The answer to this question may depend on the actions that the insured takes when it applies for coverage and during the period the policy is in force. The demand for cyberinsurance that is intended to cover exposures from data breaches, among other things, has exploded in recent years, reports The Hill. This is
Data Security
SEC’s Division of Investment Management Issues Cybersecurity Guidance
In Guidance Update No. 2015-02, the Division of Investment Management (Division) of the Securities and Exchange Commission (SEC) issued some high-level suggestions concerning the importance of cybersecurity for registered investment companies and registered investment advisers. The guidance outlines a number of measures these entities should consider for addressing cybersecurity risks. Of course, while some…
EEOC Wellness Program Regulations Offer Best Practices for Medical Record Confidentiality
As reported on our Benefits Law Advisor, the EEOC has issued proposed wellness program regulations. Much of the attention to those proposed rules understandably will be how they would affect the incentives employers have implemented to spur their employees to engage in healthier behaviors. The proposed rules also address, however, the confidentiality provisions under…
Next Step in U.S. Postal Service Breach – NLRB Sues Postal Service
As discussed in an earlier post, shortly after the United States Postal Service reported a data breach potentially affecting hundreds of thousands of employees, the American Postal Workers Union filed an unfair labor practice with the National Labor Relations Board alleging the Postal Service should have bargained with the union over the impact and…
Alabama Seeks To Become 48th State To Enact Breach Legislation
Alabama recently introduced a bill (S.B. 106) which would require notification in the event of a breach affecting the personal information of an Alabama resident. While 47 states currently have laws requiring breach notification — most recently joined by Kentucky — New Mexico, South Dakota, and Alabama are the only states that do…
Employee Apps = Employer Data Risk?
Many mobile app developers do not place a high priority on data security, as illustrated by a recent IBM/Ponemon study:
- Fifty percent of mobile app developers have no budget for security.
- Forty percent of companies don’t scan mobile app codes for vulnerabilities.
- The average company tests less than half of the apps it builds
…
The Data Security and Breach Notification Act of 2015
On March 25, 2015, the United States House of Representative, Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade approved draft legislation which would replace state data breach notification laws with a national standard. This draft legislation comes on the heels of the President’s call for a national data breach notification law. The proposed…
Email Autofill Error Exposes Personal Information of G20 World Leaders
With breaches caused by payment card thieves and hackers dominating the news, it is easy for mid-sized and small companies to think that data breaches are unfortunate events that affect only large companies. Not only is this sentiment misguided, but in relative terms the information contained in exposed emails can cause far more damage to …
Checklists Not Enough When Developing a WISP, FTC Director Comments at IAPP Global Privacy Summit
This year’s IAPP Global Privacy Summit was very informative on a number of fronts, including the helpful insight provided by officials at the Federal Trade Commission (FTC) on a range of topics. A good summary of some of their comments can be found here, which includes concerns they expressed about the Consumer Privacy Bill…
Illinois Attorney General Seeks Stronger Data Breach Notification Law, Requirement to Safeguard Personal Information
Reacting to a report that identity theft was a top concern for Illinois residents (second in a list of ten), Attorney General Lisa Madigan announced a legislative proposal to strengthen the state’s existing data breach notification law. The call for stronger breach notification laws is a trend that has emerged in other states, such as…