News & Analysis as of

Personally Identifiable Information Policies and Procedures

Foley Hoag LLP - Security, Privacy and the...

SEC Revamps and Enhances Data Protections with Amendments to Regulation S-P

The Securities and Exchange Commission (“SEC”) has announced the adoption of amendments to Regulation S-P (“Amendments”) to modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal...more

Hinckley Allen

Final Amendments to Regulation S-P under Securities Exchange Act of 1934

Hinckley Allen on

On May 15, 2024, the Securities and Exchange Commission (the “SEC”) issued final amendments (the “Amendments”) to Regulation S-P (originally adopted in 2000), which governs the treatment of a customer’s nonpublic personal...more

Quarles & Brady LLP

Friendly Reminder - Finalize and Post Your Consumer Health Data Privacy Notice Before March 31

Quarles & Brady LLP on

Friendly reminder – the Washington My Health My Data Act (“WMHMDA”) compliance deadline for regulated entities to post their consumer health data privacy policy is March 31, 2024 (June 30, 2024 for small businesses). A...more

Thomas Fox - Compliance Evangelist

The Importance of Effective Policies and Training in Data Protection: Lessons from a Scottish Hospital Breach

I recently had the chance to visit with Jonathan Armstrong on a recent data breach case that occurred in the health service provider NHS Lanarkshire (Scotland) during the COVID-19 pandemic. This breach serves as a stark...more

Bass, Berry & Sims PLC

DHS Publishes Long-Awaited Final Rule on Controlled Unclassified Information

Bass, Berry & Sims PLC on

On June 21, the Department of Homeland Security (DHS) published a final rule to implement security measures that safeguard controlled unclassified information (CUI) from unauthorized access and disclosure and improve incident...more

Health Care Compliance Association (HCCA)

Are Your Workers Data Protectors or Stewards? For Best Results, Organizations Should Foster Both

In some respects, assuring compliance with HIPAA has always been a challenge because many health care providers, particularly physicians, pride themselves on maintaining patient confidentiality—even when they aren’t. Nurses,...more

Rothwell, Figg, Ernst & Manbeck, P.C.

FTC Actions Hold Data Privacy Lessons For 2023

The Federal Trade Commission will have its eye on privacy and data security enforcement in 2023. In August, the agency announced that it is exploring ways to crack down on lax data security practices. In the announcement,...more

McDermott Will & Emery

10 Things Providers Should Know About California’s Data Exchange Framework

McDermott Will & Emery on

By January 31, 2023, general acute care hospitals, clinical labs and certain physician organizations and medical groups in California are required to enter into the Single Data Sharing Agreement (DSA) to participate in the...more

Vinson & Elkins LLP

The SEC Wants You to Take Out the Trash – Securely

Vinson & Elkins LLP on

In a recent Securities and Exchange Commission (“SEC”) enforcement action, the SEC concluded that a registered broker-dealer and investment adviser (the “Firm”) violated Rule 30 of Regulation S-P by failing to adopt...more

Partridge Snow & Hahn LLP

Non-Profit Organizations Can Reduce Risks by Addressing Data Privacy Concerns in Advance

With the threat of cyber-attacks making the news, it is a good time for all non-profit organizations to review their policies and procedures with respect to data privacy. Many non-profit organizations are particularly...more

Health Care Compliance Association (HCCA)

Hybrid Workforces and Compliance with Sheila Limmroth

Hybrid work is likely here to say, and, as Sheila Limmroth, privacy specialist at DCH Health System, and the author of the chapter Hybrid Work Environment in the Complete Healthcare Compliance Manual observes in this...more

Robinson+Cole Data Privacy + Security Insider

Data Minimization: What Is It and Why Practice It?

The European Union’s General Data Protection Regulation (GDPR) first launched the concept of data minimization, which states that a data controller should limit the collection of personal information to what is directly...more

Arnall Golden Gregory LLP

AGG Celebrates Data Privacy Day 2022 With 5 Key Data Privacy Considerations for Businesses

Started in Europe in 2007, Data Privacy Day, or Data Protection Day as it is known internationally, is an international effort that takes place annually on January 28 to create awareness of the importance of data privacy. In...more

Perkins Coie

State Privacy Laws: The Gift That Keeps on Giving?

Perkins Coie on

Though it was not long ago that resolutions of California Consumer Privacy Act (CCPA) readiness ushered in the new year, ‘tis the season once again to deck the halls with privacy compliance checklists. Retailers doing...more

Mayer Brown Free Writings + Perspectives

US Securities and Exchange Commission Increases Focus on Cybersecurity

This past summer’s string of cyber enforcement actions signals that cybersecurity has become a top priority for the US Securities and Exchange Commission (“SEC”). This focus is consistent with the SEC’s Division of...more

Goodwin

SEC Makes Cybersecurity Top Priority; Sanctions Firms for Cybersecurity Failures

Goodwin on

There is little doubt that the U.S. Securities and Exchange Commission is making cybersecurity a top priority. SEC Chair Gary Gensler told a Senate committee on Tuesday, September 14, 2021 that the agency is developing a...more

Akin Gump Strauss Hauer & Feld LLP

SEC Cyber Enforcement Actions – Lessons for Private Fund Managers

On August 30, 2021, the Securities and Exchange Commission announced three enforcement actions against registered investment advisers for alleged cybersecurity failures involving cloud-based email systems. All three actions...more

Neal, Gerber & Eisenberg LLP

NGE On Demand: Cybersecurity Considerations for Emerging Companies with Michael Gray and David Wheeler

NGE Corporate & Securities partner Michael Gray recently interviewed Data Privacy & Information Governance partner David Wheeler about the cybersecurity needs for small and emerging companies. The discussion focused on the...more

Bradley Arant Boult Cummings LLP

Circuit Split No More: 2nd Circuit Clarifies Article III Standing in Data Breach Cases

While more states push forward on new privacy legislation statutorily granting consumers the right to litigate control of their personal information, federal courts continue to ponder how data breach injury fits traditional...more

McDermott Will & Emery

CNIL Issues Provisional Recommendations for Remote Quality Control of Clinical Trials During the Health Crisis

Given the challenges of conducting clinical trials during the COVID-19 pandemic, many countries — including France — have allowed for some use of remote quality controls. In response to guidelines issued recently by European...more

NAVEX

4 Things to Know About Updated NIST 800-53 Standards

NAVEX on

[author: Matt Kelly] In September 2020 the National Institute of Standards and Technology (NIST) unveiled the fifth version of its cybersecurity standard formally known as SP 800-53, “Security and Privacy Controls for...more

Sherman & Howard L.L.C.

Routine Collection Of Employee Private Information May Open The Door To Costly Litigation If A Data Breach Occurs

In McFarlane v. Altice USA, Inc., a recent decision out of the Southern District of New York, a class of plaintiffs successfully established standing and stated a plausible claim for breach of implied contract based on a data...more

Reveal

Start Planning for Data Minimization Under the CPRA

Reveal on

...Just when we were getting used to the idea of the California Consumer Privacy Act (CCPA), a new law was passed in November 2020, which will supercede it. Fortunately, there is time to prepare since the California Privacy...more

McAfee & Taft

National Cybersecurity Awareness Month: 3 tips to jump-start your cybersecurity preparedness

McAfee & Taft on

We are all facing new challenges in this pandemic, including the shift to and growth of remote work. Meanwhile, we also have to contend with the increased volume of attempted cyberattacks. Despite the distraction of the...more

Foley Hoag LLP

SEC Office of Compliance Inspections and Examinations Issues COVID-19 Risk Alert to Broker-Dealers and Investment Advisers

Foley Hoag LLP on

On August 12, 2020, the SEC Office of Compliance Inspections and Examinations (OCIE) published a Risk Alert that identifies potential issues related to the COVID-19 pandemic for SEC-registered investment advisers and...more

103 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide