In 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act, imposed direct liability on business associates for certain violations of the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (the “HIPAA Rules”). The resulting 2013 HHS Office for
Data Security & Privacy
The Data Security & Privacy blog published by Phillips Lytle LLP focuses on legal developments and compliance issues related to data protection, privacy laws, and cybersecurity. It covers topics such as state and international privacy statutes, including the GDPR and emerging U.S. state laws, cross-border data transfer regulations, and enforcement actions. The blog also addresses privacy concerns in specific industries like online gaming and healthcare, as well as legislative proposals such as Canada's Digital Charter Implementation Act. It provides analysis of regulatory decisions impacting data analytics tools and guidance on managing privacy risks and compliance obligations for businesses operating domestically and internationally.
Latest from Data Security & Privacy - Page 2
Recent Developments in Consumer Privacy Legislation and Cybersecurity Practices
As regulators attempt to keep pace with the ever-changing technological landscape, legislation and agency guidance continue to evolve. Two recent developments worth noting:
…
Encryption Considerations under Data Breach Notification Laws
All 50 states have enacted their own version of a data breach notification statute requiring notice to affected individuals and/or regulatory bodies in the event of data loss, unauthorized data access or data exfiltration of personally identifiable information (“PII”). Many…
Cyber Risk: Addressing the Elephant in the Room
One of the biggest risks to data security is lack of vendor (third-party) and vendor subcontractor (fourth-party) management. Companies can mitigate ever-increasing vendor data security risk through purchasing appropriate cyber insurance and implementing a vendor risk management program that includes…
Be Prepared for the September 3, 2018 Deadline for New York State Department of Financial Services Cybersecurity Regulation Requirements
The New York State Department of Financial Services (“DFS”) Cybersecurity Regulation (“Regulation”) took effect on March 1, 2017, and applies to those entities operating or required to operate under New York banking, insurance and finance laws (“Covered Entities”). Covered Entities…
SEC’s Yahoo Enforcement Action and Settlement Provides Further Direction for Companies Following the SEC’s 2018 Cybersecurity Guidance
The SEC’s recent enforcement action and settlement with Altaba (formerly known as Yahoo) over the company’s major data breach provides a suggested roadmap for how companies may want to proactively approach data breach issues. Some major takeaways are: (1) companies…
Now That All U.S. States Have Data Breach Laws, National Breach Reporting Is Even More Complex
With Alabama’s recent enactment of the Alabama Data Breach Notification Act of 2018 (“Act”), all 50 states now have their own data breach reporting statutes. Given the complexity of the current U.S. data breach reporting regime, which also includes statutory…
GDPR – It’s Not Too Late to Work Towards Compliance
Everyone has been to a lot of presentations, read articles and evaluated the General Data Privacy Regulation (“GDPR”) – yet many questions remain.
Many companies continue to struggle with determining whether (1) the GDPR applies to them and, if so,…
Protecting Your Business: The Significance of Record Management and Retention Policies
Both large and small companies can be overwhelmed by the volume of records that they create both in paper and electronic formats. What does your company do with this mountain of paper and electronic records? How long should your company…
DFS Answers New FAQs Regarding Filing Procedures Under DFS Cybersecurity Regulation
The New York Department of Financial Services (“DFS”) recently issued two additional answers to frequently asked questions related to filing procedures required by the DFS Cybersecurity Regulation (“Regulation”). The new FAQs come in the wake of the Regulation’s first annual…