Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Rising Cyberattacks on U.S. Water Infrastructure: Federal Guidance and Next Steps for Operators
Blog August 17, 2026
Recent guidance issued by Federal agencies warns that malicious cyber actors are targeting internet-facing operational technology (“OT”) used by water and wastewater utilities, particularly PLCs…
When AI Becomes the Hacker: What the OpenAI–Hugging Face Breach Means for Your Organization
Blog July 23, 2026
The disclosure that OpenAI's own AI models autonomously broke out of a sandboxed testing environment and hacked into Hugging Face's production infrastructure is, without exaggeration or hyperbole, a watershed moment for anyone advising on data privacy and cybersecurity…
The White House's "Gold Eagle" Cybersecurity Initiative: More Branding Than Breakthrough?
Blog July 20, 2026
On July 14, the White House announced the launch of "Gold Eagle," a new federal government-industry clearinghouse for coordinating cybersecurity vulnerability detection and remediation across critical infrastructure…
Business Email Compromises: Current Legal Trends and Key Strategies
Blog April 03, 2026
Businesses have for years suffered from a sophisticated, targeted cybercrime that exploits trust, human relationships, and our reliance on digital communication: the business email compromise (BEC)…
System Hardening, HIPAA, and the Practical Path to Protecting ePHI
Blog January 12, 2026
The January 2026 OCR Cybersecurity Newsletter is the U.S. Department of Health and Human Services Office for Civil Rights’ latest installment in its periodic series translating HIPAA Security Rule expectations into practical, operational guidance…
Lessons on Protecting Your Company’s Crown Jewels – Do a Better Job than the Louvre Did Protecting Its Crown Jewels
Blog November 11, 2025
The Louvre is synonymous with cultural excellence. That’s what makes the recent heist of crown jewels—and the subsequent state audit—so jarring. This wasn’t a Hollywood caper. It was a case study in how predictable, preventable security failures accumulate over time when leadership choices systematically favor the visible over the vital…
U.S. House Report Addresses AI Concerns, Including Privacy and Data Security
Blog December 31, 2024
On December 17, 2024, just before leaving town until the new session of Congress, the U.S. House of Representatives’ Bipartisan Artificial Intelligence Task Force issued a “Report on Artificial Intelligence," which addresses (among other things) several key aspects of privacy and data security concerning artificial intelligence…
HHS Office for Civil Rights Proposes Measures to Strengthen Cybersecurity in Health Care Under HIPAA
Blog December 30, 2024
The Department of Health and Human Services has proposed significant modifications to the HIPAA Security Rule and the HITECH Act in an attempt to strengthen cybersecurity protections for electronic protected health information…
Holiday Cyber Security Scams: Protecting Your Business During the Festive Season Without Being a Grinch
Blog November 27, 2024
As the holiday season is upon us, businesses must remain vigilant against the increased threat of cybersecurity hacks and scams…
1 of 30

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors