Blog

State AG Insights

Foley Hoag’s State Attorney General Investigations lawyers offer their experience, insight and skill to help your business through the considerable challenges of an AG investigation or enforcement action.

In Wake of Healthcare System Cyberattack, 22 State Attorneys General Call for Further Action on Data Privacy
Blog May 06, 2024
On April 25, 2024, the attorneys general of 22 states issued a letter encouraging UnitedHealth Group and its subsidiary, Change Healthcare, to take additional steps to respond to a massively disruptive cyberattack. The broad, bipartisan group of signatories reflects both the scale of the attack’s impact and its implications for the priorities of state attorneys general—from healthcare regulation to data privacy, consumer protection, and even antitrust concerns…
The Equifax/Massachusetts Attorney General Consent Judgment: A Guide for Privacy and Security Compliance
Blog May 02, 2020
What do businesses need to do to comply with privacy and data security laws?  The first place to look is to relevant statutes.  If you store or process the personal information of Massachusetts residents, then you will at least be subject to the Massachusetts Data Breach Notification Statute and related security regulations.  These are important guides that require certain operational activities, such as maintaining a written information security program…
Top 3 State AG Trends to Watch in 2020
Blog January 14, 2020
Out of all governmental agencies, state attorneys general are likely to have the greatest impact on privacy enforcement in 2020 for the average business.  Over the past few years, state AGs have taken an increasingly active role in privacy and data security matters, using their broad consumer protection authority to enforce rapidly evolving state laws and investigate data security lapses.  Even more recently, state AGs have begun to step out of their typical enforcement roles to pursue……
States Continue to Upgrade Data Privacy Laws  A Look at North Carolina
Blog February 21, 2018
A recent Security Breach Report published by the North Carolina Attorney General's Office provides a snapshot of the various data security threats currently riling the state's public and private sectors.  Since 2006, the year North Carolina businesses and government entities became statutorily obligated to report breaches to the Attorney General's Office, reported data breaches have skyrocketed from 86 to over one thousand.  In turn, the number of affected consumers has increased ten-fold……
Cybersecurity 2018 – The Year In Preview: State Enforcement Trends
Blog December 05, 2017
As state Attorneys General continue to flex their muscles in response to serious data security lapses nationwide, patchwork enforcement continues.  Strategies employed by state Attorneys General in response to nationwide data breaches are as diverse as the profusion of data security threats alarming consumers on a daily basis.  The recent Equifax data breach offers a prime example.  The disparate reactions of Massachusetts, California, Texas and New York reflect the various tools at the……
Cybersecurity 2018 – The Year in Preview: HIPAA Compliance
Blog October 18, 2017
Like many things in Washington, the HIPAA landscape in 2018 will be shaped by the shifting priorities of President Trump's new administration.  Early signs point to less funding for the Office of Civil Rights (“OCR”) within the Department of Health and Human Services, which is responsible for enforcing HIPAA.  This is likely to lead to fewer enforcement actions, but not necessarily less aggressive enforcement within those actions…
The Massachusetts Attorney General's Complaint Against Equifax
Blog September 25, 2017
As most are aware, the Massachusetts Attorney General has won the race to the courthouse and been the first regulator to file suit against Equifax. The 28 page complaint is summed up on paragraph 4:Consumers do not choose to give their private information to Equifax, and they do not have any reasonable manner of preventing Equifax from collecting, processing, using, or disclosing it. Equifax largely controls how…
CyberOhio Initiative – An Update from the Ohio AGO
Blog April 26, 2017
We recently posted on the Ohio Attorney General's CyberOhio initiative and forecasted that the Ohio Attorney General might be the first of many Attorneys General to join forces with industry in the struggle to protect consumer information.  Ohio Deputy General Counsel Craig Rapp, Director of CyberOhio, contacted our blog not only to agree with our prediction, but also to shed more light on what is transpiring in his state…
Friend or Foe?  State Attorneys General Start to Change Their Tune on Industry  Cybersecurity
Blog February 22, 2017
Should businesses be thought of as victims or bad actors when it comes to data breaches?  State attorneys general are embracing the idea that businesses are not necessarily adversaries in the struggle to protect sensitive consumer information.  Over the past several years state attorneys general have exerted efforts to both educate businesses as to their data privacy responsibilities, and collaborate with businesses in constructing more robust cybersecurity policies.  The spotlight now is……
The Future of Data Privacy Regulation in Massachusetts?  AG's Office Foreshadows State Action on Consumer Data in First-of-its Kind Conference
Blog March 25, 2016
What is the future of data privacy regulation in Massachusetts? On March 24, 2016, the Massachusetts Attorney General's Office gave us a glimpse. In collaboration with Harvard's Berkman Center for Internet and Society, and MIT's Internet Policy Research Initiative and Computer Science and Artificial Intelligence Laboratory, the AG's Office convened a “Forum on Data Privacy.”  In this first-of-its-kind conference…
1 of 2

ABOUT

Foley Hoag’s State Attorney General Investigations lawyers have the experience, the insight and the skill to guide your business through the considerable challenges of an AG investigation or enforcement action.

Our team knows firsthand how the AG and her line assistants approach investigations. Our legal team includes a former Massachusetts Attorney General, a former chief deputy attorney general, a former first assistant attorney general, a former deputy attorney general, a former chief of the business and labor bureau, a former deputy chief of the criminal bureau, and four partners who served as assistant United States attorneys.

Foley Hoag will work closely with you to develop and implement winning strategies to achieve your objectives and successfully resolve the investigation. And if there is no reasonable alternative but to litigate, our lawyers, including American College of Trial Lawyers fellows, have a record of substantial courtroom success. Whatever the path, we will fight to protect the reputation of your business and neutralize any adverse public relations implications arising from the AG action.