News & Analysis as of

Safe Harbors Health Insurance Portability and Accountability Act (HIPAA) Data Breach

Bradley Arant Boult Cummings LLP

Florida Bill Proposes Safe Harbor Against Breach Suits to Businesses Maintaining Recognized Cybersecurity Programs

A recently introduced bill in the Florida Legislature would provide businesses operating in Florida, including health care providers, with a legal defense to data breach lawsuits if they maintain robust cybersecurity measures...more

Foley & Lardner LLP

State Data Breach Notification Laws - September 2022

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Akin Gump Strauss Hauer & Feld LLP

Connecticut Expands Breach Reporting and Creates Cybersecurity Safe Harbor

On October 1, 2021, two Acts overhauling data privacy and cybersecurity in Connecticut took effect—the latest instance of stronger state breach reporting requirements with a safe harbor protection from litigation for...more

Hogan Lovells

Hold the punitive damages: Connecticut is latest to incentivize implementing cybersecurity frameworks

Hogan Lovells on

Connecticut’s new cybersecurity standards law, which goes into effect on October 1, 2021, protects companies from punitive damages in certain data breach actions where an organization has a cybersecurity program that conforms...more

Jackson Lewis P.C.

Connecticut Enacts Safe Harbor From Punitive Damages In Data Breach Cases

Jackson Lewis P.C. on

Effective October 1, 2021, Connecticut becomes the third state with a data breach litigation “safe harbor” law (Public Act No. 21-119), joining Utah and Ohio. In short, the Connecticut law prohibits courts in the state from...more

Lowenstein Sandler LLP

States’ Safe Harbor Defense For Data Security Breaches Signals Possible Trend

Lowenstein Sandler LLP on

We are now seeing a potential trend where states are incentivizing companies through the creation of safe harbors to improve their cybersecurity posture, instead of penalizing them after a breach of personal information. Utah...more

Jackson Lewis P.C.

Indiana AG Proposed Regulations Creating Corrective Action Plan Requirement And Cybersecurity Safe Harbor

Jackson Lewis P.C. on

A proposal by Indiana’s Attorney General Curtis Hill on Wednesday would add a significant step in the incident response process for responding to breaches of security affecting Indiana residents. On Wednesday, during a U.S....more

Foley & Lardner LLP

State Data Breach Notification Laws - September 2020

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Womble Bond Dickinson

Ohio Enacts First Cybersecurity Safe Harbor

Womble Bond Dickinson on

Tacking an entirely new direction from other US states, Ohio has decided to offer defensive legal protection to businesses who have built a cybersecurity regime around well-known industry standards, even where those...more

Bricker Graydon LLP

Ohio’s new cybersecurity safe harbor law takes effect

Bricker Graydon LLP on

On November 2, 2018, Ohio’s new cybersecurity law became effective and provides entities with cybersecurity programs that meet certain requirements an affirmative defense against certain tort actions. ...more

Sheppard Mullin Richter & Hampton LLP

Ohio Gives Breach Safe Harbor for Companies with Written Data Security Program

Effective November 2, 2018, companies that suffer a breach may have certain defenses in Ohio if they have a written cybersecurity program in place. Under this new law, companies can use as an affirmative defense the existence...more

Robinson & Cole LLP

Data Privacy + Cybersecurity Insider - September 2018 #3

Robinson & Cole LLP on

Schneider Electric recently issued a consumer warning that it mistakenly shipped to its customers USB drives that were infected with malware. Schneider Electric stated in its alert that “Schneider Electric has determined that...more

Mintz - Health Care Viewpoints

OCR Highlights Importance of Physical Safeguards to Protect PHI

The May 2018 cyber security newsletter from the U.S. Department of Health and Human Services Office for Civil Rights (OCR) focused on a topic often overlooked by covered entities and their business associates: physical...more

Alston & Bird

2016 Breach Roundup, Part I: U.S. State Data Breach Notification Laws Highlights and Trends

Alston & Bird on

In many respects, 2016 has been a remarkable year, but one constant with recent history is that multiple states (six this year) amended their breach notification statutes. As is commonly stated, the U.S. ...more

Mintz - Privacy & Cybersecurity Viewpoints

Illinois Joins the Fray: Strengthens its Laws Around Data Breach Notification and Data Security

Sophisticated phishing scams and muscular hacking efforts continue to compromise personal and sensitive information held by insurers, hospital systems, and businesses large and small. In response, many states have...more

Miller & Martin PLLC

Tennessee Legislature Amends Data Breach Notification Statute - Encryption is No Longer an Automatic Safe Harbor

Miller & Martin PLLC on

On March 24, 2016, Governor Haslam signed S.B. 2005 which amends Tennessee's data breach notice statute. The amended statute will go into effect on July 1, 2016. The new Tennessee breach notice requirements are triggered by...more

Davis Wright Tremaine LLP

Tennessee Gives Businesses 45 Days for Data Breach Notice

Recent amendments to the State’s data breach statute give a hard deadline for a business to provide consumer notice, removes encryption safe harbor, exempts entities that are subject to the Health Insurance Portability and...more

Carlton Fields

The FCC's TCPA Regulatory Ruling Imposes Tighter Call Restrictions

Carlton Fields on

Last month, the Federal Communications Commission (FCC) released a long awaited declaratory ruling and order, FCC 15-72, addressing several petitions which sought clarification of or exemptions from Telephone Consumer...more

BakerHostetler

State Law Roundup: Legislatures Across the U.S. Revamp Data Breach Notification Laws

BakerHostetler on

As the number of highly publicized data breaches continues to skyrocket and proposals for a federal data breach notification law stagnate, state legislatures around the country have been busy amending their own breach...more

McDermott Will & Emery

U.S. Privacy and Data Protection: 2013 Year in Review and a Look Ahead to 2014

McDermott Will & Emery on

In Boston, we celebrated Data Privacy Day (January 28) by presenting “U.S. Privacy and Data Protection: 2013 Year In Review and a Prediction of What’s to Come in 2014” for participants in an IAPP KnowledgeNet. Our panel of...more

20 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide