Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Rising Cyberattacks on U.S. Water Infrastructure: Federal Guidance and Next Steps for Operators
Blog August 17, 2026
Recent guidance issued by Federal agencies warns that malicious cyber actors are targeting internet-facing operational technology (“OT”) used by water and wastewater utilities, particularly PLCs…
When AI Becomes the Hacker: What the OpenAI–Hugging Face Breach Means for Your Organization
Blog July 23, 2026
The disclosure that OpenAI's own AI models autonomously broke out of a sandboxed testing environment and hacked into Hugging Face's production infrastructure is, without exaggeration or hyperbole, a watershed moment for anyone advising on data privacy and cybersecurity…
HHS Unveils Version 3.6 of the Security Risk Assessment Tool: What Covered Entities and Business Associates Need to Know
Blog September 12, 2025
Anyone who has wrestled with the HIPAA Security Rule’s risk‐analysis requirement knows that the government’s free Security Risk Assessment (“SRA”) Tool can be a practical starting point—particularly for resource-constrained practices that cannot justify a commercial governance-risk-and-compliance platform…
Expanded Protections for Reproductive Health and Gender-Affirming Care: What Massachusetts Providers Need to Know
Blog September 04, 2025
On August 7, 2025, Massachusetts Governor Maura Healey signed into law an Act Strengthening Healthcare Protections in the Commonwealth (the “Act”), which amends the state’s existing “Shield Law” protections for providers of reproductive health and gender-affirming care (“Protected Care”)…
DOJ’s “Bulk Sensitive Data Rule” is in Effect, and May Require Significant Compliance Obligations as Enforcement is Set to Begin
Blog June 10, 2025
Pursuant to a newly effective U.S. Department of Justice (DOJ) regulation, the transfer and storage of certain sensitive U.S. government and personal data may be prohibited or restricted, depending on the intended recipient, based on national security risk…
Holiday Cyber Security Scams: Protecting Your Business During the Festive Season Without Being a Grinch
Blog November 27, 2024
As the holiday season is upon us, businesses must remain vigilant against the increased threat of cybersecurity hacks and scams…
HHS-OIG Releases Cybersecurity Toolkit
Blog March 26, 2024
On March 26, 2024, the HHS Office of Inspector General (OIG) released a cybersecurity toolkit for HHS leaders to help them plan and deploy information systems in response to disasters and public health emergencies…
Preparing for and Mitigating Foreign Influence Operations Targeting Critical Infrastructure (i.e., Dealing with the Fallout from Russias Invasion of Ukraine)
Blog February 22, 2022
The Cybersecurity Infrastructure Security Agency (CISA) has just released CISA Insights: Preparing for and Mitigating Foreign Influence Operations Targeting Critical Infrastructure, which provides proactive steps organizations can take to assess and mitigate risks from information manipulation. Malicious actors (i.e., Russia) may use tactics—such as misinformation, disinformation, and malinformation—to shape public opinion, undermine trust, and amplify division, which can lead to impacts……
Data Privacy Day Reflections  Compliance, Governance, Ethics (and AI)
Blog January 28, 2021
January 28 is Data Privacy Day, and on this 14th annual Data Privacy Day, I find myself reflecting on the question of data ethics. Far from being an academic concept, data ethics presents a model for data management with real practical implications for organizations.  (I should note that I am focused here on personal data.)  To understand what the concept might entail, lets take a step back and talk about two other models for data management:  compliance and governance…
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors