Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Robotics and Health Information - Privacy and Security Issues You Need to Know
Blog March 05, 2026
On March 5, 2026, Colin Zick presented to the MassRobotics Healthcare Catalyst Program on the topic, "Robotics and Health Information: Navigating Clinical Deployments in Light of Current Trends in Health Information Privacy and Security."…
42 C.F.R. Part 2 Civil Enforcement Is Here: What Substance Use Disorder Providers Need to Know
Blog February 17, 2026
February 16, 2026 marks a significant milestone for substance use disorder (SUD) treatment providers across the country…
HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points
Blog February 10, 2026
The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes…
System Hardening, HIPAA, and the Practical Path to Protecting ePHI
Blog January 12, 2026
The January 2026 OCR Cybersecurity Newsletter is the U.S. Department of Health and Human Services Office for Civil Rights’ latest installment in its periodic series translating HIPAA Security Rule expectations into practical, operational guidance…
Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records:  42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
Blog November 10, 2025
On November, 7, 2025, I spoke to the Massachusetts Health Information Management Association about the federal government’s sweeping updates to 42 CFR Part 2—the confidentiality rules governing substance use disorder (SUD) records—to better align with HIPAA while preserving Part 2’s core patient protections…
HHS Unveils Version 3.6 of the Security Risk Assessment Tool: What Covered Entities and Business Associates Need to Know
Blog September 12, 2025
Anyone who has wrestled with the HIPAA Security Rule’s risk‐analysis requirement knows that the government’s free Security Risk Assessment (“SRA”) Tool can be a practical starting point—particularly for resource-constrained practices that cannot justify a commercial governance-risk-and-compliance platform…
Expanded Protections for Reproductive Health and Gender-Affirming Care: What Massachusetts Providers Need to Know
Blog September 04, 2025
On August 7, 2025, Massachusetts Governor Maura Healey signed into law an Act Strengthening Healthcare Protections in the Commonwealth (the “Act”), which amends the state’s existing “Shield Law” protections for providers of reproductive health and gender-affirming care (“Protected Care”)…
23andMe Bankruptcy Update: How the Proceedings Highlight Best Practices for Handling and Transferring Genetic Data and Personal Information
Blog July 18, 2025
After Foley Hoag’s prior updates regarding the chapter 11 bankruptcy cases of 23andMe Holding Co and its affiliated debtors (collectively, “23andMe”), the United States Bankruptcy Court for the Eastern District of Missouri (the “Court”) approved the sale of 23andMe’s genetic data. On July 14, 2025, a notice of the closing of the sale was filed in bankruptcy court. This sale process informs best practices for companies and other entities handling sensitive personal information…
The FTC Addresses 23andMe's Bankruptcy
Blog March 31, 2025
In a March 31, 2025 letter, the Chair of the FTC, Andrew Ferguson, wrote to the Acting U.S. Bankruptcy Trustee and set out the FTC’s expectations for the protection of consumer information held by 23andMe…
1 of 3

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors