Latest Publications

Share:

European High Court Invalidates EU-U.S. Privacy Shield but Upholds Standard Contractual Clauses with Additional Safeguards

On July 16, 2020, the Court of Justice of the European Union (CJEU) issued its anxiously-awaited judgment in the Schrems II case. The CJEU’s decision upheld the Standard Contractual Clauses (SCCs) but, somewhat surprisingly,...more

Patient Records: Part 2 Final Rule Reduces Substance Use Disorder Record Sharing Barriers

On July 15, 2020, a final rule revising the federal regulations governing the Confidentiality of Substance Use Disorder Patient Records (also known as 42 C.F.R. Part 2 or Part 2) was published. The revised rule will implement...more

State Data Breach Notification Laws (Updated)

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

COVID-19: Hospitals and Health Care Providers Included in New Guidance on the Emergency Purpose Exception to the Telephone...

The Federal Communications Commission (FCC) has issued a Declaratory Ruling providing guidance (Guidance) on the implementation of the Telephone Consumer Protection Act of 1991 (TCPA) as COVID-19 continues to necessitate...more

Covid-19: CARES Act Overhauls Federal Substance Use Disorder Privacy Law

The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) passed by the Senate on March 25, 2020 would make fundamental changes to the federal law, 42 U.S.C. § 290dd-2, implemented at 42 C.F.R. Part 2 that governs...more

Managing the Commercial Impact of the Coronavirus: Implications for Health Care

The coronavirus (provisionally named SARS-CoV-2, with its disease being named COVID-19) has now been documented in more than 100 countries and territories. Over 120,000 cases have now been documented across the globe,...more

HIPAA: Second Settlement this Year Related to Right to Access Initiative

On December 12, 2019, the Office for Civil Rights (OCR) announced its second enforcement action this year related to an individual’s right to access his/her protected health information (PHI). Korunda Medical, LLC (Korunda)...more

California Consumer Privacy Act and General Data Protection Regulation: A Guide to California Businesses

Beginning with the California Online Privacy Protection Act (CalOPPA) in 2004, California has led the U.S. in adopting laws to protect the privacy of its residents. California continued this trend by enacting the California...more

HIPAA: Failure to Report Breach Costs Hospital $2.175 Million

One health system recently learned the cost of relying too heavily on the HIPAA Breach Notification Rule’s “low probability of compromise” standard when it failed to notify all affected individuals and report the HIPAA breach...more

Proposed Changes to Part 2 Rules Ease Substance-Use Disorder Record Sharing

Recently proposed changes to the federal regulations governing the confidentiality of substance-use disorder patient records (Part 2) would all but eliminate the most significant and intractable barrier to sharing protected...more

State Data Breach Notification Laws

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

HIPAA: OCR Releases New FAQs Clarifying Disclosures Amongst Covered Entities

On June 26, 2019, the Department of Health and Human Services Office for Civil Rights (OCR) issued two new FAQs that clarify: The parameters around covered entities sharing protected health information (PHI) for a...more

NIST Proposes Enhanced Security Requirements for Certain Government Contractors

The National Institute of Standards and Technology (NIST) has announced proposed changes to NIST Special Publication (SP) 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. The...more

OCR Clarifies Direct Liability for Business Associates under HIPAA

On May 24, 2019, the Department of Health and Human Services Office for Civil Rights (OCR) issued a new fact sheet which lists the provisions of the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (HIPAA)...more

Proposed Bill Would Substantially Rewrite the California Consumer Privacy Act of 2018

...On April 4, 2019, California Assembly Member Wicks proposed sweeping changes to bill AB 1760, effectively repealing the California Consumer Privacy Act of 2018 (CCPA) and replacing it with the Privacy for All Act of 2019...more

Increased Interoperability of Health Information: Two New Proposed Rules

The U.S. Department of Health and Human Services (HHS) recently proposed two new rules designed to increase patient and provider access to health records. As stated by HHS in its press release, the proposed rules “will...more

State Data Breach Notification Laws - January 2019

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

DHHS Releases Guidance on Managing Cybersecurity Threats in the Health Care Sector

The U.S. Department of Health and Human Services (DHHS) recently released Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP). DHHS states that the purpose of the HICP is to: 1. Raise...more

State Data Breach Notification Laws

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Lessons Learned from 2017 OCR HIPAA Enforcement Actions

So far 2017 is proving to be an active year for Health Insurance Portability and Accountability Act (HIPAA) enforcement. This comes on the heels of 2016, which saw an unprecedented level of enforcement actions, with 13 total...more

The Office of the National Coordinator Releases Guidance on Recent International Ransomware Campaign

With the news of the newest international ransomware campaign that is currently affecting some organizations within the Health Care sector, it is important to not only educate staff on necessary precautions, but also be aware...more

Global Ransomware Attack: Preparation is Key

Businesses have been scrambling since Friday evening when news spread that a ransomware attack named WannaCry is compromising organizations at an alarming rate. In less than 48 hours, it has compromised more than 130,000...more

State Data Breach Notification Laws

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

State Data Breach Notification Statutes: A Year in Review and Preparing for 2017

Following on the heels of an active 2015, where eight states enacted changes to their data breach notification laws, another five states amended their statutes in 2016, adding complexity to the current “patchwork” system of...more

76 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide