Time 5 Minute Read

In December 2024, the Centre for Information Policy Leadership at Hunton Andrews Kurth published a discussion paper titled, “Applying Data Protection Principles to Generative AI: Practical Approaches for Organizations and Regulators.”

Time 2 Minute Read

On December 3, 2024, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced it imposed a $1.19 million civil monetary penalty on Gulf Coast Pain Consultants, LLC d/b/a Clearway Pain Solutions Institute (“Gulf Coast Pain Consultants”) for various HIPAA Security Rule violations, including a failure to terminate former workforce members’ access to systems containing electronic protected health information (“ePHI”).

Time 2 Minute Read

On December 5, 2024, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a penalty of $548,265 against Children’s Hospital Colorado (“CHC”) in connection with a series of alleged data breaches that occurred in 2017 and 2020. In September 2017, CHC reported to OCR a phishing attack that compromised an employee’s email account. OCR’s investigation revealed that the breach occurred because multi-factor authentication was disabled on the employee’s email account. According to OCR, the second breach in April 2020 occurred in part because two workforce members provided unknown third parties with access to their email accounts by accepting a multi-factor authentication access request that neither individual had initiated. OCR also determined that CHC violated the HIPAA Privacy Rule’s requirement to train workforce members on the HIPAA Privacy Rule and the HIPAA Security Rule’s requirements regarding conducting risk analyses to determine the risks and vulnerabilities to ePHI in an organization’s systems.

Time 1 Minute Read

The telehealth and prescription drug discount provider, GoodRx, recently agreed to pay $25 million to settle class action claims originating from the company’s unauthorized disclosure of consumers’ personal health information, according to recent filings with the U.S. District Court for the Northern District of California.

Time 3 Minute Read

On December 6, 2024, the U.S. Court of Appeals for the D.C. Circuit upheld the Protecting Americans from Foreign Adversary Controlled Applications Act, which is set to take effect on January 19, 2025, and make the distribution of TikTok illegal in the U.S. if parent company ByteDance has not divested. The D.C. Circuit is now considering a request for emergency injunction pending Supreme Court review. 

Time 2 Minute Read

On December 3, 2024, the U.S. Federal Trade Commission published a proposed consent order that would settle its investigation into IntelliVision Technologies Corp. for making false, misleading or unsubstantiated claims regarding a lack of gender or racial bias in its AI-powered facial recognition technology.

Time 4 Minute Read

In November 2024, the Department of Commerce’s Artificial Intelligence Safety Institute established a new taskforce to research and test AI models in areas critical to national security and public safety, while ODNI released guidance on the acquisition and use of foundation AI models, both part of the national security community’s response to the directives of the recent White House AI Memo and Executive Order 14110.

Time 2 Minute Read

On December 3, 2024, the European Data Protection Board published its draft Guidelines 02/2024 on Article 48 of the GDPR, which focus on how a controller should act when subject to a judgment or administrative decision requiring the transfer or disclosure of personal data to a public authority in a third country.

Time 6 Minute Read

Patrick Gunning of King & Wood Mallesons reports that on November 29, 2024, the Australian Parliament passed more than 30 bills on the final sitting day for the calendar year. Among the flurry of legislative activity were the Privacy and Other Legislation Amendment Act 2024 and the Online Safety Amendment (Social Media Minimum Age) Act 2024, the latest developments in Australia’s ongoing efforts to update its privacy legislation and address concerns related to children’s privacy.

Time 1 Minute Read

In November 2024, the Federal Trade Commission released a staff perspective paper titled “Smart Device Makers’ Failure to Provide Updates May Leave You Smarting” that reflects on the findings from an FTC survey regarding software updates for smart products. 

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page