Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Why AI Is Forcing Privacy and Security Teams Back Together — And What That Means for Your Organization
Blog May 14, 2026
One of the most consequential structural decisions facing organizations today is whether to continue operating privacy and security as separate functions or to begin integrating them in anticipation of the AI-driven regulatory and operational landscape that is rapidly taking shape…
Robotics and Health Information - Privacy and Security Issues You Need to Know
Blog March 05, 2026
On March 5, 2026, Colin Zick presented to the MassRobotics Healthcare Catalyst Program on the topic, "Robotics and Health Information: Navigating Clinical Deployments in Light of Current Trends in Health Information Privacy and Security."…
System Hardening, HIPAA, and the Practical Path to Protecting ePHI
Blog January 12, 2026
The January 2026 OCR Cybersecurity Newsletter is the U.S. Department of Health and Human Services Office for Civil Rights’ latest installment in its periodic series translating HIPAA Security Rule expectations into practical, operational guidance…
If Your Password Is On This List, Its Time to Change It
Blog June 16, 2023
Its been several years since I have written about password hygeine. I have been hoping that a better security solution would be widely adopted and while I hear rumors in that regard, passwords still reign supreme.  So when I saw that the SafetyDetectives website had listed the 30 most common passwords, it seemed like a good time to revisit the topic.  Their study found that 123456 and password…
HHS Office for Civil Rights Posts HIPAA Security Rule Security Incident Procedures
Blog October 26, 2022
Every October, in recognition of National Cybersecurity Awareness Month, the federal government and its partners work to educate stakeholders on cybersecurity awareness and how best to protect the privacy and security of confidential data. Within the health care industry, the HIPAA Security Rule applies to covered entities and their business associates (“regulated entities”) and electronic protected health information (ePHI).  Because ePHI identifies individuals and includes information……
Requiring Robust Security for Financial Institutions, FTC Finalizes Amendments to Safeguards Rules
Blog November 19, 2021
The Federal Trade Commission has finalized amendments to the Standards for Safeguarding Customer Information (“Safeguards Rule”), specific to defined financial institutions, designed to strengthen security for consumer financial information following a recent uptick in data breaches. The amendments contain four main modifications to the existing Rule that outline additional protections financial institutions must implement when handling sensitive consumer data. First, the amendments……
Biden Issues Memorandum Aimed at Improving Cybersecurity
Blog July 30, 2021
On July 28, 2021, President Biden issued a Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems.  The Memo recognizes that the protection of the nation's critical infrastructure lies not only with government, i.e., at the federal, state, local, tribal, and territorial levels, but with critical infrastructure owners and operators.  In addition, the Memo states that cybersecurity threats to critical infrastructure, and the systems that control and operate it…
The SolarWinds Orion Hack: The Basics You Need to Know
Blog December 20, 2020
By now, you have heard about the SolarWinds Orion hack. But what do you need to know about it? First, if you want or need the technical details, the Cybersecurity and Infrastructure Security Agency (CISA) has them. In particular, on December 13, 2020, CISA released Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise, ordering federal civilian executive branch departments and agencies to disconnect affected devices…
The Equifax/Massachusetts Attorney General Consent Judgment:  A Guide for Privacy and Security Compliance
Blog May 02, 2020
What do businesses need to do to comply with privacy and data security laws?  The first place to look is to relevant statutes.  If you store or process the personal information of Massachusetts residents, then you will at least be subject to the Massachusetts Data Breach Notification Statute and related security regulations.  These are important guides that require certain operational activities, such as maintaining a written information security program…
1 of 8

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors