The BTI Law Firms Best at Cybersecurity 2017, a report issued by the BTI Consulting Group (pdf), lists Jackson Lewis as one of the country’s top law firms for cybersecurity and data privacy. The report was compiled “based solely on in-depth telephone interviews with leading legal decision makers,” representing more than 15 different industry segments in organizations with $1 billion or more in annual revenues. Our cybersecurity team is grateful for the recognition from our clients.

Cybersecurity and privacy issues are among the most challenging for virtually all of our clients. Today, organizations contend with vast amounts of data, an expanding, multi-layered regulatory environment, technology that evolves at a blistering pace, and sophisticated cybercriminals who can wreak havoc from thousands of miles away. Our Privacy, e-Communication and Data Security Group is committed to helping our clients navigate these cybersecurity challenges through a variety of services, such as:

  • workthruITtm. Our online applications provide helpful resources including a data breach readiness assessment, a data security assessment and a comprehensive survey of the country’s data breach notification laws. And, there are more cybersecurity and privacy apps coming. Learn more about workthruITtm here.
  • Data Incident Response Team. A tidal wave of ransomware attacks, spearphishing scams and other forms of data breach have victimized thousands of organizations. Having handled more than 500 data incidents, and as part of our commitment to client service, we announced recently a 24/7 Data Incident Response Team to be available on a moment’s notice in the event of a security incident. Learn more about our Data Incident Response Team here.
  • Prevention and Compliance: Assessments, Policies and Training. Of course it is better to avoid a breach than to experience one. So, our team works with clients to assist them with conducting risk assessments, developing policies and procedures, and training their workforce. We strive to understand our clients’ industries because not only is there likely to be different legal requirements, the customary practices and expectations in the industry also are different.
  • Vendor Selection and Management. A cybersecurity program is only as strong as its weakest link and that link could be an organization’s third party service provider. We help organizations assess their vendors’ cybersecurity capabilities, as well as negotiate and draft cybersecurity agreements including business associate agreements to help our clients minimize the risks their vendors present.
  • Government Inquiries and Litigation. We represent our clients before federal and state agencies as well in litigations to respond to claims, inquiries, investigations and compliance reviews involving cybersecurity and privacy.

Cybersecurity and privacy are necessary considerations for doing business today, and we are excited to partner with our clients to help them safely and efficiently maximize the opportunities that information and technology present. Artificial intelligence, internet of things, and “Big Data” present even greater opportunities ahead, with an even greater need to supply adequate time, resources and effort toward cybersecurity and privacy.

President Barack Obama requested $19 billion in his budget for 2017 to address cybersecurity in the United States, $5 billion more than was budgeted for the current year. Today, he issued an Executive Order that will create a commission within the Department of Commerce to be known as the “Commission on Enhancing National Cybersecurity.”

So, what will $19 billion buy? The President’s proposal calls for a number of measures designed to improve and strengthen cybersecurity. Some examples include:

  • $3.1 billion to update and replace old IT systems, along with a new position in the White House to lead the effort.
  • About $62 million is allotted for more cybersecurity professionals, including funding scholarship programs to strengthen the pipeline for this much needed human capital.
  • Amounts for the classified cyber budget for intelligence agencies such as the National Security Agency and the CIA.

The Commission on Enhancing National Cybersecurity under the President’s Executive Order would have as its mission:

To make detailed recommendations to strengthen cybersecurity in both the public and private sectors while protecting privacy, ensuring public safety and economic and national security, fostering discovery and development of new technical solutions, and bolstering partnerships between Federal, State, and local government and the private sector in the development, promotion, and use of cybersecurity technologies, policies, and best practices. The Commission’s recommendations should address actions that can be taken over the next decade to accomplish these goals.

The Commission will need to consider recommendations for at least the following:

  1. how best to bolster the protection of systems and data, including how to advance identity management, authentication, and cybersecurity of online identities, in light of technological developments and other trends;
  2. ensuring that cybersecurity is a core element of the technologies associated with the Internet of Things and cloud computing, and that the policy and legal foundation for cybersecurity in the context of the Internet of Things is stable and adaptable;
  3. further investments in research and development initiatives that can enhance cybersecurity;
  4. increasing the quality, quantity, and level of expertise of the cybersecurity workforce in the Federal Government and private sector, including through education and training;
  5. improving broad-based education of commonsense cybersecurity practices for the general public; and
  6. any other issues that the President, through the Secretary of Commerce (Secretary), requests the Commission to consider.

These actions are designed to affect both the public and private sectors. Accordingly, businesses need to monitor these activities to ensure compliance and that their efforts are consistent with recognized best practices.

As the vast array of internet-connected devices mushrooms, and technologies permit those devices to communicate with one another, calls for privacy and security can be heard. On the heels of a recent victory in the ongoing LabMD case, the Federal Trade Commission (FTC) announced yesterday “concrete steps” businesses can take to enhance the privacy and security of IoT for consumers. According to FTC Chairwoman Edith Ramirez, “The only way for the Internet of Things to reach its full potential for innovation is with the trust of American consumers.”

Increasingly, computing devices are being embedded with capabilities to connect with one another via the Internet. The FTC report estimates that currently there are 25 billion of these devices worldwide. Many believe these technologies will yield immeasurable benefits including helping organizations to understand more efficient ways to do business, perhaps resulting in lower costs and risks. As the FTC notes, and many have experienced (even if not knowing about “IoT” specifically), IoT is already entrenched in our lives. For example, millions already use FitBit and other health and fitness monitoring devices, as have millions of others deployed these technologies in their home security systems and appliances.

The global consulting firm, McKinsey & Co., discussed a number of other examples of IoT at play today, such as:

  • Pill-shaped microcameras travel through the human digestive system and send back thousands of images to pinpoint sources of illness.
  • Farming equipment communicating with remote satellites and ground sensors to assess crop conditions and adjust farming techniques.
  • Billboards assess the consumer profiles of passersby and change displayed messages based on those assessments

These technologies also can “support longer-range, more complex human planning and decision making.” McKinsey sees this occurring in many industries, such as retail, where collecting and analyzing data from shoppers moving through stores can be particularly useful in understanding buying patterns and what factors may influence the ultimate decision to buy. Clearly, in all of these industries, these same technologies can be used to collect information about a company’s workforce with similar goals in mind, including increased efficiency, improved safety, cost containment and risk avoidance. But, alas, there are significant privacy and data concerns as devices silently capture vast amounts of information about such things as movement, communications, patterns, and surroundings.

Enter the FTC. Consistent with its mission, the FTC’s report states that its focus is on IoT devices that are sold to or used by consumers, not in a business-to-business context, nor does it address broader machine-to-machine communications. Some of the concerns identified by the FTC come from a workshop it held in November 2013 – The Internet of Things: Privacy and Security in a Connected World. The risks that could harm consumers according to the FTC include:

  • enabling unauthorized access and misuse of personal information;
  • facilitating attacks on other systems; and
  • enabling privacy risks from the collection of personal information, habits, locations, and physical conditions over time that companies might use to make credit, insurance, and employment decisions.

The FTC explained, for example, that data gathered by a fitness tracker for a wellness-related purpose such as participation in an employer sponsored wellness program, could be used in the future to price health or life insurance or to infer the individual’s suitability for credit or employment – people who exercise regularly make better credit risks, employees). This creates obvious potential risks under the Fair Credit Reporting Act, the Health Insurance Portability and Accountability Act, the Americans with Disabilities Act and other federal and state laws. The FTC report also called attention to a privacy risk involving use of these devices to enable remote eavesdropping into otherwise private spaces.

To address these risks, the FTC’s report makes a number of recommendations, with security being key. Below are some of these “recommendations””

  • build security into devices at the outset – at the design stage – assess risks, collect the minimum necessary information;
  • train employees about the importance of security;
  • make sure third-party service providers maintain appropriate privacy and security protocols – “trust, but verify”;
  • employ a “defense-in-depth” strategy to apply multiple layers of security to defend against a particular risk;
  • stop unauthorized users from accessing a consumer’s device, data, or personal information; and
  • monitor devices, update as needed to address developing risks.

The FTC also recommends that notice be provided to give choices to individuals about how their information will be used, particularly when the data collection is beyond reasonable expectations, and acknowledged there are many ways effective notice could be delivered.

Companies using these technologies should review the FTC report and guidelines and, where appropriate, consider applying them as they adopt IofT. While not currently mandated, many of these guidelines are based on existing principles, best practices and laws concerning the privacy and security of personal information.

In what is believed to be the largest security breach to date, the Associated Press reported that Russian hackers have stolen 1.2 billion user names and passwords. According to the AP, Milwaukee security firm, Hold Security, learned of the breach, but has yet to provide details about the series of website hackings believed to have affected 420,000 websites. Citing nondisclosure agreements, Hold Security has not named the hacked websites.

A concern raised by some is the “breach fatigue” that may be created by the continuing stream of news reports about breaches large and small, the notification letters that follow, and the repeated warnings and recommendations to individuals and businesses about addressing data security. This “condition” may be real, but it is a condition individuals and business have to overcome as “big data” and the “internet of things” (IoT) becomes more a part of our lives, creating value in data that criminals want to steal.

A frequent refrain from some, including many small businesses, is that incidents like these will not happen to them. But, as the L.A. Times reports, according to the National Small Business Assn., 44% of survey respondents had been victims of at least one cyberattack. For well over a decade, identity theft continues to be the top crime reported to the FTC. For businesses, the risk is more than whether a breach will happen and how to respond, it is the effects the breach can have on its reputation, the enforcement that increasingly follows these incidents at the federal and state level, and increased litigation including class actions. Late last month, for instance, the Massachusetts Attorney General’s office reported a $150,000 settlement with a local hospital based on allegations of failing to properly safeguard patient data and report the incident.

For many businesses, there are a number of “best practices” that are relatively easy to implement and can have a significant impact on reducing the risks of a data breach. Many say, yes, but where do we start. Logically, the starting point is gaining an understanding of the businesses’ data privacy and security risks – doing a risk and vulnerability assessment. There are a number of resources available to assist in designing and carrying out an assessment. For example, the National Institute of Standards and Technology (NIST) recently issued a draft update of its primary guide to assessing security and privacy controls. While the work NIST does, including this guide, is designed for federal information systems and networks, it is an excellent and comprehensive source for businesses to understand steps they too can take to safeguard their systems and data.

The practical starting point, however, is getting management, C-suite support. Data privacy and security is an enterprise-wide risk which requires an enterprise-wide solution. Like many conditions, left untreated, “breach fatigue” can have significant consequences.

Businesses that track the geolocation of individuals—whether for fleet management, sales and promotion, logistics, risk mitigation, or other reasons—should closely monitor the progress of California Assembly Bill 1355 (AB 1355), also known as the California Location Privacy Act. If passed, this bill would impose significant restrictions on the collection and use of geolocation data, requiring many businesses to overhaul their location tracking policies and procedures.

California has long been at the forefront of data privacy regulation, particularly in the area of location tracking. Section 637.7 of the California Penal Code, for example, provides that no person or entity in California may use an electronic tracking device to determine the location or movement of a person. Notably the law does not apply when the registered owner, lessor, or lessee of a vehicle has consented to the use such a device with respect to that vehicle.

More recently, the California Consumer Privacy Act of 2018 (CCPA) established a comprehensive privacy and security framework for personal information of California consumers, which includes granting consumers rights over their personal information. Under the CCPA, consumers have the right, subject to some exceptions, to limit the use of their “sensitive personal information,” a defined term which includes geolocation data. The California Privacy Rights Act of 2020 (CPRA) amended the CCPA, further strengthening these protections by enhancing consumer rights and enforcement mechanisms.

Importantly, employees and contractors are considered “consumers” under the CCPA.

Key Provisions of AB 1355

If enacted, AB 1355 would place strict limits on how businesses collect, use, and retain location information. Here are the major takeaways for businesses that track geolocation data.

Who Does the Law Apply To?  The law would apply to any business (referred to as a “covered entity”) that collects or uses location data from individuals in California, although there is an exception for the location information of patients if the information is protected by HIPAA or similar laws. Government agencies are not considered covered entities but are prohibited from monetizing location information.

The bill defines “individual” as a “natural person located within the State of California.” So, it looks like the individual need not be a California resident. In addition, the collection or use of location data must be necessary to provide goods or services requested by that individual. It is unclear how this provision would apply in the employment context.

Express Opt-In Requirement. Individuals would be required to expressly opt in before their location data could be collected; businesses would not be permitted to infer consent or use pre-checked boxes.

Prohibited Actions. Businesses would not be permitted to:

  • Collect more precise location data than is necessary.
  • Retain location data longer than necessary.
  • Sell, rent, trade, or lease location data to third parties.
  • Infer additional data from collected location information beyond what is necessary.
  • Disclose location data to government agencies without a valid court order issued by a California court.

Notice and Policy Requirement. Under AB 1355, businesses would be required to provide clear, prominent notice at the point where location data is collected. The notice would need to include the name of the covered entity and service provider collecting the information, and a phone number and an internet website where the individual can obtain more information. Companies also would need to maintain a location privacy policy detailing, among other things:

  • What location data is collected.
  • The retention and deletion policies.
  • Whether the data is used for targeted advertising.
  • The identities of third parties or service providers with access to the data.

Any changes to this policy would require at least 20 days’ notice and renewed consent.

Enforcement and Legal Remedies. If enacted, AB 1355 would permit the California Attorney General, district attorneys, and other public prosecutors to bring lawsuits against non-compliant businesses. Remedies could include all of the following:

  • Actual damages suffered by affected individuals.
  • A civil penalty of $25,000.
  • Court-ordered injunctions and attorney’s fees for prevailing plaintiffs.

Implications for Businesses Engaged in Location Tracking

This bill represents a major shift in how businesses must approach location tracking. If enacted, businesses relying on geolocation data for purposes such as monitoring employees, connecting with customers, improving logistics, or managing risk must:

  • Implement new opt-in procedures before collecting location data.
  • Reevaluate their data retention policies to ensure compliance.
  • Review agreements with third-party vendors that process location data.
  • Update their privacy policies and internal procedures to align with the new legal requirements.

In addition to monitoring the path of this legislation, businesses also should consider revisiting their current electronic monitoring and tracking activities. Data privacy and security laws have expanded in recent years, with geolocation data being one of the more sensitive categories of personal information protected.

A recent Forbes article summarizes a potentially problematic aspect of AI which highlights the importance of governance and the quality of data when training AI models.  It is called “model collapse.”  It turns out that over time, when AI models use data that earlier AI models created (rather than data created by humans), something is lost in the process at each iteration and the AI model can fail.

According to the Forbes article:

Model collapse, recently detailed in a Nature article by a team of researchers, is what happens when AI models are trained on data that includes content generated by earlier versions of themselves. Over time, this recursive process causes the models to drift further away from the original data distribution, losing the ability to accurately represent the world as it really is. Instead of improving, the AI starts to make mistakes that compound over generations, leading to outputs that are increasingly distorted and unreliable.

As the researchers published in Nature who observed this effect noted:

In our work, we demonstrate that training on samples from another generative model can induce a distribution shift, which—over time—causes model collapse. This in turn causes the model to mis-perceive the underlying learning task. To sustain learning over a long period of time, we need to make sure that access to the original data source is preserved and that further data not generated by LLMs remain available over time. The need to distinguish data generated by LLMs from other data raises questions about the provenance of content that is crawled from the Internet: it is unclear how content generated by LLMs can be tracked at scale. One option is community-wide coordination to ensure that different parties involved in LLM creation and deployment share the information needed to resolve questions of provenance. Otherwise, it may become increasingly difficult to train newer versions of LLMs without access to data that were crawled from the Internet before the mass adoption of the technology or direct access to data generated by humans at scale.

These findings highlight several important considerations when using AI tools. One is maintaining a robust governance program that includes, among other things, measures to stay abreast of developing risks. We’ve heard a lot about hallucinations. Model collapse is a relatively new and a potentially devastating challenge to the promise of AI. It raises an issue similar to the concerns with hallucinations, namely, that the value of the results received from a generative AI tool, one that an organization comes to rely on, can significantly diminish over time.

Another related consideration is the need to be continually vigilant about the quality of the data being used. Trying to distinguish and preserve human generated content may become more difficult over time as sources of data will be increasingly rooted in AI-generated content. The consequences could be significant, as the Forbes piece notes:

[M]odel collapse could exacerbate issues of bias and inequality in AI. Low-probability events, which often involve marginalized groups or unique scenarios, are particularly vulnerable to being “forgotten” by AI models as they undergo collapse. This could lead to a future where AI is less capable of understanding and responding to the needs of diverse populations, further entrenching existing biases and inequalities.

Accordingly, organizations need to build strong governance and controls around the data on which their (or their vendors’) AI models were and continue to be trained. That need is only made more clear considering the potential for model collapse is only one of a number of risks and challenges facing organizations when developing and/or deploying AI.

Websites play a vital role for organizations. They facilitate communication with consumers, constituents, patients, employees, donors, and the general public. They project an organization’s image and promote goodwill, provide information about products and services and allow for their purchase. Websites also inform investors about performance, enable job seekers to view and apply for open positions, and accept questions and comments from visitors to the site or app, among many other activities and functionalities. Because of this vital role, websites have become an increasing subject of regulation making them a growing compliance concern.

Currently, many businesses are working to become compliant with the California Consumer Privacy Act (“CCPA”) which, if applicable, requires the conspicuous posting of a detailed privacy policy on a business’s website. But, the CCPA is not the first nor will it be the last compliance challenge for organizations that operate websites and other online services. An growing compliance burden has led to a wide range of operational and content requirements for websites. The push for CCPA compliance and responding to the flood of ADA accessibility litigation may cause more organizations to revisit their websites and, in the process, uncover a range of other issues that have crept in over the years.

What are some of these requirements?

AI – Artificial Intelligence. Organizations are increasingly leveraging automated decision-making tools to enhance their businesses in a range of areas, including employment. Needless to say, artificial intelligence (AI) and similar technologies, which power these tools, is being targeted for regulation. For example, the New York City Council passed a measure that subjects the use of automated decision-making tools to several requirements. One of those requirements is a “bias audit.” Employers that intend to utilize such a tool must first conduct a bias audit and must publish a summary of the results of that audit on their websites. We cover more about NYC Local Law 144 here.

ADA Accessibility. When people think about accommodating persons with disabilities, they often are drawn to situations where a person’s physical movement in a public place is impeded by a disability – stairs to get into a library or narrow doorways to use a bathroom. Indeed, Title III of the Americans with Disabilities Act grants disabled persons the right to full and equal enjoyment of the goods, services, facilities, privileges, advantages, or accommodations of any place of public accommodation. Although websites were not around when the ADA was enacted, they are now, and courts are applying ADA protections to those sites. The question is whether a website or application is accessible.

Although not yet adopted by the Department of Justice, which enforces Title III of the ADA, guidelines established by the Website Accessibility Initiative appear to be the more likely place courts will look to access the accessibility of a website to which Title III applies. State and local governments have similar obligations under Title II of the ADA, and those entities might find guidance here.

HIPAA…and tracking technologies, pixels. For anyone who has had their first visit to a doctor’s office, they likely were greeted with a HIPAA “notice of privacy practices” and asked to sign an acknowledgement of receipt. Most covered health care providers have implemented this requirement, but may not be aware of the website requirement. HIPAA regulation 45 CFR 164.520(c)(3)(i) requires that covered entities maintaining a website with information about the entity’s customer services or benefits must prominently post its notice of privacy practices on the site and make the notice available electronically through site.

Beyond the notice posting requirement, websites of HIPAA covered entities and business associates have operational issues to consider. In December 2022, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a bulletin with guidance concerning the use of online tracking technologies by covered entities and business associates under HIPAA. The OCR Bulletin follows a significant uptick in litigation concerning these technologies in industries including but not limited to the healthcare. For healthcare entities, the allegations relate to the sharing of patient data obtained from patient portals and websites. We do a deeper dive into this issue here.

COPPA. The Children’s Online Privacy Protection Act (COPPA) was enacted to give parents more control concerning the information websites collect about their children under 13. Regulated by the Federal Trade Commission (FTC), COPPA requires websites and online services covered by COPPA to post privacy policies, provide parents with direct notice of their information practices, and get verifiable consent from a parent or guardian before collecting personal information from children. COPPA applies to websites and online services directed to children under the age of 13 that collect personal information, and to sites and online services geared toward general audiences when they have “actual knowledge” they are collecting information from children under 13. Find out more about compliance here.

FTCA and more on tracking technologies. Speaking of the FTC, that agency also enforces the federal consumer protection laws, including section 5 of the Federal Trade Commission Act (FTCA) which prohibits unfair and deceptive trade practices affecting commerce. When companies tell consumers they will safeguard their personal information, including on their websites, the FTC requires that they live up these promises. Businesses should review their website disclosures to ensure they are not describing privacy and security protections that are not actually in place.

Further to the issue of website tracking technologies noted above under HIPAA, the FTC took enforcement action against digital healthcare companies for sharing user information vie third-party tracking pixels, which enable the collection of user data. However, the FTC’s new focus highlights that issues with pixel tracking are not only a concern for covered entities and business associates under HIPAA.

ACA – Transparency in Coverage. Pursuant to provisions in the Consolidated Appropriations Act, 2021, the Departments of Labor, Health and Human Services, and the Treasury issued regulations to implement the Transparency in Coverage Final Rules.  The Final Rules require certain health plans and health insurance issuers to post information about the cost to participants, beneficiaries, and enrollees for in-network and out-of-network healthcare services through machine-readable files posted on a public website.  The Final Rules for this requirement are effective for plan years beginning on or after January 1, 2022 (an additional requirement for disclosing information about pharmacy benefits and drug costs is delayed pending further guidance).

Comprehensive State Privacy Laws, including the CCPA. As mentioned above, a CCPA-covered business that maintains a website must post a privacy policy on its website through a conspicuous link on the home page using the word “privacy,” on the download or landing page of a mobile application. That is not all. The website must also provide certain mechanisms for consumers (including employees and applicants) to contact the business about their CCPA rights, such as the right to require deletion of their personal information, and the right to opt-out of the sale of personal information. The latter must be provided through an interactive webform accessible via a clear and conspicuous link titled “Do Not Sell My Personal Information,” or “Do Not Sell My Info.” Several of these requirements have been enhanced beginning in 2023 under the California Privacy Rights Act.

Since we originally published this post, five other states have enacted a similar data privacy framework – Colorado, Connecticut, Iowa, Utah, and Virginia. For organizations subject to those law, additional work may be needed on their privacy policies to comply.

CalOPPA. Even if an organization is not subject to the CCPA, it still may be subject to the California Online Privacy Protection Act (CalOPPA). CalOPPA requires certain commercial operators of online services, including websites and mobile and social apps, which collect personally identifiable information from Californians to conspicuously post a privacy policy. Privacy policies should address how companies collect, use, and share personal information. Companies can face fines of up to $2,500 each time a non-compliant app is downloaded.

Delaware and Nevada. In 2016, Delaware became the second state to have an online privacy protection act, requiring similar disclosures to those under CalOPPA. Nevada enacted website privacy legislation of its own. First, like DelOPPA and CalOPPA, NRS 603A.340 requires “operators” to make a privacy notice reasonably accessible to consumers through its Internet website or online service. That notice must, among other things, identify the categories of covered information the operator collects through the site or online service about consumers who use or visit the site or service and the categories of third parties with whom the operator may share such covered information. In general, an operator is a person who: (i) owns or operates an Internet website or online service for commercial purposes; (ii) collects and maintains covered information from consumers who reside in this State and use or visit the Internet website or online service; and (iii) engages in any activity that constitutes sufficient nexus with this State, such as purposefully directing its activities toward Nevada. Effective October 1, 2019, Nevada added to its website regulation by requiring operators to designate a request address on their websites through which a consumer may submit a verified request to opt out of the sale of their personal information.

California’s Fair Chance Act. This is California’s version of the “ban the box” law, those law enacted in many states which generally prohibit employers from asking job applicants about criminal convictions before making a conditional job offer. In California, the law imposes similar restrictions on employers with five or more employees. Why is this a website requirement?

Recently, the state’s Department of Fair Employment and Housing (DFEH) announced new efforts to identify and correct violations of the statute by using technology to conduct mass searches of online job advertisements for potentially prohibited statements. The DFEH deems blanket statements in job advertisements indicating that the employer will not consider anyone with a criminal history to be violative of the statute. In its press release, the DFEH states in one day of review it found over 500 job advertisements with statements that violate the statute. The DFEH has released a new Fair Chance Toolkit, that includes sample forms and guides, and employers should also consider reviewing the descriptions of job opportunities on their websites.

California Transparency in Supply Chains Act. California seeks to curb slavery and human trafficking by making consumers and businesses more aware that the goods and products they buy could be supporting the commission of these crimes. To do so, the Transparency in Supply Chains Act requires large retailers and manufacturers to provide consumers with information regarding their efforts to eradicate slavery and human trafficking from their supply chains. This information must be conspicuously provided on the company’s website (or provided in writing if it does not have a website). To be subject to the law, a company must (a) identify itself as a retail seller or manufacture in its tax returns; (b) satisfy the legal requirements for “doing business” in California; and (c) have annual worldwide gross receipts exceeding $100,000,000. To assist with compliance, the state has published a Resource Guide and Frequently Asked Questions.

GDPR. In 2018, the European Union’s General Data Protection Regulation (GDPR) became effective in 2018 and reached companies and organizations globally. In general, organizations subject to the GDPR which collect personal data on their websites must post a privacy policy on their website setting for the organization’s privacy practices.

Not-For-Profits, Donors, and Ratings. A donor’s decision to contribute to an organization is significantly affected by that organization’s reputation. To assist donors, several third-party rating sites, such as Charity Navigator, the Wise Giving Alliance, and CharityWatch, do much of the legwork for donors. They collect large amounts of data about these organizations, such as financial position, use of donated funds, corporate governance, transparency, and other practices. They obtain most of that data from the organizations’ Forms 990 and websites, where many organizations publish privacy policies.

Rating sites such as Charity Navigator base their ratings on comprehensive methodologies. A significant component of Charity Navigator’s rating, for example, relates to accountability and transparency, made up of 17 categories. A review of an organization’s website informs five of those 17 categories, namely (i) board members listed, (ii) key staff listed, (iii) audited financials published, (iv) Form 990 published, and (v) privacy policy content. Addressing some of these issues on an organization’s website could help boost its ratings and drive more contributions.

This is by no means an exhaustive list of the regulatory requirements that may apply to your website or online service. Organizations should regularly revisit their websites not just to add new functionality or fix broken links. They should have a process for ensuring that the sites or services meet the applicable regulatory requirements.

URL

On May 12, 2021, the Biden Administration issued an Executive Order on “Improving the Nation’s Cybersecurity” (EO). The EO was in the works prior to the Colonial Pipeline cyberattack, reportedly a ransomware incident that snarled the flow of gas on the east coast for days. Ransomware attacks are nothing new, but they are increasing in severity. Most do not see the large sums paid to hackers by victim organizations needing access to their encrypted data or wanting to stop a disclosure of sensitive information if they can. But most do see the crippling of vital infrastructure caused by compromised computer systems without which basic services cease to flow.

Of course, the Colonial Pipeline incident is not the only attack we have seen affecting entities that provide to critical infrastructure. In February of this year, ABC News reported that weak cybersecurity controls “allowed hackers to access a Florida wastewater treatment plant’s computer system and momentarily tamper with the water supply,” based on a memo by federal investigators obtained by ABC. A month later, sensitive data were exposed for some time in cloud storage by New England’s largest energy provider, according to reports. The SolarWinds breach last year, named Sunburst, was a massive compromise of government agencies including the Department of Energy.

Will the EO help? It is unclear at this point, however, the EO makes a clear statement on the policy of the Administration:

It is the policy of my Administration that the prevention, detection, assessment, and remediation of cyber incidents is a top priority and essential to national and economic security.  The Federal Government must lead by example.  All Federal Information Systems should meet or exceed the standards and requirements for cybersecurity set forth in and issued pursuant to this order.

The effect of the EO will mostly affect the federal government and its agencies. However, several of the requirements in the EO will reach certain federal contractors, and also will influence the private sector. Below are several of the items directed by the EO:

  • Removing contractual barriers in contracts between the federal government and its information technology (IT) and operational technology (OT) service providers. The goal here is to increase information sharing about threats, incidents, and risks in order to accelerate incident deterrence, prevention, and response efforts and to enable more effective defense of government systems and information. As part of this effort, the EO requires a review of the Federal Acquisition Regulation (FAR) concerning contracts with such providers and recommendations for language designed to achieve these goals. Recommendations will include, for example, time periods contractors must report cyber incidents based on severity, with reporting on the most severe cyber incidents not to exceed 3 days after initial detection. The changes also will seek to standardize common cybersecurity contractual requirements across agencies.
  • Modernize approach to cybersecurity. To achieve this goal, some of the steps called for in the EO include adopting security best practices, advance to Zero Trust Architecture, move to secure cloud services, including Software as a Service (SaaS), and centralize and streamline access to cybersecurity data to drive analytics for identifying and managing cybersecurity risks. More specifically, the EO requires that within 180 days of the date of the EO, agencies must adopt multi-factor authentication and encryption for data at rest and in transit, to the maximum extent consistent with Federal records laws and other applicable laws.
  • Improve software supply chain security. Driven by the impact of the SolarWinds incident, the EO points to the lack of transparency in the software development and whether adequate controls exist to prevent tampering by malicious actors, among other things. The EO calls for guidance to be developed that will strengthen this supply chain, which will include standards, procedures, and criteria, such as securing development environments and attesting to conformity with secure software development practices. The EO also requires recommendations for contract language that would require suppliers of software available for purchase by agencies to comply with, and attest to complying with the guidance developed. Efforts also will be made to reach the private sector. For instance, pilot programs will be initiated by the Secretary of Commerce acting through the Director of NIST to educate the public on the security capabilities of Internet-of-Things (IoT) devices and software development practices, and shall consider ways to incentivize manufacturers and developers to participate in these programs.
  • Establishing a Cyber Safety Review Board. Among the Board’s duties would include reviewing and assessing certain significant cyber incidents affecting FCEB Information Systems or non-Federal systems, threat activity, vulnerabilities, mitigation activities, and agency responses.
  • Standardize incident response. Standardize the federal government’s response to cybersecurity vulnerabilities and incidents to ensure a more coordinated and centralized cataloging of incidents and tracking of agencies’ progress toward successful responses.
  • Improve detection. The EO seeks to improve detection of cybersecurity vulnerabilities and incidents on federal government networks.
  • Improving the federal government’s investigative and remediation capabilities. The Administration recognizes it is essential that agencies and their IT service providers collect and maintain network and system logs on federal information systems in order to address a cyber incident. The EO seeks recommendations on the types of logs to be maintained, the time periods to retain the logs and other relevant data, the time periods for agencies to enable recommended logging and security requirements, and how to protect logs. These recommendations will also be considered by the FAR Council when promulgating rules for removing barriers to sharing threat information.

It is expected the U.S. government will ramp up efforts to strengthen its cybersecurity, and we can expect states to continue to legislate and regulate in this area. All businesses, including federal contractors, likely will experience pressure to evaluate their data privacy and security threats and vulnerabilities and adopt measures to address their risk and improve compliance.

In a recent post, we highlighted the need for a privacy and cybersecurity training program, one not solely focused on spotting phishing attempts (although that is quite important as well). A primary reason, quite simply, is that employees continue to be a leading cause of data breaches. This fact was reaffirmed for the Wyoming Department of Health (WDOH) when an employee mistake resulted in the disclosure of nearly 165,000 Wyomingites. And, the risk is only amplified in the current remote work environment.

The WDOH announced on April 27, 2021, that it had inadvertently exposed 53 files containing COVID-19 and Influenza test data and 1 file containing breath alcohol test results. Some of the files had been exposed as early as November 5, 2020, but WDOH did not discover the incident until March 10, 2021. According to WDOH, the files included name or patient ID, address, date of birth, test result(s), and date(s) of service, but did not contain social security numbers, banking, financial, or health insurance information.

The breach resulted from an “inadvertent exposure” of the files by a WDOH workforce employee who mistakenly and impermissibly uploaded the files to private and public GitHub.com repositories, resulting in disclosure to unauthorized individuals. Notably, WDOH intended GitHub.com, internet-based software development company, be used by its employees only for software code storage and maintenance.

It is not clear why the WDOH employee uploaded 54 files containing patient test result data, including COVID-19 test results, to a service intended for storage of coding data. And, we do not know whether the employee in this case received training on the purpose and use of GitHub.com. However, according to WDOH’s announcement, the files were promptly removed from GitHub.com, the employee was sanctioned, and WDOH retrained its workforce on data privacy and security best practices.

Certainly, mistakes processing personal information are going to happen and no amount of training will prevent all data incidents and breaches. There is no silver bullet. An important question for an organization to ask, however, is whether reasonable steps are being taken to minimize the risk to data, even with regard to inadvertent errors in handling and with regard to use of company systems, among other things.

Training can be one of a number of tools organizations use to create a culture of privacy and security. Increased awareness can help to minimize, even if not eliminate, inadvertent errors. The white paper we provided in our earlier post outlines several considerations for developing a robust program designed to continually remind employee of the vigilance needed to protect personal information from unauthorized access, acquisition, modification, and disclosure. It is and will continue to be an ongoing challenge, particularly in the current environment with workplaces shifting as we emerge from the harshest effects of the pandemic.