Healthcare organizations face unprecedented cybersecurity challenges in an increasingly hostile threat environment. In response to major breaches and security incidents affecting the industry, the Health Infrastructure Security and Accountability Act (HISAA) has been re-introduced and the U.S. Senate has advanced the Health Care Cybersecurity and Resiliency Act (HCCRA). This blog post summarizes the key provisions of these bills.
The California Privacy Protection Agency Board (the “Board”) held a public meeting on February 3, 2023, adopting and approving the current set of draft rules (the “Draft Rules”), which implement and clarify the California Consumer Privacy Act of 2018 (“CCPA”) as amended by the California Privacy Rights Act of 2020 (“CPRA”). The Draft Rules cover many CCPA requirements, including restrictions on the collection and use of personal information, transparency obligations, consumer rights and responding to consumer requests, and service provider contract requirements. At the meeting, the Board also addressed additional proposed rulemaking processes concerning cybersecurity audits, risk assessments, and automated decision-making.
Recent Updates
- Congressional Action on Health Care Cybersecurity: HISAA is Re-Introduced and the Health Care Cybersecurity and Resiliency Act Moves Forward
- DOJ Corporate Fraud Enforcement Memo: What Health Care Companies Need to Know Now
- Attorneys General of Three States File Two Sweeping Lawsuits Targeting Telehealth Abortion Providers and State Shield Laws
- RFI Seeks Input on Medicare Part D’s Pharmacy Contract Standards
- Proposed H.R. 10336 Would Balance Innovation, Access to Dietary Supplements—Yet Change the Definition