Latest Posts › Popular

Share:

White House Releases America’s AI Action Plan: A Strategic Framework for Innovation, Infrastructure, and Global AI Leadership

On July 23, 2025, the White House released America’s AI Action Plan, a comprehensive national strategy designed to strengthen the United States’ position in artificial intelligence through investment in innovation,...more

Exploring California’s Proposed AI Bill

California lawmakers have proposed new legislation to reshape the growing use of artificial intelligence (AI) in the workplace. While this bill aims to protect workers, employers have expressed concerns about how it might...more

Tips for Vacation Rental, Property Mgmt. Businesses Facing Vendor Cybersecurity Risk

No organization can eliminate data breach risks altogether, regardless of industry, size, or even if the organization has taken significant steps to safeguard their systems and train employees to avoid phishing attacks....more

California Establishes AI Transparency Act

According to the California legislature, audio recordings, video recordings, and still images can be compelling evidence of the truth. However, the proliferation of Artificial Intelligence (AI), specifically, generative AI,...more

Exploring AI Risks Reported in SEC Filings Can Be Helpful For Many Organizations, Including SMBs

One of our recent posts discussed the uptick in AI risks reported in SEC filings, as analyzed by Arize AI. There, we highlighted the importance of strong governance for mitigating some of these risks, but we didn’t address...more

Nebraska Adds to the List of States That Have Enacted a Comprehensive Consumer Data Privacy Law

On April 17, 2024, Nebraska’s governor signed Legislative Bill 1074, which establishes a consumer data privacy law for the state. Nebraska’s law takes effect January 1, 2025. To Whom does the law apply? The law applies to...more

Top 10 for 2024 – Happy Data Privacy Day!

To celebrate Data Privacy Day (January 28), we present our top ten data privacy and cybersecurity predictions for 2024. 1. AI regulations to protect data privacy. Automated decision-making tools, smart cameras, wearables,...more

AI, Phishing Attacks, Healthcare, and a $480,000 OCR Settlement under HIPAA

Phishing has long been a favorite tactic for threat actors (hackers) to commence a cyberattack. The rapid expansion of more adaptable and available artificial intelligence (AI) technologies, such as natural language...more

Corporate Boards Mulling Effects of SEC Cyber Enforcement and CISO Exposure, and Possibly Hacker Complaints to SEC

According to a New York Times story this weekend, the Security Exchange Commission’s lawsuit against SolarWinds is driving discussions in boardrooms and corporate security departments of large organizations about the handling...more

Sanction Policies Can Help Drive Cybersecurity and HIPAA Compliance, OCR Says

Many HIPAA covered entities and business associates struggle with developing and implementing a sanctions policy. What should it say, is zero-tolerance required, do we have to impose discipline in every case, etc. These are...more

Insights From The IBM 2023 Cost of a Data Breach Report

The annual Cost of a Data Breach Report (Report) published by IBM is reliably full of helpful cybersecurity data. This year is no different. After reviewing the Report, we pulled out some interesting data points. Of course,...more

Top Ten for 2023 – Happy Data Privacy Day!

To celebrate Data Privacy Day, we present our top ten data privacy and cybersecurity predictions for 2023. 1. Healthcare and Medical Data Security and Tracking- The healthcare industry has been facing increased scrutiny...more

Getting Healthcare in 2023 and Beyond…Virtually…and Securely

Much is being written about “remote work” – is it productive, will demand for it continue or be curtailed in a recession, is cybersecurity compromised, does it inhibit workplace culture, collaboration, etc. Lots of questions,...more

2023 New Year’s Resolution: Don’t Get “Whacked” By A State AG for Cybersecurity Compliance

It usually happens after a reported data breach. The organization experiencing the breach sends notifications to affected individuals, as well as federal and or state agencies where appropriate and perhaps other parties. Not...more

Nevada Gaming Commission Adopts Cybersecurity Regulations

On December 22, 2022, the Nevada Gaming Commission (NGC) adopted regulations creating new cybersecurity requirements for certain gaming operators. This action joins agencies in other jurisdictions moving quickly to protect...more

OCR Reminds Healthcare Providers and Their Business Associates – You Need an Incident Response Plan!

We have been quite busy this October, which happens to be National Cybersecurity Awareness Month. But, we did not want to let the month go by without some recognition; and we are grateful to the HHS Office for Civil Rights...more

New York State Bar Adds Cybersecurity, Privacy, and Data Protection as New CLE Category

On August 17, 2022, New York announced an amendment to the Continuing Legal Education (CLE) Program Rules, which adds a requirement for attorneys to complete at least one CLE credit hour in Cybersecurity, Privacy, and Data...more

North Carolina Prohibits Public Sector Entities from Paying Ransom in a Ransomware Cyberattack

Organizations attacked with ransomware have a bevy of decisions to make, very quickly! One of those decisions is whether to pay the ransom. Earlier this year, I had the honor of contributing to a two-part series, entitled...more

Construction Industry: Data Security Considerations

No industry is immune to privacy and cybersecurity risks, and the construction industry is no exception. Those in the construction industry can protect against a potential cyberattack by understanding the risks and...more

Is Crypto Too Cryptic for Your 401(k) Plan?

It started sometime last year and, in hindsight, was inevitable. Clients with 401(k) plans and a crypto-savvy employee population began asking whether they could offer cryptocurrency as a plan investment option. In the...more

Cyber Incident, Ransom Payment Reporting to DHS Mandatory for Critical Infrastructure Entities

Included within the Consolidated Appropriations Act, 2022, signed by President Joe Biden on March 15, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Act) creates new data breach reporting requirements....more

Massachusetts Privacy Bill Provides WISP Reminder, Safe Harbor for Punitive Damages

When Massachusetts issued its data security regulations in 2009 (Regulations), it led the way for states on data security. The Regulations became effective 12 years ago, almost to the day, March 1, 2010. The Bay State is now...more

SEC to Advisors and Funds – Adopt and Implement Cybersecurity Policies and Procedures

On February 9, the Securities and Exchange Commission (“SEC”) voted to propose rule 206(4)-9 under the Advisers Act and 38a-2 under the Investment Company Act (collectively, “Proposed Rule”). In general, the Proposed Rule...more

98 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide