Latest Publications

Share:

White House Issues Open Letter to Private Businesses Regarding the Threat of Ransomware

On June 2, 2021, Anne Neuberger, Deputy Assistant to the President and Deputy National Security Advisor for Cyber and Emerging Technology, published a rare open letter to the corporate executives and business leaders of...more

European Commission Approves New Standard Contractual Clauses for Transfer of European Personal Data

Earlier today, the European Commission approved and adopted a new version of the Standard Contractual Clauses (SCCs) that revises how data may be transferred by including additional privacy and legal safeguards. The remodeled...more

President Biden Issues Executive Order to Strengthen U.S. Cybersecurity Practices

On May 12, 2021, President Biden issued an Executive Order on Improving the Nation’s Cybersecurity following a series of highly publicized cybersecurity incidents during the first four months of his presidency, including the...more

[Webinar] Data Privacy Management in 2021: Navigating Compliance in an Ever-Changing Environment - February 17th, 11:00 am - 11:45...

Participate in a thoughtful discussion with a panel of privacy experts, and moderated by Epiq, on the challenges, learnings, and best practices to handle privacy and compliance. We would like to personally invite you to...more

Appeals Court Vacates HIPAA Penalty Imposed Against M.D. Anderson

On January 14, 2021, the U.S. Court of Appeals for the Fifth Circuit vacated the civil monetary penalty (CMP) imposed by the Department of Health and Human Services (HHS) against the University of Texas M.D. Anderson Cancer...more

OCR Relaxes Enforcement on Providers Using Scheduling Apps for COVID-19 Vaccinations

On January 19, 2021, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Enforcement Discretion (Notice) announcing that it will not impose penalties for...more

Key Findings & Takeaways from OCR HIPAA Audit Findings

The Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services recently published its findings from audits conducted in 2016 and 2017 of covered entities’ and business associates’ compliance with...more

Proposed Modifications to HIPAA Expands Individual Access Rights and Encourages Further Sharing of PHI for Care Coordination

On December 10, 2020, the Department of Health and Human Services, Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) to revise the HIPAA Privacy Rule. The proposed revisions to the Privacy Rule seek...more

HIPAA Right of Access Initiative: 2020 Year in Review

In 2020, the Office for Civil Rights (OCR) kept the promise it made the prior year to “vigorously enforce” the rights of patients to access and exercise control over their medical records. OCR has settled ten “right of...more

European Commission Publishes Draft Standard Contractual Clauses

On November 12, 2020, the European Commission (“EC”) published a draft implementing decision on standard contractual clauses (“SCCs”) for the transfer of personal data to third countries pursuant to the General Data...more

European Data Protection Board Issues Recommendations for Exports of Personal Data From the European Economic Area

As many organizations continue to struggle with the fallout from the July 2020 Schrems II decision from the European Court of Justice (“CJEU”), in November, the European Data Protection Board (“EDPB”) published two pieces of...more

Practical Guidance In-House Counsel Should Follow & Share with IT Staff Handling Data Breaches

On August 20, 2020, Uber’s former Chief Security Officer, Joe Sullivan, was charged by the U.S. Department of Justice (DOJ) with obstruction of justice and concealing a felony for allegedly trying to cover up a 2016...more

Department of Defense Formally Implements Cybersecurity Maturity Model Certification Requirements for Department of Defense...

On November 30, 2020, the U.S. Department of Defense (“DoD”) will begin to roll out the new Cybersecurity Maturity Model Certification (“CMMC”) framework that eventually will require all DoD contractors, subcontractors, and...more

New Cybersecurity Assessment Requirement for Department of Defense Contractors Effective November 30, 2020

As of November 30, 2020, certain U.S. Department of Defense (“DoD”) prime contractors and subcontractors will need to complete a cybersecurity self-assessment prior to receiving new DoD contracts and prior to the exercise of...more

State Data Breach Notification Laws - September 2020

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

European High Court Invalidates EU-U.S. Privacy Shield but Upholds Standard Contractual Clauses with Additional Safeguards

On July 16, 2020, the Court of Justice of the European Union (CJEU) issued its anxiously-awaited judgment in the Schrems II case. The CJEU’s decision upheld the Standard Contractual Clauses (SCCs) but, somewhat surprisingly,...more

State Data Breach Notification Laws (Updated)

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

COVID-19: Privacy and Cybersecurity Regulatory and Enforcement Guidance (Updated)

On March 19, 2020, the European Data Protection Board (EDPB) adopted a statement on the processing of personal data in the context of the COVID-19 outbreak. The EDPB made it clear that while the EU’s General Data Protection...more

COVID-19: Privacy and Cybersecurity Regulatory and Enforcement Guidance

As industry continues to adapt to the evolving realities of shelter-in-place orders, companies face challenges in supporting an unprecedented remote workforce while balancing compliance with a variety of regulatory agencies....more

Defending Against Phishing and Other Rising Cybersecurity Threats as Attackers Exploit Coronavirus Vulnerabilities

As the coronavirus (also known as COVID-19) continues to impact all organizations globally and create uncertainty, cyber criminals are looking to exploit these vulnerabilities and fears and pose heightened cybersecurity...more

Managing the Commercial Impact of the Coronavirus: Implications for Health Care

The coronavirus (provisionally named SARS-CoV-2, with its disease being named COVID-19) has now been documented in more than 100 countries and territories. Over 120,000 cases have now been documented across the globe,...more

California Consumer Privacy Act and General Data Protection Regulation: A Guide to California Businesses

Beginning with the California Online Privacy Protection Act (CalOPPA) in 2004, California has led the U.S. in adopting laws to protect the privacy of its residents. California continued this trend by enacting the California...more

ISO/IEC 27701 Released as a New Standard for Privacy Compliance

On August 6, 2019, the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) released ISO/IEC 27701 (ISO 27701), a privacy extension to ISO/IEC 27001 and ISO/IEC 27002...more

State Data Breach Notification Laws

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

69 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide