<?xml version='1.0' encoding='UTF-8'?>
			<?xml-stylesheet type='text/xsl' href='https://www.healthlawadvisor.com/rss.xsl' ?>
			<rss version='2.0' xmlns:content='http://purl.org/rss/1.0/modules/content/'
					xmlns:atom='http://www.w3.org/2005/Atom'
					xmlns:dc='http://purl.org/dc/elements/1.1/'>
				<channel>
					<title>Health Law Advisor - Laws and Regulations Affecting Health Care and Life
Sciences - Featuring HEAL® | Epstein Becker Green</title>
					<link>https://www.healthlawadvisor.com/category/privacy-and-security-law/</link>
					<atom:link href='https://www.healthlawadvisor.com/category/privacy-and-security-law/?rss' rel='self' type='application/rss+xml' />
					<description><![CDATA[The latest updates to Health Law Advisor - Laws and Regulations Affecting Health Care and Life Sciences - Featuring HEAL®.]]></description>
					<lastBuildDate>Fri, 07 Aug 2026 15:36:43 -0700</lastBuildDate>
					
				<item>
				<title>The DOJ’s Bulk Sensitive Data Rule and Your Obligation to “Know Your
Reporting Requirements”</title>
				<link>https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-reporting-requirements</link>
<dc:creator>Elizabeth J. McEvoy, Elena M. Quattrone</dc:creator>
<guid isPermaLink='false'>the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-reporting-requirements</guid>

					<pubDate>Thu, 30 Apr 2026 09:00:01 -0700</pubDate>
					<description><![CDATA[<p>Epstein Becker Green (&ldquo;EBG&rdquo;) has previously advised U.S. organizations that share data in bulk or otherwise grant access to U.S. sensitive data to countries of concern or covered persons to &ldquo;<a href="https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-data">Know Their Data</a>&rdquo; and &ldquo;<a href="https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-vendor">Know Their Vendors</a>.&rdquo; In this post, we discuss why U.S. organizations across all industries with cross-border operations &ndash; including health care / life sciences, finance, e-commerce, and research &ndash; must &ldquo;know their reporting requirements,&rdquo; to fully comply with the BSD Rule and its brand-new reporting obligations. &nbsp;&nbsp;</p>]]></description>
</item>

				<item>
				<title>Fighting Fire with Fire: Project Glasswing and AI-Powered Cyber Defense in
Health Care, Financial Health and Other Critical Infrastructure</title>
				<link>https://www.healthlawadvisor.com/fighting-fire-with-fire-project-glasswing-and-ai-powered-cyber-defense-in-health-care-financial-health-and-other-critical-infrastructure</link>
<dc:creator>Alaap B. Shah, Brian G. Cesaratto, Eleanor T. Chung</dc:creator>
<guid isPermaLink='false'>fighting-fire-with-fire-project-glasswing-and-ai-powered-cyber-defense-in-health-care-financial-health-and-other-critical-infrastructure</guid>

					<pubDate>Tue, 28 Apr 2026 09:00:02 -0700</pubDate>
					<description><![CDATA[<p class="introText">Anthropic&rsquo;s new initiative&mdash;&ldquo;<a href="https://www.anthropic.com/glasswing">Project Glasswing</a>,&rdquo; announced in April 2026&mdash;reflects a significant development in the cybersecurity landscape that should command the immediate attention of every C-suite leader, privacy officer, information security professional, and compliance executive in health care and life sciences, financial services and other critical infrastructure industries, and their legal counsel.</p>]]></description>
</item>

				<item>
				<title>Listen: DOJ’s Bulk Sensitive Data Transfer Rule: Key Insights for Health
Care Compliance Teams – Diagnosing Health Care</title>
				<link>https://www.healthlawadvisor.com/listen-dojs-bulk-sensitive-data-transfer-rule-key-insights-for-health-care-compliance-teams-diagnosing-health-care</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>listen-dojs-bulk-sensitive-data-transfer-rule-key-insights-for-health-care-compliance-teams-diagnosing-health-care</guid>

					<pubDate>Thu, 16 Apr 2026 11:05:00 -0700</pubDate>
					<description><![CDATA[<p>What health care and life sciences organizations need to know:</p>
<ul>
<li><strong>&ldquo;Bulk&rdquo; Has a New Definition: </strong>The volume thresholds under the U.S. Department of Justice&rsquo;s (DOJ&rsquo;s) Bulk Sensitive Data (BSD) Transfer Rule are surprisingly low&mdash;sharing genomic data on just 100 people can trigger compliance requirements, catching many organizations off guard.</li>
<li><strong>HIPAA Compliance Is Not Enough: </strong>The BSD Transfer Rule creates an entirely new compliance layer that goes beyond existing privacy frameworks, such as the Health Insurance Portability and Accountability Act (HIPAA), applying even when data has been de-identified or anonymized.</li>
<li><strong>It&rsquo;s About Access, Not Just Transfers: </strong>Simply giving a foreign vendor, board member, or investor the ability to view sensitive data can trigger the BSD Transfer Rule&mdash;no formal data-sharing agreement is required.</li>
</ul>
<p>In this episode of <em>Diagnosing Health Care</em><sup>&reg;</sup>, Epstein Becker Green attorneys <a href="https://www.ebglaw.com/people/laura-j-deponio">Laura DePonio</a>, <a href="https://www.ebglaw.com/people/elizabeth-j-mcevoy">Elizabeth McEvoy</a>, and <a href="https://www.ebglaw.com/people/elena-m-quattrone">Elena Quattrone</a> walk health care and life sciences organizations through the DOJ&rsquo;s BSD Transfer Rule&mdash;from scoping and compliance to enforcement risks and exemptions.</p>]]></description>
</item>

				<item>
				<title>Diagnostic Imaging Interoperability Request for Information Shines a
Spotlight on the Lack of Patient-Centered Longitudinal Health Records</title>
				<link>https://www.healthlawadvisor.com/diagnostic-imaging-interoperability-request-for-information-shines-a-spotlight-on-the-lack-of-patient-centered-longitudinal-health-records</link>
<dc:creator>Rachel Snyder Good, Karen  Mandelbaum, Elizabeth  Scarola, Alaap B. Shah,
Emily Chi Fogler</dc:creator>
<guid isPermaLink='false'>diagnostic-imaging-interoperability-request-for-information-shines-a-spotlight-on-the-lack-of-patient-centered-longitudinal-health-records</guid>

					<pubDate>Wed, 25 Feb 2026 12:00:00 -0800</pubDate>
					<description><![CDATA[<p>On January 29, 2026, the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (&ldquo;ASTP/ONC&rdquo;) released the <a href="https://isp.healthit.gov/sites/default/files/2026-01/Draft-USCDI-Version-7-January-2026.pdf">Draft United States Core Data for Interoperability Version 7</a> (&ldquo;USCDI v7&rdquo;) for public comment through <a href="https://healthit.gov/standards-and-technology/onc-standards-bulletin/onc-standards-bulletin-2026-1/">Standards Bulletin 2026-1</a>. The very next day, ASTP/ONC also issued a <a href="https://www.govinfo.gov/content/pkg/FR-2026-01-30/pdf/2026-01866.pdf">Request for Information</a> (&ldquo;RFI&rdquo;) seeking public input on the potential adoption of diagnostic imaging interoperability standards and certification criteria under the ONC Health IT Certification Program.</p>]]></description>
</item>

				<item>
				<title>Governing Health AI Development and Adoption: Insights from HHS’s Recently
Announced Strategy to Promote AI in Healthcare</title>
				<link>https://www.healthlawadvisor.com/governing-health-ai-development-and-adoption-insights-from-hhss-recently-announced-strategy-to-promote-ai-in-healthcare</link>
<dc:creator>Alaap B. Shah, Brian G. Cesaratto, Eleanor T. Chung, James A. Boiani</dc:creator>
<guid isPermaLink='false'>governing-health-ai-development-and-adoption-insights-from-hhss-recently-announced-strategy-to-promote-ai-in-healthcare</guid>

					<pubDate>Tue, 13 Jan 2026 09:00:05 -0800</pubDate>
					<description><![CDATA[<p>The Trump Administration continues to pursue a policy of AI dominance, which began with its January 23, 2025 <a href="https://www.federalregister.gov/documents/2025/01/31/2025-02172/removing-barriers-to-american-leadership-in-artificial-intelligence">executive order</a> to remove &ldquo;barriers&rdquo; to Artificial Intelligence (&ldquo;AI&rdquo;) innovation to promote &ldquo;human flourishing, economic competitiveness and national security.&rdquo; On December 11, 2025, the Administration issued another <a href="https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/">executive order</a> announcing a policy to remove state law impediments to adopting a &ldquo;minimally burdensome national standard&rdquo; for AI development and use.</p>]]></description>
</item>

				<item>
				<title>The DOJ’s Bulk Sensitive Data Rule and Your Obligation to “Know Your
Vendor”</title>
				<link>https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-vendor</link>
<dc:creator>Elizabeth J. McEvoy, Elena M. Quattrone</dc:creator>
<guid isPermaLink='false'>the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-vendor</guid>

					<pubDate>Wed, 07 Jan 2026 09:00:06 -0800</pubDate>
					<description><![CDATA[<p><em>This blog post is the latest installment in a series focused on the DOJ&rsquo;s Bulk Sensitive Data Rule, and is intended to help stakeholders navigate the complex rule&rsquo;s requirements and move toward full compliance. </em></p>
<p>Epstein Becker Green&rsquo;s <a href="https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-data">previous blog post</a> on this topic encouraged U.S. organizations across all industries with cross-border operations &ndash; including health care/life sciences, finance, e-commerce, and research &ndash; to &ldquo;know their data.&rdquo;&nbsp; In this post, we discuss why it is critical for these organizations to also &ldquo;know their vendors.&rdquo; We discuss how the BSD Rule imposes new requirements on U.S.-based companies to monitor and scrutinize vendor engagements beyond those with the six designated countries of concern.</p>]]></description>
</item>

				<item>
				<title>Podcast: The Down-Low on Data for Value-Based Enterprises and Their
Participating Providers – Diagnosing Health Care</title>
				<link>https://www.healthlawadvisor.com/podcast-the-down-low-on-data-for-value-based-enterprises-and-their-participating-providers-diagnosing-health-care</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>podcast-the-down-low-on-data-for-value-based-enterprises-and-their-participating-providers-diagnosing-health-care</guid>

					<pubDate>Thu, 11 Dec 2025 10:05:00 -0800</pubDate>
					<description><![CDATA[<p><em>New from the <a target="_blank" title="Visit the Diagnosing Health Care Podcast Episode Page" rel="noopener noreferrer" href="https://www.ebglaw.com/dhc92">Diagnosing Health Care Podcast</a>:&nbsp;</em>Value-based enterprises depend on timely, accurate data, yet the rules that govern how that data moves between <span>the Centers for Medicare &amp; Medicaid Services (</span>CMS<span>)</span>, <span>accoun</span><span>table care organizations</span>, payors, and providers remain complex and often inconsistent.</p>
<p>On this episode, Epstein Becker Green attorneys <a target="_blank" rel="noopener" href="https://www.ebglaw.com/people/kevin-j-malone">Kevin Malone</a>&nbsp;and&nbsp;<a target="_blank" rel="noopener" href="https://www.ebglaw.com/people/karen-mandelbaum">Karen Mandelbaum</a><span> </span>unpack the regulatory frameworks shaping data exchange in value-based care.</p>
<p>They outline how federal privacy laws, CMS rules, <span>the Health Insurance Portability and Accountability Act (</span>HIPAA<span>)</span>, and state requirements intersect; why CMS-sourced data operates under a different regime than Medicare Advantage; and where organizations face the biggest operational hurdles when using, sharing, and governing data across large networks.</p>]]></description>
</item>

				<item>
				<title>The DOJ’s Bulk Sensitive Data Rule and Your Obligation to “Know Your Data”</title>
				<link>https://www.healthlawadvisor.com/the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-data</link>
<dc:creator>Elizabeth J. McEvoy, Lisa Pierce Reisz, Elena M. Quattrone</dc:creator>
<guid isPermaLink='false'>the-dojs-bulk-sensitive-data-rule-and-your-obligation-to-know-your-data</guid>

					<pubDate>Tue, 09 Dec 2025 12:00:00 -0800</pubDate>
					<description><![CDATA[<p>As Epstein Becker &amp; Green, P.C. previously <a href="https://www.ebglaw.com/insights/publications/dojs-final-rule-on-bulk-data-transfers-a-road-map">reported</a>, the National Security Division of the U.S. Department of Justice (&ldquo;DOJ&rdquo;) issued a final rule, effective on April 8, 2025, called the Bulk Sensitive Data Rule (&ldquo;BSD Rule&rdquo;) (codified at 28 C.F.R. Part 202), which prohibits and/or restricts U.S. persons and/or companies from engaging in certain transactions involving certain categories of government-related data and sensitive personal data with covered persons or six countries of concern&ndash; China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela.</p>]]></description>
</item>

				<item>
				<title>NYDFS Cybersecurity Crackdown: New Requirements Now in Force, and "Covered
Entities" Include HMOs, CCRCs—Are You Compliant?</title>
				<link>https://www.healthlawadvisor.com/nydfs-cybersecurity-crackdown-new-requirements-now-in-force-and-covered-entities-include-hmos-ccrcs-are-you-compliant</link>
<dc:creator>Frances M. Green, Alexander C.B. Barnard</dc:creator>
<guid isPermaLink='false'>nydfs-cybersecurity-crackdown-new-requirements-now-in-force-and-covered-entities-include-hmos-ccrcs-are-you-compliant</guid>

					<pubDate>Wed, 26 Nov 2025 14:30:00 -0800</pubDate>
					<description><![CDATA[<p>As cybersecurity breaches grow more complex and frequent, regulators are increasingly focused on organizational compliance. Organizations such as <a href="https://www.crowdstrike.com/en-us/global-threat-report/">Crowdstrike report that in 2025,</a> cyberattacks are increasing in speed, volume, and sophistication&mdash;and cybercrime has evolved as a &ldquo;highly efficient business.&rdquo; The escalating threat landscape demands robust security frameworks that can withstand evolving risks.</p>
<p>Enter the amendments announced in November 2023 to the New York&rsquo;s Department of Financial Services (NYDFS) Cybersecurity Regulation, 23 NYCRR Part 500 (&ldquo;Amended Regulation&rdquo;), that became effective on November 1. This post explores the breadth of these Amended Regulations, and the steps that covered entities need to take now.</p>]]></description>
</item>

				<item>
				<title>DOJ Subpoena Seeks Health Information of Hospital Patients Receiving
Gender-Affirming Care: Will Judge Grant Motion to Quash?</title>
				<link>https://www.healthlawadvisor.com/doj-subpoena-seeks-health-information-of-hospital-patients-receiving-gender-affirming-care-will-judge-grant-motion-to-quash</link>
<dc:creator>Eric J. Neiman, Elena M. Quattrone</dc:creator>
<guid isPermaLink='false'>doj-subpoena-seeks-health-information-of-hospital-patients-receiving-gender-affirming-care-will-judge-grant-motion-to-quash</guid>

					<pubDate>Fri, 14 Nov 2025 11:01:00 -0800</pubDate>
					<description><![CDATA[<p>On June 12, 2025, the Children&rsquo;s Hospital of Philadelphia (&ldquo;CHOP&rdquo;) received a subpoena issued by the Department of Justice (&ldquo;DOJ&rdquo;) requesting highly sensitive patient health and procedure information related to gender-affirming care. These subpoenas, <a href="https://www.justice.gov/opa/pr/department-justice-subpoenas-doctors-and-clinics-involved-performing-transgender-medical">issued to multiple hospitals, doctors, and clinics,</a> were directly related to the Trump Administration&rsquo;s January 28, 2025, Executive Order entitled, <a href="https://www.federalregister.gov/documents/2025/02/03/2025-02194/protecting-children-from-chemical-and-surgical-mutilation">&ldquo;Protecting Children from Chemical and Surgical Mutilation&rdquo; (&ldquo;EO 14187&rdquo;).</a> &nbsp;The subpoena to CHOP has resulted in recent court activity over its purpose and enforceability.&nbsp;</p>]]></description>
</item>

				<item>
				<title>Podcast: 42 CFR Part 2 Final Rule: What’s Changing and What Do You Need to
Know? – Diagnosing Health Care</title>
				<link>https://www.healthlawadvisor.com/podcast-42-cfr-part-2-final-rule-whats-changing-and-what-do-you-need-to-know-diagnosing-health-care</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>podcast-42-cfr-part-2-final-rule-whats-changing-and-what-do-you-need-to-know-diagnosing-health-care</guid>

					<pubDate>Thu, 13 Nov 2025 10:05:00 -0800</pubDate>
					<description><![CDATA[<p><em>New from the <a target="_blank" title="Visit the Diagnosing Health Care Podcast Episode Page" rel="noopener noreferrer" href="https://www.ebglaw.com/dhc91">Diagnosing Health Care Podcast</a>:&nbsp;</em>By early 2026, substance use disorder (SUD) providers, health plans, clinicians, health information exchanges (HIEs), and vendors must meet new federal privacy standards for SUD treatment records or face Health Insurance Portability and Accountability Act (HIPAA)-level enforcement and penalties.</p>
<p>On this episode, Epstein Becker Green attorneys <a href="https://www.ebglaw.com/people/lisa-pierce-reisz">Lisa Pierce Reisz</a>, <a href="https://www.ebglaw.com/people/david-shillcutt">David Shillcutt</a>, and <a href="https://www.ebglaw.com/people/laura-j-deponio">Laura DePonio</a>&nbsp;join <strong>Nichole Sweeney,</strong> General Counsel and Chief Privacy Officer at <a href="https://www.crisphealth.org/">CRISP</a>, to break down the 42 CFR Part 2 final rule: what&rsquo;s changing, what&rsquo;s staying the same, and what organizations often miss.</p>
<p>The group explains how the final rule aligns with (but does not replace) HIPAA, why patient consent remains central, and what new operational risks are emerging.</p>
<p>Tune in to learn about the changes that matter most and the risks you can&rsquo;t ignore.<a href="https://www.ebglaw.com/subscribe."></a></p>]]></description>
</item>

				<item>
				<title>DOJ’s Final Rule on Bulk Data Transfers: The First 180 Days</title>
				<link>https://www.healthlawadvisor.com/dojs-final-rule-on-bulk-data-transfers-the-first-180-days</link>
<dc:creator>Elizabeth J. McEvoy</dc:creator>
<guid isPermaLink='false'>dojs-final-rule-on-bulk-data-transfers-the-first-180-days</guid>

					<pubDate>Fri, 10 Oct 2025 15:00:00 -0700</pubDate>
					<description><![CDATA[<p>Well before the latest government shutdown, the U.S. Department of Justice&rsquo;s National Security Division (DOJ NSD) issued a <a href="https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern">final rule at 28 CFR Part 202</a> (&ldquo;2025 Final Rule&rdquo; or &ldquo;Rule&rdquo;) to help prevent &ldquo;countries of concern&rdquo; or &ldquo;covered persons&rdquo; from accessing U.S. government-related data and Americans&rsquo; bulk sensitive personal data. The 2025 Final Rule took effect in April&mdash;and after a 90-day safe harbor period, the DOJ began enforcement on July 8.</p>
<p>Six months after implementation&mdash;with the U.S. Senate now passing the BIOSECURE Act <a href="https://www.cnbctv18.com/india/healthcare/explained-the-us-biosecure-act-and-implications-for-indias-pharma-sector-ws-e-19710909.htm">restricting certain biotech business with China</a>&mdash;compliance remains the key for affected stakeholders, including those exchanging personal health data. <a href="https://www.ebglaw.com/insights/publications/dojs-final-rule-on-bulk-data-transfers-a-road-map">As we reported in July</a>, the 2025 Final Rule implemented the prior administration&rsquo;s <a href="https://www.federalregister.gov/documents/2024/03/01/2024-04573/preventing-access-to-americans-bulk-sensitive-personal-data-and-united-states-government-related">Executive Order 14117 of February 28, 2024</a>, by prohibiting and restricting &ldquo;bulk&rdquo; data transactions with countries that could threaten U.S. national security through the use of Americans&rsquo; sensitive personal data.</p>
<p>While the 2025 Final Rule remains largely untested, federal agencies and stakeholders alike have taken action to test the bounds of the Rule and, in some instances, expand applicability beyond 28 CFR Part 202. Below is a brief refresher of the key elements of the Rule and some recent developments.</p>]]></description>
</item>

				<item>
				<title>Novel Lawsuits Allege AI Chatbots Encouraged Minors’ Suicides, Mental
Health Trauma: Considerations for Stakeholders</title>
				<link>https://www.healthlawadvisor.com/novel-lawsuits-allege-ai-chatbots-encouraged-minors-suicides-mental-health-trauma-considerations-for-stakeholders</link>
<dc:creator>Alaap B. Shah, Frances M. Green, James A. Boiani, Eleanor T. Chung</dc:creator>
<guid isPermaLink='false'>novel-lawsuits-allege-ai-chatbots-encouraged-minors-suicides-mental-health-trauma-considerations-for-stakeholders</guid>

					<pubDate>Tue, 07 Oct 2025 10:30:00 -0700</pubDate>
					<description><![CDATA[<p>In the wake of a lawsuit filed in federal district court in California in August&mdash;alleging that an artificial intelligence (AI) chatbot encouraged a 16-year-old boy to commit suicide&mdash;a similar suit filed in September is now claiming that an AI chatbot is responsible for death of a 13-year-old girl.</p>
<p>It&rsquo;s the latest development illustrating a growing tension between AI&rsquo;s promise to improve access to mental health support and the alleged perils of unhealthy reliance on AI chatbots by vulnerable individuals. This tension is evident in recent reports that some users, particularly minors, are becoming addicted to AI chatbots, causing them to sever ties with supportive adults, lose touch with reality and, in the worst cases, engage in self-harm or harm to others.</p>
<p>While not yet reflected in diagnostic manuals, experts are recognizing the phenomenon of <a href="https://www.pbs.org/newshour/show/what-to-know-about-ai-psychosis-and-the-effect-of-ai-chatbots-on-mental-health">&ldquo;AI psychosis&rdquo;</a>&mdash;distorted thoughts or delusional beliefs triggered by interactions with AI chatbots. According to <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">Psychology Today,</a> the term describes cases in which AI models have amplified, validated, or even co-created psychotic symptoms with individuals. <a href="https://www.pbs.org/newshour/show/what-to-know-about-ai-psychosis-and-the-effect-of-ai-chatbots-on-mental-health">Evidence indicates</a> that AI psychosis can develop in people with or without a preexisting mental health issue, although the former is more common.</p>]]></description>
</item>

				<item>
				<title>DOJ False Claims Act Priorities: Cybersecurity Is Still on the Radar</title>
				<link>https://www.healthlawadvisor.com/doj-false-claims-act-priorities-cybersecurity-is-still-on-the-radar</link>
<dc:creator>George B. Breen</dc:creator>
<guid isPermaLink='false'>doj-false-claims-act-priorities-cybersecurity-is-still-on-the-radar</guid>

					<pubDate>Mon, 08 Sep 2025 11:25:00 -0700</pubDate>
					<description><![CDATA[<p>By the third quarter of 2025, the Department of Justice (DOJ) has made plain that it will continue using the False Claims Act (FCA) to advance administration priorities.</p>
<p>While the focus on diversity, equity, and inclusion (DEI)&mdash;addressed in our <a href="https://www.healthlawadvisor.com/from-best-practices-to-enforcement-decoding-dojs-july-29-anti-discrimination-guidance">August 8 post</a>&mdash;continues to make headlines, DOJ is not taking its eye off cybersecurity. Two settlements announced in late July, totaling approximately $11.5 million, reinforce that noncompliance with cybersecurity obligations can trigger FCA exposure.</p>]]></description>
</item>

				<item>
				<title>Gender-Affirming Care Protections Eroded by Recent HHS Guidance and White
House Executive Orders</title>
				<link>https://www.healthlawadvisor.com/gender-affirming-care-protections-eroded-by-recent-hhs-guidance-and-white-house-executive-orders</link>
<dc:creator>Alaap B. Shah, Lisa Pierce Reisz</dc:creator>
<guid isPermaLink='false'>gender-affirming-care-protections-eroded-by-recent-hhs-guidance-and-white-house-executive-orders</guid>

					<pubDate>Mon, 17 Mar 2025 16:00:00 -0700</pubDate>
					<description><![CDATA[<p>On February 20, 2025, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced the recission of &ldquo;HHS Notice and Guidance on Gender Affirming Care, Civil Rights, and Patient Privacy&rdquo; (the &ldquo;Rescinded 2022 Guidance&rdquo;) pursuant to recent <a href="https://www.federalregister.gov/documents/2025/02/03/2025-02194/protecting-children-from-chemical-and-surgical-mutilation">Executive Order (&ldquo;EO&rdquo;) 14187 (&ldquo;Protecting Children from Chemical and Surgical Mutilation&rdquo;)</a> and <a href="https://www.federalregister.gov/documents/2025/01/30/2025-02090/defending-women-from-gender-ideology-extremism-and-restoring-biological-truth-to-the-federal">EO 14168 (&ldquo;Defending Women from Gender Ideology Extremism and Restoring Biological Truth to the Federal Government&rdquo;)</a>, issued under the current Trump administration. These executive orders directed HHS to revoke policies promoting gender-affirming care and reconsider its interpretation of civil rights protections and health information privacy laws as they relate to such care.</p>
<h2>Background on the Rescinded 2022 Guidance</h2>
<p>The Rescinded 2022 Guidance, originally issued on March 2, 2022 under the Biden administration, and which we previously discussed <a href="https://www.ebglaw.com/insights/podcasts/unveiling-gender-affirming-care-why-it-matters-and-whats-at-stake">here</a>, established a framework for applying federal civil rights protections and patient privacy laws to gender-affirming care in three key ways:</p>]]></description>
</item>

				<item>
				<title>Proposed Modernization of the HIPAA Security Rules</title>
				<link>https://www.healthlawadvisor.com/proposed-modernization-of-the-hipaa-security-rules</link>
<dc:creator>Brian G. Cesaratto, Lisa Pierce Reisz, Alaap B. Shah</dc:creator>
<guid isPermaLink='false'>proposed-modernization-of-the-hipaa-security-rules</guid>

					<pubDate>Fri, 31 Jan 2025 16:47:00 -0800</pubDate>
					<description><![CDATA[<p>The HIPAA Security Rule was originally promulgated over 20 years ago. While it historically provided an important regulatory floor for securing electronic protected health information, the Security Rule&rsquo;s lack of prescriptiveness, combined with advances in technology and evolution of the cybersecurity landscape, increasingly indicate the HIPAA Security Rule neither reflects cybersecurity best practices nor effectively mitigates the proliferation of cyber risks in today&rsquo;s interconnected digital world.&nbsp; On December 27, 2024, the HHS Office of Civil Rights (&ldquo;OCR&rdquo;) announced a <span><a href="https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information">Notice of Proposed Rulemaking</a></span>, including significant changes to strengthen the HIPAA Security Rule (the &ldquo;Proposed Rule&rdquo;).&nbsp; In its announcement, OCR stated that the Proposed Rule seeks to &ldquo;strengthen cybersecurity by updating the Security Rule&rsquo;s standards to better address ever-increasing cybersecurity threats to the health care sector.&rdquo;&nbsp; One key aim of the Proposed Rule is to provide a much clearer roadmap to achieve Security Rule compliance.</p>
<p>The Proposed Rule contains significant textual modifications to the current HIPAA Security Rule.&nbsp; While the actual redline changes may appear daunting, the proposed new requirements are aimed at aligning with current cybersecurity best practices as reflected across risk management frameworks, including <span><a href="https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20">NIST&rsquo;s Cybersecurity Framework</a></span>.&nbsp; For organizations that have already adopted these &ldquo;best practices&rdquo;, many of the new Proposed Rule requirements will be familiar and, in many cases, will have already been implemented.&nbsp; Indeed, for such organizations, the biggest challenge will be to comply with the new administrative requirements, which will involve policy updates, updates to business associate agreements, increased documentation rules (including mapping requirements), and the need for additional vendor management.&nbsp; For organizations that are still trying to meaningfully comply with the existing HIPAA Security Rule, or that seek to extend the Rule&rsquo;s application to new technologies and systems handling PHI, the Proposed Rule will likely require significant investment of human and financial resources to meet the new requirements.</p>]]></description>
</item>

				<item>
				<title>Recent Developments in Health Care Cybersecurity and Oversight: 2024 Wrap
Up and 2025 Outlook</title>
				<link>https://www.healthlawadvisor.com/recent-developments-in-health-care-cybersecurity-and-oversight-2024-wrap-up-and-2025-outlook</link>
<dc:creator>Alaap B. Shah, Brian G. Cesaratto, Laura J. DePonio</dc:creator>
<guid isPermaLink='false'>recent-developments-in-health-care-cybersecurity-and-oversight-2024-wrap-up-and-2025-outlook</guid>

					<pubDate>Thu, 16 Jan 2025 11:15:00 -0800</pubDate>
					<description><![CDATA[<p>As Cyberattacks targeting the health care sector have continued to intensify over the past year, including ransomware attacks that have resulted in major data breaches impacting health care organizations, the protection of health data has gained the focus of regulators and prompted bipartisan legislative efforts to strengthen cybersecurity requirements in the health care sector.</p>
<h2>OIG Report on OCR&rsquo;s HIPAA Audit Program</h2>
<p>Under the Health Information Technology for Economic and Clinical Health Act (HITECH), the HHS Office for Civil Rights (OCR) is required to perform periodic audits of covered entities and business associates (collectively, Regulated Entities) to assess compliance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules (collectively, &ldquo;HIPAA Rules&rdquo;).</p>
<p>Last month, the HHS Office of Inspector General (OIG) released a <a href="https://oig.hhs.gov/reports/all/2024/the-office-for-civil-rights-should-enhance-its-hipaa-audit-program-to-enforce-hipaa-requirements-and-improve-the-protection-of-electronic-protected-health-information/">new report</a> assessing OCR&rsquo;s HIPAA audit program, raising concerns about the effectiveness of current oversight and the need for enhanced measures to address growing cybersecurity risks in the sector. In its assessment of OCR&rsquo;s HIPAA audit program, OIG reviewed OCR&rsquo;s final HIPAA audit reports of Regulated Entities, guidance, and enforcement activities from January 2016 to December 2020.</p>]]></description>
</item>

				<item>
				<title>OCR Withdraws Appeal of District Court Order Declaring Unlawful and
Vacating the “Proscribed Combination” Portion of Its HIPAA Online Tracking
Technologies Guidance</title>
				<link>https://www.healthlawadvisor.com/ocr-withdraws-appeal-of-district-court-order-declaring-unlawful-and-vacating-the-proscribed-combination-portion-of-its-hipaa-online-tracking-technologies-guidance</link>
<dc:creator>Brian G. Cesaratto, Laura J. DePonio, Alaap B. Shah, Patricia (Trish) M.
Wagner</dc:creator>
<guid isPermaLink='false'>ocr-withdraws-appeal-of-district-court-order-declaring-unlawful-and-vacating-the-proscribed-combination-portion-of-its-hipaa-online-tracking-technologies-guidance</guid>

					<pubDate>Mon, 07 Oct 2024 11:18:00 -0700</pubDate>
					<description><![CDATA[<p>On March 18, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) <a href="https://www.healthlawadvisor.com/revised-ocr-guidance-provides-new-examples-but-raises-more-questions-regarding-use-of-online-tracking-technologies-by-hipaa-covered-entities-and-business-associates">issued updated guidance</a> regarding the use of online tracking technologies by entities and business associates subject to the Health Insurance Portability and Accountability Act of 1996 (&ldquo;HIPAA&rdquo;).</p>
<p>The <a href="https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html">updated guidance</a> replaced <a href="https://www.healthlawadvisor.com/hhs-warns-hipaa-covered-entities-and-business-associates-that-use-of-website-cookies-pixels-and-other-tracking-technology-may-violate-hipaa-rules">OCR&rsquo;s original guidance issued in December 2022</a>, both of which warn companies subject to HIPAA, Covered Entities and their Business Associates (collectively &ldquo;Regulated Entities&rdquo;), that use of online tracking technologies, such as cookies and pixels, may result in the impermissible disclosure of Protected Health Information (&ldquo;PHI&rdquo;) to third parties in violation of HIPAA, including &ldquo;individually identifiable health information&rdquo; (&ldquo;IIHI&rdquo;). The guidance explained that covered entities&rsquo; HIPAA obligations are triggered where an online tracking technology connects an individual&rsquo;s IP address with a visit to an unauthenticated public webpage addressing specific health conditions or health care providers (the &ldquo;Proscribed Combination&rdquo;).</p>]]></description>
</item>

				<item>
				<title>Video: New HIPAA Final Rule - Key Changes to Reproductive Health Care
Privacy – Thought Leaders in Health Law</title>
				<link>https://www.healthlawadvisor.com/video-new-hipaa-final-rule-key-changes-to-reproductive-health-care-privacy-thought-leaders-in-health-law</link>
<dc:creator></dc:creator>
<guid isPermaLink='false'>video-new-hipaa-final-rule-key-changes-to-reproductive-health-care-privacy-thought-leaders-in-health-law</guid>

					<pubDate>Tue, 24 Sep 2024 16:00:00 -0700</pubDate>
					<description><![CDATA[<p><em>From our <a target="_blank" title="View the Thought Leaders in Health Law series" rel="noopener" href="https://www.ebglaw.com/videos-podcasts/thought-leaders-in-health-law">Thought Leaders in Health Law video series</a>:&nbsp;</em>The U.S. Supreme Court&rsquo;s 2022 decision in&nbsp;<em>Dobbs v. Jackson Women&rsquo;s Health Organization</em>&nbsp;to eliminate the federal constitutional right to abortion continues to alter the legal landscape across the country.</p>
<p>On April 26, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights published a final rule entitled the &ldquo;<a href="https://www.govinfo.gov/content/pkg/FR-2024-04-26/pdf/2024-08503.pdf">HIPAA Privacy Rule to Support Reproductive Health Care Privacy</a>&rdquo; (the &ldquo;Final Rule&rdquo;).</p>
<p>The Final Rule&mdash;amending the Standards for Privacy of Individually Identifiable Health Information (the &ldquo;Privacy Rule&rdquo;) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009&mdash;strengthens privacy protections related to the use and disclosure of reproductive health care information. HIPAA&rsquo;s Privacy Rule limits the disclosure of protected health information (PHI) and is part of HHS&rsquo;s efforts to ensure that patients will not be afraid to seek health care from, or share important information with, health care providers.</p>
<p>What are the key takeaways from the Final Rule?</p>]]></description>
</item>

				<item>
				<title>Consumer Privacy Update: What Organizations Need to Know About Impending
State Privacy Laws Going into Effect in 2024 and 2025</title>
				<link>https://www.healthlawadvisor.com/consumer-privacy-update-what-organizations-need-to-know-about-impending-state-privacy-laws-going-into-effect-in-2024-and-2025</link>
<dc:creator>Alaap B. Shah, Audrey  Davis</dc:creator>
<guid isPermaLink='false'>consumer-privacy-update-what-organizations-need-to-know-about-impending-state-privacy-laws-going-into-effect-in-2024-and-2025</guid>

					<pubDate>Fri, 13 Sep 2024 14:45:00 -0700</pubDate>
					<description><![CDATA[<p>Over the past several years, the number of states with comprehensive consumer data privacy laws has increased exponentially from just a handful&mdash;California, Colorado, Virginia, Connecticut, and Utah&mdash;to up to twenty by some counts. Many of these state laws will go into effect starting Q4 of 2024 through 2025. We have previously written in more detail on <a href="https://www.healthlawadvisor.com/new-jersey-passes-comprehensive-consumer-privacy-law">New Jersey</a>&rsquo;s comprehensive data privacy law, which goes into effect January 15, 2025, and <a href="https://www.healthlawadvisor.com/patchwork-of-state-data-privacy-laws-adds-three-new-patches">Tennessee</a>&rsquo;s comprehensive data privacy law, which goes into effect July 1, 2025. Some laws have already gone into effect, like <a href="https://capitol.texas.gov/tlodocs/88R/billtext/html/HB00004F.htm">Texas&rsquo;s Data Privacy and Security Act</a>, and <a href="https://olis.oregonlegislature.gov/liz/2023R1/Downloads/MeasureDocument/SB619/Enrolled">Oregon&rsquo;s Consumer Privacy Act</a>, both of which became effective July of 2024. Now is a good time to take stock of the current landscape as the next batch of state privacy laws go into effect.&nbsp;</p>
<p>Over the next year, the following laws will become effective:</p>
<ol>
<li><a href="https://leg.mt.gov/bills/2023/billpdf/SB0384.pdf">Montana Consumer Data Privacy Act</a> (effective Oct. 1, 2024)</li>
<li><a href="https://legis.delaware.gov/BillDetail?LegislationId=140388">Delaware Personal Data Privacy Act</a> (effective Jan. 1, 2025)</li>
<li><a href="https://www.legis.iowa.gov/legislation/BillBook?ga=90&amp;ba=SF262">Iowa Consumer Data Protection Act</a> (effective Jan. 1, 2025)</li>
<li><a href="https://nebraskalegislature.gov/FloorDocs/108/PDF/Slip/LB1074.pdf">Nebraska Data Privacy Act</a> (effective Jan. 1, 2025)</li>
<li><a href="https://gencourt.state.nh.us/bill_status/billinfo.aspx?id=865&amp;inflect=1">New Hampshire Privacy Act</a> (effective Jan. 1, 2025)</li>
<li><a href="https://pub.njleg.state.nj.us/Bills/2022/S0500/332_R6.PDF">New Jersey Data Privacy Act</a> (effective Jan. 15, 2025)</li>
<li><a href="https://publications.tnsosfiles.com/acts/113/pub/pc0408.pdf">Tennessee Information Protection Act</a> (effective July 1, 2025)</li>
<li><a href="https://www.revisor.mn.gov/bills/text.php?number=HF4757&amp;type=bill&amp;version=4&amp;session=ls93&amp;session_year=2024&amp;session_number=0">Minnesota Consumer Data Privacy Act</a> (effective July 31, 2025)</li>
<li><a href="https://mgaleg.maryland.gov/2024RS/bills/sb/sb0541T.pdf">Maryland Online Data Privacy Act</a> (effective Oct. 1, 2025)</li>
</ol>
<p>These nine state privacy laws contain many similarities, broadly conforming to the Virginia Consumer Data Protection Act we discussed <a href="https://www.healthlawadvisor.com/where-is-the-tipping-point-comprehensive-state-privacy-law-update">here</a>.&nbsp; All nine laws listed above contain the following familiar requirements:</p>]]></description>
</item>

			</channel></rss>