Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
When AI Becomes the Hacker: What the OpenAI–Hugging Face Breach Means for Your Organization
Blog July 23, 2026
The disclosure that OpenAI's own AI models autonomously broke out of a sandboxed testing environment and hacked into Hugging Face's production infrastructure is, without exaggeration or hyperbole, a watershed moment for anyone advising on data privacy and cybersecurity…
The Health Sector Cybersecurity Coordination Center’s September 19 Threat Briefing on Healthcare Technology Security
Blog September 19, 2024
In a joint September 19, 2024 presentation, the Department of Health and Human Services’ Office of Technology and the Health Sector Cybersecurity Coordination Center explored key concepts and definitions, examined various technologies, electronic records systems, medical devices, and AI, and discussed defense and mitigation strategies that sophisticated compliance personnel must consider…
Massachusetts Attorney General Announces Breach Resources for Consumers Impacted by Change Healthcare Breach
Blog July 15, 2024
The Massachusetts Attorney General’s Office issued an announcement last week to inform consumers who may have had their personal information breached in Change Healthcare’s cyberattack this past February. The AGO was joined by a bipartisan group of state attorneys general in sharing these consumer protection resources…
AT&T/Snowflake Breach Hits Most of US - Vendor Exposure Strikes Again
Blog July 15, 2024
AT&T Inc. announced in a July 12, 2024, SEC filing that hackers stole a cache of six months’ worth of mobile phone customer data, illegally downloading the records from a workspace account at the cloud-service provider Snowflake Inc…
In Wake of Healthcare System Cyberattack, 22 State Attorneys General Call for Further Action on Data Privacy
Blog May 06, 2024
On April 25, 2024, the attorneys general of 22 states issued a letter encouraging UnitedHealth Group and its subsidiary, Change Healthcare, to take additional steps to respond to a massively disruptive cyberattack. The broad, bipartisan group of signatories reflects both the scale of the attack’s impact and its implications for the priorities of state attorneys general—from healthcare regulation to data privacy, consumer protection, and even antitrust concerns…
FTC's Updated Health Data Breach Rule Covers Apps, Other New Tech
Blog April 29, 2024
The FTC’s Health Breach Notification Rule (HBNR) was originally adopted in 2009 and applies to entities that handle personal health records (PHR), records that are not Protected Health Information (PHI) covered by the Health Insurance Portability and Accountability Act (HIPAA).  The FTC has updated its HBNR to clarify that the rule also restricts marketing practices involving personal health information…
The Federal Communications Commission Updates Its Data Breach Rules
Blog December 26, 2023
On December 21, 2023, the Federal Communications Commission released an order updating its data breach rules.  These updated rules require telecommunications providers to report breaches of customer proprietary network information, such as numbers that have been dialed and when they have been dialed, but also require reporting of personally-identifiable information (PII), such as drivers license numbers, Social Security numbers, and credit card numbers.  The new FCC rules also require……
Your Password Cant Possibly Be This Bad, Can It?
Blog November 19, 2023
NordPass (the purveyor of a password manager) has assembled a list of the top 20 passwords in healthcare, based on usage by the worlds largest companies…
If Your Password Is On This List, Its Time to Change It
Blog June 16, 2023
Its been several years since I have written about password hygeine. I have been hoping that a better security solution would be widely adopted and while I hear rumors in that regard, passwords still reign supreme.  So when I saw that the SafetyDetectives website had listed the 30 most common passwords, it seemed like a good time to revisit the topic.  Their study found that 123456 and password…
1 of 27

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors