Latest Publications

Share:

AI-Powered Text Messaging by Digital Health Companies: Supreme Court Raises the Stakes

Share on Twitter Share by Email Share Back to top Digital health companies increasingly rely on AI-powered messaging platforms, chatbots, and virtual assistants to engage patients through text and voice. However, a June 2025...more

AI Contracts in Health Care: Avoiding the Data Dumpster Fire

For AI companies in the health care space, data is everything. It fuels model performance, drives product differentiation, and can make or break scalability. Yet too often, data rights are vaguely defined or completely...more

HIPAA Risk Analyses for Digital Health: Navigating AI, M&A and Vendor Diligence

Share on Twitter Share by Email Share Back to top HIPAA Security Risk Analyses (SRAs) should be the foundation of every digital health company’s cybersecurity compliance. Far more than a checkbox exercise, a comprehensive SRA...more

HIPAA Compliance Risks with AI Scribes in Health Care: What Digital Health Leaders Need to Know

AI scribes are quickly becoming the digital sidekick of modern health care. They promise to reduce clinician burnout, streamline documentation, and improve the patient experience. But as health care providers and digital...more

State Data Breach Notification Laws - June 2025

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

The Intersection of AI, Digital Health, and the TCPA: What You Need to Know

Artificial intelligence (AI) is widely transforming digital health, including by automating certain patient communications. However, as health care companies consider deploying AI-driven chatbots, texting platforms, and...more

HIPAA Compliance for AI in Digital Health: What Privacy Officers Need to Know

Artificial intelligence (AI) is rapidly reshaping the digital health sector, driving advances in patient engagement, diagnostics, and operational efficiency. However, for Privacy Officers, AI’s integration into digital health...more

Key Takeaways: 7th Annual “Let’s Talk Compliance” Conference

Editor’s Note: PYA and Foley & Lardner hosted the 7th Annual “Let’s Talk Compliance” two-day virtual conference on January 23 and 24, 2025. Panelists included Foley attorneys and PYA subject matter experts. The event was...more

New York’s Proposed Health Information Privacy Act Takes Aim at Digital Health Companies

The New York Health Information Privacy Act (NYHIPA), if enacted, could create a chilling effect on patient access and engagement to readily available digital health care services relied upon by New Yorkers. Digital health...more

HHS Proposes Changes to Strengthen HIPAA Security Rule

Material updates to the HIPAA Security Rule could be on the way — affecting all HIPAA-regulated entities — for the first time in two decades. The Department of Health and Human Services (HHS) issued a Notice of Proposed...more

HIPAA Reproductive Health Care Amendments: Compliance in an Uncertain Enforcement Landscape

The amendments to the HIPAA Privacy Rule designed to protect reproductive health care information (Amendments) are under legal challenge as the compliance date quickly approaches. As discussed in more detail in our...more

OCR Says HIPAA Audits Will Resume: OIG Makes Recommendations for Enhancement

Recognizing the increasing number of successful cyberattacks targeting health care organizations and their valuable patient data, the Office of the Inspector General (OIG) is calling for enhancements to the HIPAA audit...more

State Data Breach Notification Laws - November 2024

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

U.S. State Comprehensive Consumer Data Privacy Law Comparison

Since the passage of the California Consumer Privacy Act (CCPA) in 2018, other U.S. states have followed suit by enacting comprehensive consumer data privacy laws in rapid succession. While these state consumer privacy laws...more

HIPAA: Amendments to Protect Reproductive Health Care Information Can Now be Implemented with OCR’s Final Rule

Share on Twitter Print Share by Email Share Back to top HIPAA regulated entities may now begin implementing the amendments to the HIPAA Privacy Rule to provide additional protections for reproductive health care information...more

Vermont Governor Vetoes Data Privacy Act

Following the Vermont Senate’s failure to override Governor Phil Scott’s veto of the Vermont Data Privacy Act (VDPA), the much-discussed bill will not be enacted into law – at least in its current form. As passed by the...more

HHS Updates Pixels and Trackers Guidance for HIPAA Regulated Entities

Pixels, cookies, and trackers continue to be front of mind for HIPAA regulated entities seeking clarity on their ability to advertise, market, and engage with existing and prospective patients. On March 18, 2024, the U.S....more

NIST Publishes Final “Cybersecurity Resource Guide” on Implementing the HIPAA Security Rule

In an important development for HIPAA-regulated entities looking for practical assistance in understanding, implementing, and enhancing compliance with the HIPAA Security Rule, the National Institute of Standards and...more

“Let’s Talk Compliance”: Health Care Privacy and Cybersecurity

Editor’s Note: PYA and Foley & Lardner hosted the 6th Annual “Let’s Talk Compliance” two-day Virtual Conference on January 18 and 19, 2024. Panelists included Foley & Lardner attorneys and PYA experts. The event was hosted by...more

HIPAA and Part 2 Harmonized: What Health Care Organizations Need to Know

Substance Use Disorder (SUD) programs and HIPAA-regulated entities seeking to streamline their privacy and security practices and workflows received welcome news from the U.S. Department of Health & Human Services (HHS) last...more

New Jersey Passes Comprehensive Privacy Law to Lead the 2024 Wave of State Privacy Laws

On January 16, 2024, New Jersey Governor Phil Murphy signed Senate Bill (SB) 332, establishing New Jersey’s consumer data privacy law, the New Jersey Data Privacy Act (NJDPA) which will be effective January 15, 2025. This...more

Wisconsin State Assembly Fast Tracks Wisconsin Data Privacy Act

On November 14, 2023, the Wisconsin State Assembly passed Assembly Bill 466, otherwise known as the Wisconsin Data Privacy Act (WDPA). The bill passed on its third reading and was immediately ordered to the Wisconsin State...more

Telehealth Providers: HHS Issues HIPAA Best Practices

Recognizing the evolving landscape of care delivery and growth of telehealth, the U.S. Department of Health and Human Services (HHS) published a resource guide aimed at assisting telehealth providers in explaining the privacy...more

California Expands Data Deletion Rights Against Data Brokers

On October 10, 2023, California Governor Gavin Newsom signed into law SB-362, a measure amending existing California laws regulating data brokers and granting California residents the right to delete all personal information...more

State Data Breach Notification Laws - September 2023

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

76 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide