News & Analysis as of

Third-Party Service Provider Data Security

Foley Hoag LLP - Security, Privacy and the...

HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points

The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes. Regulators spent 2025 refining the tools they use, broadening...more

Foley & Lardner LLP

Your Data’s Travel Diary

Foley & Lardner LLP on

Today I left the house again. I thought my life would be simple, maybe settle into a spreadsheet and hang out for a while. Instead, I’m a frequent flyer in every modern organization. I have more passport stamps than a travel...more

Bond Schoeneck & King PLLC

Countdown to Data Privacy Day 2026 - Protect Your Business – Cybersecurity Provisions in Contracts

Cybersecurity and data privacy provisions should be a central consideration whenever parties negotiate contracts involving third‑party service providers who will access or process business data. This applies across a broad...more

Blake, Cassels & Graydon LLP

What Can Service Providers to the Public Sector Learn From the PowerSchool Privacy Incident?

On November 17, 2025, Ontario’s Information and Privacy Commissioner (ON IPC) and Alberta’s Office of the Information and Privacy Commissioner (AB OIPC) each released their findings from their investigations into a...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Ropes & Gray LLP

NYDFS Regulated Entities Face Stronger Cybersecurity Regulations

Ropes & Gray LLP on

The New York Department of Financial Services (“NYDFS”) implemented the final phases of amendments to its NYDFS Cybersecurity Regulation (23 NYCRR Part 500) in May and November....more

Orrick, Herrington & Sutcliffe LLP

NCUA publishes list of federal resources for credit unions using AI

Recently, the NCUA published a list of resources aimed toward guiding credit unions implementing AI or partnering with AI third-party vendors. The publication noted that while AI presented significant opportunities for...more

Jackson Lewis P.C.

The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party...

Jackson Lewis P.C. on

As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and...more

Venable LLP

Practical Tips for Reviewing AI Service and AI related "Software as a Service" (SaaS) Agreements in 2026

Venable LLP on

Artificial intelligence has quickly shifted from an innovative experiment to a core operational tool across industries. As business teams explore new AI service providers—ranging from automated analytics engines to...more

Wiley Rein LLP

Updates to NIST Cybersecurity Guidance Show Continued Focus on Cloud Services

Wiley Rein LLP on

Recent draft cybersecurity guidance from the National Institute of Standards and Technology (NIST) provides an opportunity for government contractors who provide IT services to federal agencies to weigh in on implementation...more

Troutman Pepper Locke

NCUA Issues Updated AI Resource Hub

Troutman Pepper Locke on

On December 22, the National Credit Union Administration (NCUA) updated its Artificial Intelligence (AI) resource page to consolidate key technical and policy references for federally insured credit unions. The page sits...more

Mitratech Holdings, Inc

Third-Party Data Breaches: What You Need to Know

A third-party data breach occurs when malicious actors compromise a vendor, supplier, contractor, or other organization to gain access to sensitive information or systems of the victim’s customers, clients, or business...more

Ropes & Gray LLP

On the Tenth Day of Data… Looking Back at 2025 and Ahead to NYDFS Enforcement Priorities in 2026

Ropes & Gray LLP on

While 2025 may have brought questions about the level of enforcement we would see from federal regulators, there was no question that state regulators would continue to be active, especially in the financial privacy space....more

Ropes & Gray LLP

On the Seventh Day of Data… The Growing Pains of Regulation S-P in 2025

Ropes & Gray LLP on

Financial regulators including the Securities and Exchange Commission (“SEC”) continued to focus on data protection and cybersecurity issues throughout 2025....more

Constangy, Brooks, Smith & Prophete, LLP

Warm up your defenses against cyber holiday risks

Each year, there is a holiday surge in cyberattacks employing a wide range of attack vectors. This heightened activity can make organizations more vulnerable to legal and regulatory scrutiny. This is a good time to check your...more

Robinson+Cole Data Privacy + Security Insider

Auto Credit Check Company Breach Affects 5.6 Million

700Credit, a Michigan-based company that runs credit checks and identification verification services for automobile dealerships nationwide, has announced that an “integrated partner” was compromised, allowing a bad actor to...more

Foley & Lardner LLP

Amended Regulation S-P: Here to Stay and Being Examined in 2026

Foley & Lardner LLP on

Last month, the U.S. Securities and Exchange Commission (SEC) Division of Examinations released its Fiscal Year 2026 “Examination Priorities.” In this year’s release, the SEC announced that it will begin examining covered...more

Mayer Brown

China's Cybersecurity Incident Reporting Measures Come into Effect

Mayer Brown on

The Cyberspace Administration of China (the "CAC") released the Measures on the Management of Cybersecurity Incident Reporting (the "Incident Reporting Measures") which came into force on 1 November 2025. The Measures provide...more

Morrison & Foerster LLP

Data, Cyber + Privacy Predictions for 2026

Morrison & Foerster LLP on

The Morrison Foerster Data, Cyber + Privacy team provides creative, practical advice across every stage of the information lifecycle, from navigating complex privacy laws and managing breach response to litigating data...more

Cadwalader, Wickersham & Taft LLP

When Privacy Rules Meet Fund Finance, December 2025 - The New Regulation S-P Amendments and What They Mean for Lenders in Fund...

The SEC's 2024 amendments to Regulation S-P introduce the most comprehensive update to federal privacy and data security standards for SEC-regulated institutions since the rule was adopted. While the amendments are directed...more

Blake, Cassels & Graydon LLP

Affaires mondiales Canada publie des lignes directrices sur les technologies contrôlées et le stockage dans le nuage

Le 5 novembre 2025, Affaires mondiales Canada a publié l’Avis aux exportateurs no 1159 (les « lignes directrices »), qui précise les situations où l’utilisation des services infonuagiques constitue une exportation de...more

Jones Day

NY Department of Financial Services Signals Increased Scrutiny of Third-Party Technology Risk Management

Jones Day on

On October 21, 2025, the New York Department of Financial Services ("NYDFS") sent a letter to the executives and information security personnel at covered entities with new guidance for managing technology and data risks...more

Orrick, Herrington & Sutcliffe LLP

SEC announces examination priorities for fiscal year 2026

On November 17, the SEC’s Division of Examinations published its 2026 examination priorities, outlining key areas of regulatory focus for the upcoming year. ...more

Sheppard Mullin Richter & Hampton LLP

The Ghost of Employees Past: The Data Breach Risks from User-Credential Management

A recent settlement with an education service provider and three states – California, Connecticut, and New York – serves as a reminder to deactivate the credentials of departed employees. The case arose following a data...more

DLA Piper

Singapore: Key Amendments to the Cybersecurity Act Now in Force

DLA Piper on

Since the enactment of Singapore’s Cybersecurity Act 2018 (Cybersecurity Act), Singapore’s digital economy has grown rapidly, and cyber threats have evolved at a remarkable pace. To address this shifting landscape, the...more

174 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide