Recent enforcement actions, audit activity, proposed rulemakings, and guidance issued by the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) highlight the agency’s focus on health data...more
1/17/2025
/ Artificial Intelligence ,
Audits ,
Compliance ,
Cyber Attacks ,
Cybersecurity ,
Data Privacy ,
Data Security ,
Enforcement Actions ,
Health Insurance Portability and Accountability Act (HIPAA) ,
OCR ,
Ransomware ,
Risk Management
On May 30, 2024, the FTC published amendments to its Health Breach Notification Rule (“HBNR” or “Rule”) in the Federal Register, memorializing the Rule’s expanded scope that now explicitly includes direct-to-consumer health...more
The HIPAA Privacy Rule has been modified by the US Department of Health and Human Services (HHS) to increase privacy protections for reproductive health care information. These changes, which will take effect in early 2026,...more
The U.S. Department of Health and Human Services (HHS) has finalized amendments to more closely align the Part 2 substance use disorder (SUD) regulations with HIPAA. These changes have the potential to streamline compliance...more
President Biden’s groundbreaking Executive Order on artificial intelligence carries significant implications for the health and life science industry. The Order tasks federal agencies, including those responsible for health...more
Responding to incidents impacting consumer health and wellness technologies, including apps, will be more complex under proposed breach notice rules by the U.S. Federal Trade Commission (“FTC”). Businesses have until August...more
The FTC continues to scrutinize the privacy practices of consumer health companies. After taking action against patient couponing and mental health companies, the FTC has now turned its attention to genetic testing....more
In the wake of the Supreme Court’s seismic decision in Dobbs v. Jackson Women’s Health Organization, the U.S. Department of Health and Human Services (HHS) has issued guidance to help patients, providers, and other health...more
The US Department of Health Human Services (HHS) is seeking public comments about the appropriate role of “recognized security practices” in enforcement of the HIPAA Security Rule. Congress, through an amendment to the HITECH...more
States continue to enact laws targeting the protection of genetic data with two important developments in California and Florida. California’s Genetic Information Privacy Act (“GIPA”), which came into effect on January 1,...more