News & Analysis as of

Third-Party Service Provider Risk Management

Bass, Berry & Sims PLC

From 1999 to Prime Time: OIG Revamps Medicare Advantage Guidance for Today’s—and Tomorrow’s—Evolving Market

On February 3, the U.S. Department of Health and Human Services Office of Inspector General (OIG) issued new Medicare Advantage Industry Segment-Specific Compliance Program Guidance (MA ICPG) for the MA industry and...more

Foley & Lardner LLP

Medicare Advantage: New OIG Compliance Guidance Has Implications for Providers

Foley & Lardner LLP on

On February 3, 2026, the U.S. Department of Health & Human Services, Office of Inspector General (OIG), published the long-awaited Medicare Advantage Industry Segment-Specific Compliance Program Guidance (Medicare Advantage...more

Latham & Watkins LLP

UK Parliamentary Committee Publishes Report on AI in Financial Services

Latham & Watkins LLP on

The Committee believes that the financial services regulators are not doing enough to manage the risks presented by AI....more

The Volkov Law Group

Episode 390 — AI Risks: A Focused and Realistic Approach

The Volkov Law Group on

The compliance industry appears to be taken over by AI-this and AI-that. Third party risk bleeds into major AI risks, corporate governance needs to incorporate AI risks, and policies and procedures have to incorporate AI...more

WaterStreet Company

5 Considerations for Outsourcing Print & Mail Operations in P&C Insurance

WaterStreet Company on

Property and casualty insurers manage high volumes of regulated, document-driven communications, including policies, endorsements, billing statements, and legally required notices, that must be produced and delivered...more

Bond Schoeneck & King PLLC

Countdown to Data Privacy Day 2026 - Protect Your Business – Cybersecurity Provisions in Contracts

Cybersecurity and data privacy provisions should be a central consideration whenever parties negotiate contracts involving third‑party service providers who will access or process business data. This applies across a broad...more

Blake, Cassels & Graydon LLP

What Can Service Providers to the Public Sector Learn From the PowerSchool Privacy Incident?

On November 17, 2025, Ontario’s Information and Privacy Commissioner (ON IPC) and Alberta’s Office of the Information and Privacy Commissioner (AB OIPC) each released their findings from their investigations into a...more

A&O Shearman

Managing cyber risk under escalating threat and enforcement pressure

A&O Shearman on

Cyber law and practice have continued to evolve over the past 12 months. New laws and regulations have been unveiled or come into force, while enforcement authorities have sharpened their focus on issues including board...more

The Volkov Law Group

Reviewing the 5 Major AI Risks (Part II of II)

The Volkov Law Group on

Here are the five primary risk areas when a company uses AI in a supportive or assistance-based role as opposed to an algorithmic-based use case....more

The Volkov Law Group

Soothing the AI-Risk Hysteria: A Focused Approach to AI Risks (Part I of II)

The Volkov Law Group on

From my perspective, hopefully a reasonable one, there is a little too much AI-Risk Hype. Not to belittle the experts or ignore potential risk concerns but this is getting a little carried away....more

Freeman Mathis & Gary

A first look at NIST’s new cyber AI framework

Freeman Mathis & Gary on

The National Institute of Standards and Technology (NIST) recently released their initial preliminary draft of NIST IR 8596, also known as the Cybersecurity Framework Profile for Artificial Intelligence. This new...more

Wiley Rein LLP

FedRAMP Issues Final Proposed Changes to Cloud Authorization Process, Seeks Comments from Industry

Wiley Rein LLP on

WHAT: The FedRAMP Program Management Office (PMO) has released a “final set” of proposed changes to the FedRAMP process for authorizing and assessing the security of cloud services for federal consumption. The final proposed...more

Morgan Lewis - Tech & Sourcing

Navigating Cloud Computing Contracts: Essential Capacity Considerations

As demand for data-intensive and AI-driven workloads continues to grow, customers are increasingly encountering constraints on cloud compute resources—particularly specialized processors and region-specific capacity. These...more

Morgan Lewis - Data Center Bytes

Contracting for Cloud Computing Capacity: Key Concerns for Customers

Cloud computing has been sold as elastic, on-demand access to virtually unlimited resources. However, the rapid growth of data-intensive and artificial intelligence–driven workloads has strained the availability of certain...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Loeb & Loeb LLP

60 Seconds on Tech & Sourcing: Unlocking the BPaaS Advantage—Key Considerations for Successful Deals

Loeb & Loeb LLP on

While often described as a hybrid of Software‑as‑a‑Service (SaaS) and Business Process Outsourcing (BPO), Business-Process-as-a-Service (BPaaS) is far more than the sum of its parts. It represents a strategic shift toward...more

Parker Poe Adams & Bernstein LLP

New Industry Letter Provides Guidance for Companies Using Third-Party Service Providers

As organizations increasingly rely on third-party service providers (TPSPs) for critical services, including cloud computing, IT management, and fintech solutions, the scale and complexity of cyber risks have grown. A recent...more

Ropes & Gray LLP

NYDFS Regulated Entities Face Stronger Cybersecurity Regulations

Ropes & Gray LLP on

The New York Department of Financial Services (“NYDFS”) implemented the final phases of amendments to its NYDFS Cybersecurity Regulation (23 NYCRR Part 500) in May and November....more

Orrick, Herrington & Sutcliffe LLP

NCUA publishes list of federal resources for credit unions using AI

Recently, the NCUA published a list of resources aimed toward guiding credit unions implementing AI or partnering with AI third-party vendors. The publication noted that while AI presented significant opportunities for...more

Jackson Lewis P.C.

The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party...

Jackson Lewis P.C. on

As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and...more

Troutman Pepper Locke

Legal AI in Practice: Firm Governance, Build vs. Buy Decisions, and Vendor Due Diligence — The Good Bot Podcast

Troutman Pepper Locke on

In this episode of The Good Bot, Brett Mason sits down with Leigh Zeiser, director of AI and automation at Troutman Pepper Locke, to unpack how the firm operationalizes AI responsibly. They discuss the firm's AI portfolio —...more

Venable LLP

Practical Tips for Reviewing AI Service and AI related "Software as a Service" (SaaS) Agreements in 2026

Venable LLP on

Artificial intelligence has quickly shifted from an innovative experiment to a core operational tool across industries. As business teams explore new AI service providers—ranging from automated analytics engines to...more

Wiley Rein LLP

Updates to NIST Cybersecurity Guidance Show Continued Focus on Cloud Services

Wiley Rein LLP on

Recent draft cybersecurity guidance from the National Institute of Standards and Technology (NIST) provides an opportunity for government contractors who provide IT services to federal agencies to weigh in on implementation...more

Cooley LLP

The Most Common AI “Risk Factor” Categories

Cooley LLP on

With the news that over 70% of S&P 500 companies provide some sort of AI-related risk factors in their SEC disclosures, it’s a good time to review the type of risk factors that you might want to consider – of course,...more

Pillsbury Winthrop Shaw Pittman LLP

Lessons from a Major Software Sunsetting: Contractual and Post-Contractual Best Practices

Proactive planning and governance from both clients and vendors are essential to manage software sunsetting effectively....more

262 Results
 / 
View per page
Page: of 11

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide