News & Analysis as of

Regulatory Requirements Enforcement Actions Data Privacy

Arnall Golden Gregory LLP

OIG Audit Finds Cybersecurity Gaps at Large Northeastern Hospital

On July 11, 2025, the U.S. Department of Health and Human Services (“HHS”), Office of Inspector General (“OIG”) posted a report that announced the findings of a cybersecurity audit it conducted of a large Northeastern...more

Loeb & Loeb LLP

NY Delays Algorithmic Pricing Disclosure Enforcement as Lawsuit Proceeds

Loeb & Loeb LLP on

Last week, on July 14, 2025, a New York federal court issued a general stay of enforcement of the NY Algorithmic Pricing Disclosure Act, which went into effect just days earlier, on July 8, 2025. As a result, businesses...more

Sheppard Mullin Richter & Hampton LLP

China Initiates Mandatory Reporting Regime for Personal Information Protection Officers

On July 18, 2025, the Cyberspace Administration of China (the “CAC”) issued the Notice on Launching the Reporting Mechanism for Personal Information Protection Officers (the “Notice ”). This development marks a significant...more

Greenbaum, Rowe, Smith & Davis LLP

Navigating New Jersey’s Medical Spa Regulatory Landscape: Key Compliance and Risk Management Considerations

The medical spa industry is thriving, but with growth comes complexity, particularly in New Jersey where healthcare and professional licensing rules intersect with business and real-estate regulations. For physicians, nurses,...more

Paul Hastings LLP

ICO Annual Report Provides Insight Into Data Protection Risks for Businesses

Paul Hastings LLP on

The UK Information Commissioner’s Office’s (the ICO’s) latest Annual Report summarises its accomplishments and priorities, including last year’s enforcement actions. Based on our review of the report, we see the ICO focusing,...more

Mintz - Privacy & Cybersecurity Viewpoints

No More Warnings: Ignoring AG Costs $85,000

Connecticut Attorney General William Tong recently announced the state’s first-ever enforcement settlement under the Connecticut Data Privacy Act (CTDPA) with TicketNetwork, Inc., an online ticket marketplace. The settlement...more

Skadden, Arps, Slate, Meagher & Flom LLP

SkadBytes Podcast | Tech’s Shifting Landscape: Five Trends Shaping the Conversation

Introducing “SkadBytes,” our newest podcast where Skadden’s IP and Tech team discusses pivotal changes driving tech regulation and innovation. Host Deborah Kirk and colleagues Alistair Ho and Jonathan Stephenson reflect on...more

Wiley Rein LLP

Wiley Consumer Protection Download (July 15, 2025)

Wiley Rein LLP on

FTC Sends Warning Letters Regarding Potential Noncompliance With “Made in USA” Requirements. On July 8, the FTC sent letters to a flagpole retailer, footwear maker, football equipment company, and personal care products...more

Kelley Drye & Warren LLP

Connecticut AG Announces First Settlement Under the Connecticut Data Privacy Act

On July 8, Connecticut Attorney General William Tong announced a settlement with TicketNetwork, Inc. for alleged violations of the Connecticut Data Privacy Act (CTDPA). The settlement is the first publicly announced...more

McDonnell Boehnen Hulbert & Berghoff LLP

AI News Roundup – Impostor uses AI to imitate U.S. Secretary of State, EU unveils code of practice for AI regulations, AI-powered...

To help you stay on top of the latest news, our AI practice group has compiled a roundup of the developments we are following....more

Morgan Lewis

AI in Healthcare: Opportunities, Enforcement Risks and False Claims, and the Need for AI-Specific Compliance

Morgan Lewis on

The risks associated with the growth of AI in the healthcare and life sciences industries, as well as recent federal and state activity and enforcement actions, emphasize the importance of understanding and implementing a...more

Ropes & Gray LLP

U.S. District Court Ruling Vacates HIPAA Final Rule that Strengthened Privacy Protections for Reproductive Health Information

Ropes & Gray LLP on

On June 18, 2025, the United States District Court for the Northern District of Texas Amarillo Division issued an opinion, Purl v. Department of Health and Human Services, declaring the U.S. Department of Health and Human...more

McCarter & English, LLP

Connecticut Data Privacy Act: Statutory Changes and the Start of Fines

Connecticut continues to refine its data privacy act as it implements its first violation settlement. TicketNetwork, Inc., reached a settlement of $85,000 for deficiencies in its privacy notice to consumers. Despite receiving...more

Orrick, Herrington & Sutcliffe LLP

DOJ begins enforcement of its Data Security Program

On July 8, the DOJ’s National Security Division (NSD) will begin enforcing its Data Security Program according to a notice from April titled “Data Security Program Implementation and Enforcement Policy” which outlined the...more

Womble Bond Dickinson

The ICO’s Penalty Against 23andMe Brings New Emphasis on Cybersecurity Risks - Key Takeaways for U.S. Companies

Womble Bond Dickinson on

The dramatic increase in global reach that the internet provides U.S.-based companies comes as a double edge sword. While it significantly increases a company’s potential customer pool, it also subjects companies to...more

Morgan Lewis

DOJ's Data Security Program Enforcement in Full Swing: Key Considerations for Companies

Morgan Lewis on

The US Department of Justice’s (DOJ’s) final rule implementing Executive Order (EO) 14117, Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern went...more

Bodman

DOJ Data Security Program – Another Privacy and Security Law that Impacts the Health Care Industry

Bodman on

The Department of Justice (“DOJ”) implemented the Data Security Program (“DSP”) intending to prevent access to Americans’ bulk sensitive personal data and government-related data by Countries of Concern. The DSP is aimed at...more

Wiley Rein LLP

Update: Enforcement of DOJ Data Security Program Set to Begin July 9

Wiley Rein LLP on

The U.S. Department of Justice (DOJ) is set to enforce its sweeping new rule on certain U.S. data transactions with countries of concern and covered persons as of July 9, 2025. The new rule regarding “Preventing Access to...more

Orrick, Herrington & Sutcliffe LLP

5 Things In-House Counsel Must Know Before DOJ’s Bulk Transfer Rule Enforcement Begins

The Department of Justice’s (DOJ) 90-day grace period for compliance with the Data Security Program (DSP) ends on July 8, 2025, and enforcement is expected to begin. This regulatory regime was created for national security...more

Troutman Pepper Locke

Mass. AG Emerges as Key Player in Consumer Protection

Troutman Pepper Locke on

Massachusetts Attorney General Andrea Campbell has emerged as a significant figure in the landscape of consumer protection and corporate accountability. Her actions and initiatives have positioned her as a thought leader...more

Alston & Bird

UK Data Protection Regulator Fines 23andMe ~$3.1 Million Following Credential Stuffing Attack

Alston & Bird on

On June 5, 2025, the UK’s Information Commissioner’s Office (ICO) fined 23andMe £2.31 million (~$3.1 million). The fine was for failing to implement adequate security measures to protect the personal data of over 155,000 UK...more

DLA Piper

Spain: Spanish Data Protection Authority Publishes Annual Report

DLA Piper on

The Spanish Data Protection Authority (“AEPD“) has published its 2024 annual report, which includes the AEPD’s awareness-raising activities; the collaboration and inspection activities of the Spanish authorities; relevant...more

Orrick, Herrington & Sutcliffe LLP

RegFi Episode 63: DOJ Issues Final Rule on International Data Transfers

Orrick Partners Matthew Coleman and Jeanine McGuinness join RegFi co-hosts Jerry Buckley and Sherry Safchuk to explore the implications of the Justice Department’s recent issuance of a final rule prohibiting and restricting...more

HaystackID

Operating in Flux: Doing Business Under Europe’s Intensifying Regulatory Environment

HaystackID on

Editor’s Note: Europe’s regulatory landscape has undergone a fundamental transformation, extending far beyond GDPR’s foundational framework to encompass a complex ecosystem of interconnected laws governing digital platforms,...more

Clark Hill PLC

Beyond HIPAA: How state laws are reshaping health data compliance

Clark Hill PLC on

We are in an era where smartphones track sleep patterns, fitness apps monitor heart rates, and online searches reveal sensitive medical inquiries. As a result, the notion of “health data” has expanded dramatically. This...more

221 Results
 / 
View per page
Page: of 9

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide