On September 19, 2022, a Massachusetts federal District Court denied Boston Globe Media Partners LLC’s motion to dismiss a consumer class action suit against it. This case is one of 47 proposed class actions filed since February 2022 against various
Security, Privacy and the Law
Legal Perspectives on the Expanding Universe of Information Security & Privacy Issues.
Latest from Security, Privacy and the Law - Page 5
Is the VPPA a New Litigation Weapon for Consumers?
On September 19, 2022, a Massachusetts District Court denied Boston Globe Media Partners LLC’s (the Globe) motion to dismiss a class action suit brought against it in what could be a boon for consumers’ demands to protect their digital privacy.…
Looking to a New EU-US Data Privacy Framework
As we wrote in July 2020, the European Court of Justice issued a landmark decision that invalidated the Privacy Shield as untenable under the European General Data Protection Regulation (GDPR). The decision sparked negotiations between the United States and the…
HHS Office for Civil Rights Posts HIPAA Security Rule Security Incident Procedures
Every October, in recognition of National Cybersecurity Awareness Month, the federal government and its partners work to educate stakeholders on cybersecurity awareness and how best to protect the privacy and security of confidential data. Within the health care industry, the…
California Trails Closely Behind UK to Protect Children’s Privacy
Recently signed into law by California Governor Gavin Newsom on September 15, 2022, the California Age-Appropriate Design Code Act (“AADC”) changes the playing field for certain businesses that provide online services, products, or features accessible to children under the age…
Password Security & Best Practices – A Refresher
As more and more of us return to the office, it’s a good time to revisit the passwords you use. It is therefore timely that the U.S. Department of Health and Human Services, Health Sector Cybersecurity Coordination Center (“HC3”)…
The FTC’s Post-Dobbs Focus on Location Privacy Draws a Legal Challenge
As we had previously blogged, the FTC in guidance following the Supreme Court’s decision in Dobbs v. Jackson Women’s Health indicated that it would aggressively wield its enforcement authority in relation to deceptive statements about location privacy, particularly in…
Federalism Rankles National Privacy Debate: California Weighs in on the proposed American Data Protection and Privacy Act
Federal Agencies Issue Alert Regarding Maui Ransomware
On July 7, 2022, three federal agencies – the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and the Department of the Treasury – issued a joint alert regarding Maui Ransomware, which has been linked to ransomware attacks…
Anonymization v. De-Identification, Post-Dobbs; Rumblings from the FTC
When is personal data “anonymized”? The answer to this question has largely been based on jurisdiction. If your business is in the U.S., so long as HIPAA or the CCPA does not govern, then generally aggregated or de-identified data could…