HIPAA
September 1, 2026
In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.
Read more →
Privacy Class Actions
September 1, 2026
Privacy claims rarely settle on the merits before a court rules on certification. This post traces what Rule 23 requires by its own terms, how Dukes, Amgen, Comcast, Tyson Foods and TransUnion frame the inquiry, and where the courts of appeals have divided on ascertainability and on classes containing uninjured members.
Read more →
Data Breaches
September 1, 2026
Item 1.05 of Form 8-K is an investor-disclosure obligation, not a breach-notification law: it is triggered by a registrant's determination that a cybersecurity incident is material, runs four business days from that determination, and asks about impact rather than incident detail.
Read more →
GLBA
September 1, 2026
Amendments adopted in May 2024 rewrote 17 CFR 248.30 to require broker-dealers, investment companies, registered advisers and transfer agents to maintain an incident response program and to notify affected individuals within 30 days. Both compliance dates have now passed.
Read more →
TCPA
September 1, 2026
The FCC's 2023 order would have required consumers to consent to telemarketing robocalls one seller at a time, and limited each call's subject matter to the site where consent was given. The Eleventh Circuit vacated both restrictions on January 24, 2025, before the rule took effect, and the Commission removed the text from the CFR in August 2025.
Read more →
TCPA
September 1, 2026
A February 2024 FCC order codified the right to revoke TCPA consent by any reasonable means, fixed seven per se opt-out words for reply texts, capped the processing window at ten business days, and permitted one confirmation message. The cross-message-type portion of that rule has been waived twice and is now scheduled to take effect January 31, 2027.
Read more →
BIPA
August 31, 2026
Two 2023 decisions of the Illinois Supreme Court set the outer bounds of exposure under the Biometric Information Privacy Act, and the legislature answered one of them in 2024. The reasoning in each is more revealing than the result: both courts reached conclusions the statutory text compelled while acknowledging the consequences.
Read more →
BIPA
August 31, 2026
Section 10 of the Illinois Biometric Information Privacy Act carves health care information out of the definition of a biometric identifier. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court held that the carve-out is two clauses joined by "or" and that only the first is limited to patients. The second turns on purpose, whatever the source.
Read more →
BIPA
August 31, 2026
The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.
Read more →
Biometric Privacy
August 31, 2026
Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.
Read more →
AI & Privacy
August 24, 2026
There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.
Read more →
Biometric Privacy
August 24, 2026
Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.
Read more →