Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points
Blog February 10, 2026
The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes…
HHS OCR Settles HIPAA Security Rule Investigation with Health Fitness Corporation
Blog March 24, 2025
On March 21, 2025, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement of HIPAA security rule claims involving Health Fitness Corporation (Health Fitness)…
HHS Office for Civil Rights Proposes Measures to Strengthen Cybersecurity in Health Care Under HIPAA
Blog December 30, 2024
The Department of Health and Human Services has proposed significant modifications to the HIPAA Security Rule and the HITECH Act in an attempt to strengthen cybersecurity protections for electronic protected health information…
Holiday Cyber Security Scams: Protecting Your Business During the Festive Season Without Being a Grinch
Blog November 27, 2024
As the holiday season is upon us, businesses must remain vigilant against the increased threat of cybersecurity hacks and scams…
The Federal Communications Commission Updates Its Data Breach Rules
Blog December 26, 2023
On December 21, 2023, the Federal Communications Commission released an order updating its data breach rules.  These updated rules require telecommunications providers to report breaches of customer proprietary network information, such as numbers that have been dialed and when they have been dialed, but also require reporting of personally-identifiable information (PII), such as drivers license numbers, Social Security numbers, and credit card numbers.  The new FCC rules also require……
Massachusetts Extends Protections for Counseling Records of Survivors of Sexual Assault
Blog November 05, 2023
Massachusetts Extends Protections for Counseling Records of Survivors of Sexual Assault The Massachusetts Supreme Judicial Court has ruled in In the Matter of a Motion to Compel, SJC-13336 that the Superior Court could not order a Massachusetts counseling center to turn over, at the behest of a Rhode Island court, counseling records of the alleged minor victim of a sexual assault that occurred in Rhode Island…
Biden Administration Publishes the National Cybersecurity Strategy Implementation Plan
Blog July 25, 2023
On July 13, 2023, the Biden Administration released its National Cybersecurity Strategy Implementation Plan (NCSIP) with the goal of providng transparency and coordination for its existing goals. The NCSIP details more than 65 Federal initiatives (some completed, some ongoing, others planned for the future). Each NCSIP initiative is assigned to a responsible agency and has a timeline for completion. There are five major pillars to the NCSIP: Defending Critical Infrastructure Disrupting……
Privacy and Security of Genetic Information: The FTC Is Putting Privacy and Security Promises of DNA Companies to the Test
Blog June 20, 2023
In the FTC's first case focused on the privacy and security of genetic information, the FTC alleges that San Francisco-based Vitagene, Inc. – now known as 1Health.io – failed to live up to its promises and unfairly changed material privacy terms without customers' consent. After consumers paid between $29 and $259, sent a saliva sample to Vitagene, and answered an online questionnaire about their health history…
CISA and Partners Update the #StopRansomware Guide, Developed through the Joint Ransomware Task Force
Blog May 24, 2023
On May 23, 2023, CISA, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published an updated version of the #StopRansomware Guide, as ransomware actors have accelerated their tactics and techniques since its initial release in 2020. The update incorporates lessons learned from the past two years and includes additional recommended actions…
1 of 30

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors