An Office for Civil Rights (OCR) report issued this month reveals some interesting details about data breach activity under HIPAA, as well as some helpful reminders and recommendations for covered entities and business associates. Section 13402(i) of the HITECH Act requires the Secretary of Health and Human Services to submit a report to various Senate
Information Management
FTC Objects to Sale of Company Assets Based on Potential Breach of Privacy Policy
Recently, the Federal Trade Commission (“FTC”) filed a limited objection in bankruptcy court to the proposed sale of assets of ConnectEdu, Inc. (“ConnectEdu”) on the grounds that the company’s privacy policy protecting customer personal information had potentially not been complied with.
Specifically, ConnectEdu, an education technology company that provided interactive tools to assist students, parents …
Louisiana Follows Wisconsin and Tennessee in Protecting Employee and Student Personal Online Account Access Information
Following the enactment of similar laws in Wisconsin and Tennessee earlier this year, Louisiana Governor Bobby Jindal signed HB 340, the Personal Online Account Privacy Protection Act, into law prohibiting employers and schools in Louisiana from demanding access to personal email, social media and other types of online accounts. The Act applies to…
Volunteer State (Tennessee) Prohibits Employers From Asking Employees, Applicants to Volunteer Access to Social Media, Internet Accounts
Effective January 1, 2015, Tennessee employers, including government entities, will be prohibited from requesting or requiring access to the private social networking or online accounts of employees and job applicants under the Volunteer State’s “Employee Online Privacy Act of 2014,” signed by Governor Bill Haslam. Our Tennessee colleagues outline the key provisions of the law…
Employers, the NLRB Wants Some Control Over Your Company Email
You’ve just finished your email, electronic communications, social media and/or BYOD policies for employees assuming, among other things, that you did not have to permit employees to use company-provided communication systems for nonwork-related purposes, such as to fulfill certain union-related purposes or other “protected concerted activities” under for Section 7 of the National Labor Relations…
Florida Legislature Seeks to Overhaul Existing Data Security Law
On the heels of recent nationwide data breaches of consumer personal information, the Florida State Senate has proposed SB 1524, which if adopted will become effective on July 1, 2014, to revamp and replace existing state data security law and, in particular, impose a statutory requirement to safeguard personal information, reporting a breach to…
Kentucky Enacts a Data Breach Notification Law and Protects Student Data in the Cloud
Kentucky Gov. Steve Beshear signed H.R. 232 on April 10, 2014, making the Commonwealth the 47th state to enact a data breach notification law. The law also limits how cloud service providers can use student data. A breach notification law in New Mexico may follow shortly.
Data Breach Notification Mandate
The Kentucky law follows the…
California Attorney General Announces More Active Role in Dealing with Data Breaches, and Helpful Guide for Small Business
On Thursday, California Attorney General Kamala Harris announced heightened enforcement concerning data breaches, reports USAToday. AG Harris’ office also issued a Guide that provides recommendations to California businesses, particularly small businesses, to help them protect against and respond to the increasing threat of malware, data breaches and other cyber risks.
The circumstances are certainly…
“Blackphone” to address key smartphone privacy and security concerns?
Smartphone privacy and security concerns continue to weigh on businesses, particularly for companies in certain industries such as healthcare, and for those that have or are thinking of moving to a “bring your own device” (BYOD) model. Promoters of the “Blackphone,” according to a Reuters report, hope that their version of Google’s Android…
U.S. Attorney General Eric Holder Urges the Passage of a National Data Breach Notification Law
After years of identity theft holding the top spot for crimes reported to the Federal Trade Commission, and following recent reports of massive data breaches, U.S. Attorney General Eric Holder urged Congress today to enact a national law setting a uniform standard for notifying individuals regarding breaches involving their personal information, according to a report…