Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Robotics and Health Information - Privacy and Security Issues You Need to Know
Blog March 05, 2026
On March 5, 2026, Colin Zick presented to the MassRobotics Healthcare Catalyst Program on the topic, "Robotics and Health Information: Navigating Clinical Deployments in Light of Current Trends in Health Information Privacy and Security."…
42 C.F.R. Part 2 Civil Enforcement Is Here: What Substance Use Disorder Providers Need to Know
Blog February 17, 2026
February 16, 2026 marks a significant milestone for substance use disorder (SUD) treatment providers across the country…
HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points
Blog February 10, 2026
The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes…
System Hardening, HIPAA, and the Practical Path to Protecting ePHI
Blog January 12, 2026
The January 2026 OCR Cybersecurity Newsletter is the U.S. Department of Health and Human Services Office for Civil Rights’ latest installment in its periodic series translating HIPAA Security Rule expectations into practical, operational guidance…
Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records:  42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
Blog November 10, 2025
On November, 7, 2025, I spoke to the Massachusetts Health Information Management Association about the federal government’s sweeping updates to 42 CFR Part 2—the confidentiality rules governing substance use disorder (SUD) records—to better align with HIPAA while preserving Part 2’s core patient protections…
Expanded Protections for Reproductive Health and Gender-Affirming Care: What Massachusetts Providers Need to Know
Blog September 04, 2025
On August 7, 2025, Massachusetts Governor Maura Healey signed into law an Act Strengthening Healthcare Protections in the Commonwealth (the “Act”), which amends the state’s existing “Shield Law” protections for providers of reproductive health and gender-affirming care (“Protected Care”)…
HHS Office for Civil Rights Proposes Measures to Strengthen Cybersecurity in Health Care Under HIPAA
Blog December 30, 2024
The Department of Health and Human Services has proposed significant modifications to the HIPAA Security Rule and the HITECH Act in an attempt to strengthen cybersecurity protections for electronic protected health information…
The Health Sector Cybersecurity Coordination Center’s September 19 Threat Briefing on Healthcare Technology Security
Blog September 19, 2024
In a joint September 19, 2024 presentation, the Department of Health and Human Services’ Office of Technology and the Health Sector Cybersecurity Coordination Center explored key concepts and definitions, examined various technologies, electronic records systems, medical devices, and AI, and discussed defense and mitigation strategies that sophisticated compliance personnel must consider…
FTC's Updated Health Data Breach Rule Covers Apps, Other New Tech
Blog April 29, 2024
The FTC’s Health Breach Notification Rule (HBNR) was originally adopted in 2009 and applies to entities that handle personal health records (PHR), records that are not Protected Health Information (PHI) covered by the Health Insurance Portability and Accountability Act (HIPAA).  The FTC has updated its HBNR to clarify that the rule also restricts marketing practices involving personal health information…
1 of 18

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors