by Ilan Jenkins | Jan 14, 2025 | Cybersecurity, Health Information, HIPAA, Regulators, United States, US HHS
Always a crowd favorite when negotiating Business Associate Agreements and Data Processing Agreements alike, breach notification periods almost always generate lively discussion. One party wants “immediate” notification of data breaches; one says it can...
by Ilan Jenkins | Mar 25, 2024 | Data Retention, Europe, GDPR, Policies, Regulators, United States
I’ve previously posted about data retention being one of the hardest data privacy compliance tasks for organizations to complete. This holds true for organizations large and small in all sectors. Finding your data, cataloging it, deciding on retention periods,...
by Ilan Jenkins | Aug 28, 2023 | Ad Tech, Artificial Intelligence, CFPB, Credit Data, FCRA, FTC, Regulators, United States
Consumer Financial Protection Bureau Director Rohit Chopra recently announced a rulemaking that would apply the Fair Credit Reporting Act to certain data brokers. The CFPB also published an FAQ with background related to this announcement. The FCRA applies to credit...
by Ilan Jenkins | Aug 2, 2023 | Colorado, Oregon, Regulators, State Privacy Laws, United States
On July 12th, the Colorado Attorney General’s office announced its enforcement of the Colorado Privacy Act (“CPA”) with a bang by sending out informational letters to companies and publishing a tranche of compliance resources. The letters were not...
by Ilan Jenkins | Jul 26, 2023 | Ad Tech, FTC, HIPAA, Regulators, Technology, United States, US HHS
The Federal Trade Commission and US Dept. of Health and Human Services Office for Civil Rights sent 130 hospital system and telehealth providers a letter reminding them of their responsibilities related to processing health data, both under HIPAA and other laws. The...