In one of its last data security enforcement actions of the Biden Administration, the Federal Trade Commission (FTC) brought claims against GoDaddy, one of the world’s largest web hosting companies, for allegedly failing to implement reasonable...
On December 27, 2024, the U.S. Department of Health and Human Services (HHS) proposed significant amendments to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, aiming to bolster cybersecurity requirements for covered entities and business...
A hashed value, like 2813448ce6316cb70b38fa29c8c64130, looks like a wild scramble of gobbledygook. But in a recent blog, the FTC warned companies that when a hash is used to uniquely identify or target a consumer, that hash...
The California Privacy Protection Agency (CPPA) has recently proposed regulations (the “Proposed Regulations”) implementing California’s data broker registration statute, Cal Civ. Code § 1798.99.80 (the “Data Broker Registration Statute”). If adopted as drafted, the Regulations...
The Washington Attorney General (“WA AG”) recently updated its My Health, My Data Act (“MHMDA”) FAQs to clarify that consumer health data (“CHD”) does not include the purchase of non-prescription medication, but does include inferences about a consumer’s health based on that purchase....
The National Institute of Standards and Technology (NIST) recently finalized its consensus-based cybersecurity framework, often referred to as the “CSF.” The CSF provides organizational tools for reducing cybersecurity risk and, with the latest revisions, offers new tailored guidance...