News & Analysis as of

Reporting Requirements Data Breach Personally Identifiable Information

Tarter Krinsky & Drogin LLP

Businesses Have 30 Days to Report a Security Breach of New Yorker’s Private Information

New York State Governor Hochul recently gave us a “pre” New Year’s gift: effective on December 21, 2024, any individuals or businesses possessing the “private information” of New Yorkers must notify them, and certain state...more

Troutman Pepper Locke

Amendments Align Pennsylvania’s Breach Notification Law With Majority of States

Troutman Pepper Locke on

Earlier this year, Governor Josh Shapiro signed amendments to Pennsylvania’s Breach of Personal Information Notification Act (BPINA) into law, which go into effect on September 26. As part of the implementation of these...more

Health Care Compliance Association (HCCA)

Privacy Briefs: September 2024

The HHS Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS) are notifying 946,801 people whose protected health information or other personally identifiable information...more

Health Care Compliance Association (HCCA)

Privacy Briefs: April 2024

The Cybersecurity and Infrastructure Agency (CISA) is seeking comment on a proposed rule to implement reporting requirements for critical infrastructure entities, including health care entities, on cyberattacks and ransomware...more

Health Care Compliance Association (HCCA)

Privacy Briefs: February 2024

The American Hospital Association (AHA) has warned that information technology (IT) help desks are being targeted in a social engineering scheme that uses the stolen identity of revenue cycle employees or employees in other...more

Pillsbury Winthrop Shaw Pittman LLP

FCC Updates Data Breach Notification Rules

At its December meeting, the Federal Communications Commission approved a Report and Order modifying its data protection rules. The order expands the scope of protected data to include personally identifiable information....more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

Stikeman Elliott LLP

Québec’s Proposed Confidentiality Incident Regulation: When to Notify and What to Include

Stikeman Elliott LLP on

A little over nine months after it passed An Act to modernize legislative provisions as regards the protection of personal information (“Bill 64”) overhauling, among other legislation, the province’s public and private sector...more

McDermott Will & Emery

Federal Data Breach Reporting Requirements Continue to Evolve

McDermott Will & Emery on

Complementing the patchwork of state data breach notification laws, a number of federal agencies recently have promulgated sector-specific reporting rules affecting a variety of companies, both directly and indirectly, with...more

Epstein Becker & Green

Annual Breach Reporting Required Under NY SHIELD Act for Some Health Care Companies

As discussed in an earlier blog post, the New York state Stop Hacks and Improve Electronic Data Security Act (or “SHIELD Act”), was signed into law on July 25, 2019....more

Blake, Cassels & Graydon LLP

One Year into Mandatory Reporting, Canada’s Privacy Commissioner Releases Key Data Breach Trends

To mark the one-year anniversary of mandatory breach reporting under the Personal Information Protection and Electronic Documents Act (PIPEDA), the Office of the Privacy Commissioner of Canada (OPC) published a blog post...more

Fox Rothschild LLP

Canada Releases One-Year Report On National Breach Reporting Law

Fox Rothschild LLP on

On November 1st of last year, businesses became subject to new mandatory breach reporting regulations under Canada’s federal private sector privacy law, the Personal Information Protection and Electronic Documents Act...more

BCLP

CCPA Security FAQs: Do businesses have to report data breaches to the state of California?

BCLP on

Sometimes. While the CCPA does not require that companies report data breaches to the state of California, California’s data breach notification statute, enacted in 2003, requires that some data breaches that involve...more

Hogan Lovells

A new model for obtaining data protection consents: unbundling the proposed amendments to China's Personal Information Security...

Hogan Lovells on

On 1 February, 2019, the National Information Security Standardization Technical Committee issued an amended version of the GB/T 35372-2017 Information Technology – Personal Information Security Specification for public...more

White & Case LLP

Chapter 10: Obligations of controllers – Unlocking the EU General Data Protection Regulation

White & Case LLP on

Why does this topic matter to organisations? Each time an organisation processes personal data, it will do so as either a controller or a processor. These roles bear different responsibilities. Therefore, it is critically...more

BakerHostetler

Racing to Meet the 72-hour Deadline to Report a Personal Data Breach in the EU? A GDPR Resource Is Available

BakerHostetler on

Companies face substantial challenges in complying with breach notification requirements under Article 33 of the General Data Protection Regulation (GDPR). Article 33 requires a data controller to report a personal data...more

Mintz - Privacy & Cybersecurity Viewpoints

Uber and FTC Arrive at Settlement: Extensive Monitoring, but no FTC Fines Ahead

Recently, the Federal Trade Commission (“FTC”) announced that it has finalized its expanded settlement with ride-haling giant, Uber Technologies, Inc. (“Uber”) related to two major data breach incidents. The initial breach...more

Blake, Cassels & Graydon LLP

What to Expect Come November 2018: Privacy Commissioner’s Final Guidelines on Mandatory Breach Reporting under PIPEDA

On October 29, 2018, the Office of the Privacy Commissioner of Canada (OPC) published the final guidance intended to assist organizations in complying with the mandatory breach reporting and record-keeping requirements under...more

Mintz - Privacy & Cybersecurity Viewpoints

Failure to Signal: Uber Forced to Accept Expanded Settlement after Concealing Security Breach from FTC

Uber Technologies, Inc. (“Uber”) has agreed to an expansion of its initial August 2017 proposed consent agreement with the Federal Trade Commission (“FTC”), in light of revelations of an additional security breach in October...more

Blake, Cassels & Graydon LLP

Federal Data Breach Reporting Regulations Published – Take Effect November 2018

The final Breach of Security Safeguards Regulations (Regulations) under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) were made on March 26, 2018, and published on April 18, 2018. The...more

Harris Beach Murtha PLLC

Uber Goes 0-2 in Data Breach Notifications

In August, 2017, the Federal Trade Commission (“FTC”) proposed a settlement agreement with Uber stemming from its investigation of a 2014 data breach due to Uber’s “unreasonable security practices”. The lengthy investigation...more

Littler

Data Breach Notification Coming to Canada

Littler on

The Government of Canada has announced that its proposed data breach notification requirements pursuant to the Digital Privacy Act (the “Act”) will take effect on November 1, 2018. The Act amends Canada’s Personal...more

Sheppard Mullin Richter & Hampton LLP

New York Settles EmblemHealth Breach for $575,000

The recent $575,000 settlement with EmblemHealth signals a push from AG Schneiderman “for stronger security laws and hold[ing] businesses accountable for protecting their customers’ personal data.” Noting New York’s “weak and...more

Bricker Graydon LLP

Reminder: Notice of 2017 small HIPAA breaches due to HHS soon

Bricker Graydon LLP on

The deadline to submit notice to the Department of Health and Human Services (HHS) of small HIPAA breaches (those that affected fewer than 500 individuals) discovered in calendar year 2017 is March 1, 2018....more

Bass, Berry & Sims PLC

General Services Administration Announces Plans to Update Cybersecurity Requirements for Contractors

Bass, Berry & Sims PLC on

In mid-January, the General Services Administration (GSA) released their Semiannual Regulation Agenda. Within this agenda, GSA announced plans to update requirements in the General Services Administration Acquisition...more

33 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide