The Office of the Attorney General of Washington (the “AG”) has updated the Frequently Asked Questions (the “FAQs”) for the Washington My Health My Data Act (the “Act” or “Washington Act”) to provide guidance on the AG’s position concerning whether … [Read more] about Washington AG’s Office Updates FAQs for My Health My Data Act
NYDFS Releases Industry Letter on the Use of Self-Service Password Reset Feature
On January 12, 2024, the New York State Department of Financial Services (“NYDFS”) released a new Industry Letter on the use of self-service password reset (“SSPR”) services, which enable users to reset their own password without the assistance of … [Read more] about NYDFS Releases Industry Letter on the Use of Self-Service Password Reset Feature
Making (Brain) Waves: New Colorado Legislation Poised to Protect Privacy of Neural Data
Neurotechnology, like wearable EEG headbands and invasive brain implants, collects information from electrical nerve impulses and brain waves derived from your brain, spinal cord, or nervous system. This information, or neurodata, is valuable, … [Read more] about Making (Brain) Waves: New Colorado Legislation Poised to Protect Privacy of Neural Data
NY AG’s Office Announces Significant Cybersecurity Settlement with Healthcare Company
On January 5, 2024, the New York Attorney General’s Office (“NY AG”) announced a settlement with Refuah Health Center, Inc. (“Refuah”) based on the company’s alleged failures to appropriately safeguard its patients’ information, including failing to … [Read more] about NY AG’s Office Announces Significant Cybersecurity Settlement with Healthcare Company
Are You Using EU Standard Contractual Clauses for Data Transfers? Be Aware of these Breach Notification Requirements
It has become common knowledge that the General Data Protection Regulation (2016/679) (GDPR) heavily restricts transfers of personal data outside of the European Union (EU). In the absence of an adequacy decision by the European Commission, the GDPR … [Read more] about Are You Using EU Standard Contractual Clauses for Data Transfers? Be Aware of these Breach Notification Requirements