition to agreeing to pay $500,000, the online merchant consented to...more

Is Crypto Too Cryptic for Your 401(k) Plan?

It started sometime last year and, in hindsight, was inevitable. Clients with 401(k) plans and a crypto-savvy employee population began asking whether they could offer cryptocurrency as a plan investment option. In the...more

Cyber Incident, Ransom Payment Reporting to DHS Mandatory for Critical Infrastructure Entities

Included within the Consolidated Appropriations Act, 2022, signed by President Joe Biden on March 15, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Act) creates new data breach reporting requirements....more

Not-For-Profits, Charities Might Attract More Donors with Improved Website Content, Attention to Privacy

According to Giving USA, charitable contributions in 2020 exceeded $470 billion, 70 percent of which came from individuals. Individuals deciding to donate to a particular organization may be considering factors beyond the...more

Do Employers Need a CISO for ERISA Compliance?

According to a recent survey, about 45% of companies do not have a Chief Information Security Officer (CISO). As West Monroe’s “The Importance of a CISO” observes, it would be terrific for all organizations to have a CISO,...more

California State Senator Introduces a BIPA-like Law to Protect Biometric Information

Some members of the California legislature want their state to remain the leader for data privacy and cybersecurity regulation in the U.S. This includes protections for biometric information, similar to those under the...more

Massachusetts Privacy Bill Provides WISP Reminder, Safe Harbor for Punitive Damages

When Massachusetts issued its data security regulations in 2009 (Regulations), it led the way for states on data security. The Regulations became effective 12 years ago, almost to the day, March 1, 2010. The Bay State is now...more

SEC to Advisors and Funds – Adopt and Implement Cybersecurity Policies and Procedures

On February 9, the Securities and Exchange Commission (“SEC”) voted to propose rule 206(4)-9 under the Advisers Act and 38a-2 under the Investment Company Act (collectively, “Proposed Rule”). In general, the Proposed Rule...more

Jump in Facial and Voice Recognition Raises Privacy, Cybersecurity, Civil Liberty Concerns

Facial recognition, voiceprint, and other biometric-related technology are booming, and they continue to infiltrate different facets of everyday life. The technology brings countless potential benefits, as well as significant...more

Fraud, Data Breaches Continuing to Crush Federal and State Unemployment Benefit Departments, Pennsylvania’s Next?

Few want to get past the COVID-19 pandemic more than leaders of federal and state unemployment benefit departments. For the last 2 years they have been successfully targeted for fraud and data breaches, racking up billions in...more

The RIPTA Data Breach May Provide Valuable Lessons About Data Collection and Retention

Efforts to secure systems and data from a cyberattack often focus on measures such as multifactor authentication (MFA), endpoint monitoring solutions, antivirus protections, and role-based access management controls, and for...more

From Time Keeping to Dashcams, BIPA Litigation Continues

The use of smart dashcams and vehicle cameras, including those leveraging AI technology, may trigger the next wave of BIPA litigation, according to two cases filed in Illinois this week. Enacted in 2008, the Illinois...more

Preventing “Credential Stuffing” Attacks, Guidance from NY State Attorney General Letitia James

After reading New York Attorney General Letitia James’ Business Guide for Credential Stuffing Attacks (“Guide”), I promptly reminded my family (and myself!) to change passwords. The practice of using the same password for...more

Does a Poor ESG, Social Responsibility Rating Increase an Organization’s Cyber Risk?

With ransomware and other cyber threats top of mind for most in the c-suite these days, a question frequently raised is whether a particular organization is a target for hackers. Of course, nowadays, any organization is at...more

Does Your Cyber Insurance Policy Look More Like Health Insurance?

Over the past several years, if your organization experienced a cyberattack, such as ransomware or a diversion of funds due to a business email compromise (BEC), and you had cyber insurance, you likely were very thankful....more

Responding to the Kronos Cyber Attack – What Should Employers Be Thinking About?

According to reports, Kronos, the cloud-based, HR management service provider, suffered a data incident involving ransomware affecting its information systems. Kronos communicated that it discovered the incident late on...more

Employee Monitoring: New York Establishes New Requirements for Employers

Earlier this month, New York Governor Kathy Hochul signed into a law a bill that will require New York private sector employers to provide written notice to employees before engaging in electronic monitoring of their...more

OSHA ETS: What Records Must Covered Employers Collect, Retain, Safeguard, and Make Available Upon Request

Last week, the Occupational Safety and Health Administration (OSHA) issued an Emergency Temporary Standard (ETS) implementing President Joe Biden’s COVID-19 vaccine mandate covering employers with at least 100 employees. The...more

452 Results
 / 
View per page
Page: of 19

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide