News & Analysis as of

State Data Breach Notification Statutes Data Breach Cybersecurity

Epiq

Cyber Incidents on the Rise: Tips for Effective Data Breach Notification

Epiq on

Cyber incidents have been growing at an exponential rate in recent years. A recent report from the Identity Theft Resource Center found that there were over one billion data breach victims in Q2 of 2024, which is around five...more

Manatt, Phelps & Phillips, LLP

Balancing New Federal & State Cyber Reporting Rules on Health Care & Financial Services Industries

Balancing cybersecurity incident disclosures has been a challenge for those in the trenches for years. That has not changed, and recent regulatory activity should not alter the challenges breach counsel confront. In short,...more

BakerHostetler

Florida and Connecticut Expand Breach Laws to Include Geolocation Data as Personal Information

BakerHostetler on

Consistent with recent trends in broadening the scope of state data breach notification statutes, Connecticut and Florida have expanded the definitions of personal information under their respective data breach notification...more

Venable LLP

Data Breach Notice Requirement Added to Safeguards Rule for Non-bank Financial Institutions

Venable LLP on

Non-bank financial institutions will have a new data breach disclosure requirement effective May 13, 2024. The Federal Trade Commission (FTC) recently updated the Gramm-Leach-Bliley Safeguards Rule (“Safeguards Rule”), adding...more

Troutman Pepper

Cleanup on Aisle 1: Pennsylvania Grocer Rutters Latest to Settle Single-State Data Breach Investigation With Pennsylvania AG

Troutman Pepper on

Rutters, a prominent grocery chain in Pennsylvania with 80 locations statewide, settled a data breach investigation with Attorney General (AG) Michelle Henry’s office by agreeing to pay $1 million and to implement certain...more

Perkins Coie

2023 Breach Notification Law Update: Changes to Notification and Security Requirements Continue at State and Federal Levels

Perkins Coie on

A flurry of legislative activity over the past year has brought meaningful changes to a variety of privacy and security provisions in state and federal law. At the state level, as in 2022, we have seen a handful of changes to...more

Davis Wright Tremaine LLP

New Iowa Legislation Creates Cybersecurity Safe Harbor

Iowa becomes the fourth U.S. state to provide an affirmative defense for companies that adopt a cybersecurity framework - Iowa is the fourth state—following Ohio, Connecticut, and Utah—to provide a statutory incentive for...more

Davis Wright Tremaine LLP

Data Breach Notification Law Update: Texas

Texas amended its data breach notification law to significantly tighten the deadline for notifying the state attorney general (AG) of a data breach affecting 250 or more state residents. Senate Bill 768, which amended Section...more

Davis Wright Tremaine LLP

Data Breach Notification Law Update: Utah and Pennsylvania

For businesses subject to data breach notification requirements in Utah and Pennsylvania, a series of significant amendments will soon go into effect in both states. ...more

Foley & Lardner LLP

State Data Breach Notification Laws - March 2023

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Ankura

Ankura CTIX FLASH Update - January 2023 - 4

Ankura on

PayPal Discloses December 2022 Security Incident Involving Credential Stuffing Attacks - PayPal has begun sending out notification letters to individuals impacted by a security incident that occurred in early December...more

Mintz - Privacy & Cybersecurity Viewpoints

FCC Proposes Changes to its Reporting Requirements for Customer Data Breaches

On December 28, 2022, the Federal Communications Commission (“FCC”) adopted a Notice of Proposed Rulemaking (“NPRM”) seeking to modernize and strengthen its rules to better protect consumers from the harm caused by breaches...more

Wyrick Robbins Yates & Ponton LLP

2022 Hindsight: Breach Notification Year in Review

While new comprehensive state privacy laws took most of the headlines this year, security threats and incident response remain key risk factors for privacy compliance programs and the subject of important legal developments....more

Hinshaw & Culbertson LLP

Hinshaw Insurance Law TV – Cybersecurity Part One: Data Breach Notification

Scott Seaman—Chicago-based partner and co-chair of Hinshaw's global Insurance Services Practice Group—hosts Hinshaw partner Annmarie Giblin in a discussion about data security plans for businesses and data breach...more

BakerHostetler

[Podcast] 2022 DSIR Report Deeper Dive: The Expanding Landscape of State Data Privacy Laws

BakerHostetler on

The Data Security Incident Response Report features insights and metrics from 1,270+ incidents that members of the firm’s DADM Practice Group helped clients manage in 2021. This episode takes us deeper into the expanding...more

HaystackID

[Webcast Transcript] Data Mining in Incident Response: Managing Risk and Spend through an Effective Evidence-Based Approach

HaystackID on

Editor’s Note: On August 31, 2022, HaystackID shared an educational webcast on the topic of data mining in data breach incident response. As data mining has increasingly become one of the largest expenses during a cyber...more

Foley & Lardner LLP

State Data Breach Notification Laws - September 2022

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Orrick, Herrington & Sutcliffe LLP

Federal Trade Commission (FTC) Update: Following Breach Notification Laws Not Enough; Must Notify Consumers and Others to Mitigate...

The Federal Trade Commission (FTC) recently announced its position on breach notification:  “Regardless of whether a breach notification law applies, a breached entity that fails to disclose information to help parties...more

Robinson+Cole Data Privacy + Security Insider

Indiana Amends Breach Notification Law to Require Notification Within 45 Days

Indiana has amended its breach notification law to require entities to notify individuals “without unreasonable delay, but not more than forty-five (45) days after the discovery of the breach.” It clarifies that a delay is...more

Kennedys

Kennedys cybersecurity and privacy (US) 2021 year in review

Kennedys on

As the world emerged from lockdown, it should come as no surprise that cybersecurity and data privacy remained dominant topics in the media and legal industry. Some of 2021 was much like 2020 – ransomware attacks continued to...more

Polsinelli

Recent Amendments to State Breach Notification Laws

Polsinelli on

Over the last several months, a minority of states amended their data breach notification statutes or enacted sector-specific breach notification requirements. ...more

Vinson & Elkins LLP

Time for a Check-Up: Updates in Data Breach Notification and Reporting

Vinson & Elkins LLP on

As the onslaught of data breaches and ransomware attacks continues, state governments are grappling with ways to bolster the impact and reach of breach notification laws. All fifty states, Puerto Rico, Guam, the Virgin...more

Pietragallo Gordon Alfano Bosick & Raspanti,...

[Webinar] Privacy, Data and Cyber Security: The Current Legal Landscape - November 11th, 12:00 pm - 1:00 pm EST

Companies and consumers alike are under perpetual assault from bad actors as IoT, work from home, and cloud migration – all intended to improve productivity – have expanded the cyber attack surface. The continually evolving...more

Akin Gump Strauss Hauer & Feld LLP

Connecticut Expands Breach Reporting and Creates Cybersecurity Safe Harbor

On October 1, 2021, two Acts overhauling data privacy and cybersecurity in Connecticut took effect—the latest instance of stronger state breach reporting requirements with a safe harbor protection from litigation for...more

Hogan Lovells

Hold the punitive damages: Connecticut is latest to incentivize implementing cybersecurity frameworks

Hogan Lovells on

Connecticut’s new cybersecurity standards law, which goes into effect on October 1, 2021, protects companies from punitive damages in certain data breach actions where an organization has a cybersecurity program that conforms...more

301 Results
 / 
View per page
Page: of 13

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide