News & Analysis as of

Reporting Requirements Cybersecurity Personally Identifiable Information

Katten Muchin Rosenman LLP

SEC Grants Further Relief From Including Personally Identifiable Information in CAT Reporting

On February 10, the Securities and Exchange Commission (SEC) granted relief exempting industry members from reporting a natural person’s name, address, and year of birth to the Consolidated Audit Trail (CAT). Industry members...more

Tarter Krinsky & Drogin LLP

Businesses Have 30 Days to Report a Security Breach of New Yorker’s Private Information

New York State Governor Hochul recently gave us a “pre” New Year’s gift: effective on December 21, 2024, any individuals or businesses possessing the “private information” of New Yorkers must notify them, and certain state...more

Holland & Knight LLP

NY Department of Health Bolsters Hospital Cybersecurity Regulations

Holland & Knight LLP on

New York hospitals have less than a year to dust off their Health Insurance Portability and Accountability Act (HIPAA) compliance programs and update them to comply with more stringent and detailed state regulations. Last...more

Lippes Mathias LLP

Hospital Administrators – Is Your Hospital Cyber-Secure?

Lippes Mathias LLP on

On October 2, 2024, New York adopted new regulations requiring general hospitals to implement heightened cybersecurity safeguards. General hospitals, as defined in Article 28 of the NY Public Health Law, generally must begin...more

Health Care Compliance Association (HCCA)

Privacy Briefs: September 2024

The HHS Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS) are notifying 946,801 people whose protected health information or other personally identifiable information...more

Foley Hoag LLP - Security, Privacy and the...

SEC Revamps and Enhances Data Protections with Amendments to Regulation S-P

The Securities and Exchange Commission (“SEC”) has announced the adoption of amendments to Regulation S-P (“Amendments”) to modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal...more

Ballard Spahr LLP

FHA Requiring Reporting of Significant Cybersecurity Incidents

Ballard Spahr LLP on

In Mortgagee Letter 2024-10, FHA announced a requirement for FHA approved lenders to notify the U.S. Department of Housing and Urban Development (HUD) of Significant Cybersecurity Incidents. The Mortgagee Letter, which is...more

Health Care Compliance Association (HCCA)

Privacy Briefs: April 2024

The Cybersecurity and Infrastructure Agency (CISA) is seeking comment on a proposed rule to implement reporting requirements for critical infrastructure entities, including health care entities, on cyberattacks and ransomware...more

Health Care Compliance Association (HCCA)

Privacy Briefs: February 2024

The American Hospital Association (AHA) has warned that information technology (IT) help desks are being targeted in a social engineering scheme that uses the stolen identity of revenue cycle employees or employees in other...more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

Stikeman Elliott LLP

Québec’s Proposed Confidentiality Incident Regulation: When to Notify and What to Include

Stikeman Elliott LLP on

A little over nine months after it passed An Act to modernize legislative provisions as regards the protection of personal information (“Bill 64”) overhauling, among other legislation, the province’s public and private sector...more

McDermott Will & Emery

Federal Data Breach Reporting Requirements Continue to Evolve

McDermott Will & Emery on

Complementing the patchwork of state data breach notification laws, a number of federal agencies recently have promulgated sector-specific reporting rules affecting a variety of companies, both directly and indirectly, with...more

Epstein Becker & Green

Annual Breach Reporting Required Under NY SHIELD Act for Some Health Care Companies

As discussed in an earlier blog post, the New York state Stop Hacks and Improve Electronic Data Security Act (or “SHIELD Act”), was signed into law on July 25, 2019....more

Blake, Cassels & Graydon LLP

One Year into Mandatory Reporting, Canada’s Privacy Commissioner Releases Key Data Breach Trends

To mark the one-year anniversary of mandatory breach reporting under the Personal Information Protection and Electronic Documents Act (PIPEDA), the Office of the Privacy Commissioner of Canada (OPC) published a blog post...more

Fox Rothschild LLP

Canada Releases One-Year Report On National Breach Reporting Law

Fox Rothschild LLP on

On November 1st of last year, businesses became subject to new mandatory breach reporting regulations under Canada’s federal private sector privacy law, the Personal Information Protection and Electronic Documents Act...more

Harris Beach Murtha PLLC

With SHIELD Act, New York State Requires Enhanced Protection of Residents' Private Data

Just prior to the sweltering hot weekend, Governor Cuomo signed into law the Stop Hacks and Improve Electronic Data Security Act, or SHIELD Act. Taking effect on March 22, 2020, the law imposes new obligations on entities to...more

Hogan Lovells

A new model for obtaining data protection consents: unbundling the proposed amendments to China's Personal Information Security...

Hogan Lovells on

On 1 February, 2019, the National Information Security Standardization Technical Committee issued an amended version of the GB/T 35372-2017 Information Technology – Personal Information Security Specification for public...more

BakerHostetler

Racing to Meet the 72-hour Deadline to Report a Personal Data Breach in the EU? A GDPR Resource Is Available

BakerHostetler on

Companies face substantial challenges in complying with breach notification requirements under Article 33 of the General Data Protection Regulation (GDPR). Article 33 requires a data controller to report a personal data...more

Bradley Arant Boult Cummings LLP

New Year, New Data Security Requirement: South Carolina Adopts New Data Security Law

On January 1st, South Carolina became the first state to adopt the model insurance data security law requiring certain insurance licensees to investigate and report cybersecurity events in the state of South Carolina. The law...more

Mintz - Privacy & Cybersecurity Viewpoints

Uber and FTC Arrive at Settlement: Extensive Monitoring, but no FTC Fines Ahead

Recently, the Federal Trade Commission (“FTC”) announced that it has finalized its expanded settlement with ride-haling giant, Uber Technologies, Inc. (“Uber”) related to two major data breach incidents. The initial breach...more

Blake, Cassels & Graydon LLP

What to Expect Come November 2018: Privacy Commissioner’s Final Guidelines on Mandatory Breach Reporting under PIPEDA

On October 29, 2018, the Office of the Privacy Commissioner of Canada (OPC) published the final guidance intended to assist organizations in complying with the mandatory breach reporting and record-keeping requirements under...more

FordHarrison

OSHA Proposes Rescinding Part of Electronic Records Rule

FordHarrison on

On July 27, 2018, the Occupational Safety and Health Administration (OSHA) issued a news release stating that it has issued a Notice of Proposed Rulemaking to “better protect personally identifiable information or data that...more

Holland & Hart LLP

Defending Data: New Colorado Law Creates Stricter Obligations for Handling Data Breaches, Disposal, and Security

Holland & Hart LLP on

Last week, Governor John Hickenlooper signed a bill with wide ranging implications for any entity that collects and maintains the personal information of Colorado residents. The law, which goes into effect on September 1,...more

Mintz - Privacy & Cybersecurity Viewpoints

Failure to Signal: Uber Forced to Accept Expanded Settlement after Concealing Security Breach from FTC

Uber Technologies, Inc. (“Uber”) has agreed to an expansion of its initial August 2017 proposed consent agreement with the Federal Trade Commission (“FTC”), in light of revelations of an additional security breach in October...more

Blake, Cassels & Graydon LLP

Federal Data Breach Reporting Regulations Published – Take Effect November 2018

The final Breach of Security Safeguards Regulations (Regulations) under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) were made on March 26, 2018, and published on April 18, 2018. The...more

34 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide