On August 3, 2018, the Governor in Ohio signed into law the Data Protection Act, which provides businesses with an affirmative defense to data breach claims if the business was in compliance with reasonable security measures at the time
Privacy and Cybersecurity Perspectives
Insights into privacy and cybersecurity developments in business and healthcare
Privacy and Cybersecurity Perspectives, published by Murtha Cullina LLP, focuses on legal developments and regulatory issues related to data privacy, cybersecurity threats, and compliance obligations. The blog covers topics such as consumer privacy laws including the California Privacy Rights Act, HIPAA compliance and enforcement actions, cybersecurity risks facing healthcare and other industries, and best practices for managing remote workforce security. It also addresses government enforcement trends, risk analysis requirements, and the impact of evolving privacy regulations on businesses. The content is aimed at helping organizations navigate complex privacy and cybersecurity legal frameworks and implement effective compliance strategies.
Latest from Privacy and Cybersecurity Perspectives - Page 4
Denmark Implements Email Encryption Requirement, What Countries Will Follow?
On July 23, 2018, Denmark’s data protection agency announced that companies must encrypt all emails transmitting sensitive personal data. This new rule goes into effect January 1, 2019, giving companies that do business in or with Denmark approximately five months…
Data Breach Costs Up; Planning and Swift Response Save Money
The much-anticipated Ponemon Institute 2018 Cost of Data Breach Study: Global Overview is out and, not surprisingly, the cost of a data breach continues to rise. In this country, the cost is up $8 per record, going from $225 per record…
EU Commission Recommends Suspension of Privacy Shield; Recent FTC Efforts May Be Too Little Too Late
On July 5, 2018, the EU Parliament passed a non-binding resolution encouraging the European Commission to suspend the EU-US Privacy Shield Program unless the US is fully compliant by September 1, 2018. The EU Parliament believes that the current Privacy…
California Gets Its Very Own GDPR with Statutory Damages
You could almost hear the cheers of plaintiffs’ class action lawyers in California last night, as California’s governor signed the most sweeping privacy law this country has seen to date. Notably, the law gives consumers the right to statutory damages…
SCOTUS Requires Warrant for Cell Phone Location Records
Today, in a 5-4 decision, the US Supreme Court ruled that the government’s acquisition of information regarding an individual’s location based on a cell phone record amounts to a Fourth Amendment search and generally requires a warrant. In Carpenter v.…
ALJ Judge Upholds OCR’s $4,348,000 Data Breach Penalty on Texas Hospital
HIPAA has teeth. On June 1, 2018, an Administrative Law Judge (ALJ) ruled that the University of Texas MD Anderson Cancer Center violated HIPAA. In doing so, the ALJ granted the Office of Civil Rights (OCR) summary judgment, requiring the…
District Court Gives Narrow, Reasonable Scope to TCPA
In March of this year, we told you that the D.C. Circuit Court of Appeals issued a decision in ACA Int’l. v. FCC, wherein the court set aside two FCC interpretations of the Telephone Consumer Protection Act, or TCPA.…
OCR Issues Guidance on the Use of HIPAA Authorizations for Research
This week, the Department of Health and Human Services Office for Civil Rights (OCR) issued guidance on the use of HIPAA-compliant authorizations for research based on a mandate in the Cures Act for such guidance. The guidance addresses authorizations and…
Connecticut Legislature Responds to Proliferation of Data Breaches
On June 4, 2018, the Governor signed into law Public Act 18-90, An Act Concerning Security Freezes on Credit Reports, Identity Theft Prevention Services and Regulations of Credit Rating Agencies (the “Act”), likely in reaction to the Equifax breach among…