HIPAA

HHS Has Proposed the First Real Rewrite of the HIPAA Security Rule Since 2013

September 1, 2026

In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.

Read more →
Privacy Class Actions

Rule 23 Certification Standards in Privacy Class Actions

September 1, 2026

Privacy claims rarely settle on the merits before a court rules on certification. This post traces what Rule 23 requires by its own terms, how Dukes, Amgen, Comcast, Tyson Foods and TransUnion frame the inquiry, and where the courts of appeals have divided on ascertainability and on classes containing uninjured members.

Read more →
TCPA

The FCC's One-to-One Consent Rule, Vacated Before It Ever Took Effect

September 1, 2026

The FCC's 2023 order would have required consumers to consent to telemarketing robocalls one seller at a time, and limited each call's subject matter to the site where consent was given. The Eleventh Circuit vacated both restrictions on January 24, 2025, before the rule took effect, and the Commission removed the text from the CFR in August 2025.

Read more →
TCPA

Revoking TCPA Consent: The 2024 FCC Rule, and the Part of It Still Waived

September 1, 2026

A February 2024 FCC order codified the right to revoke TCPA consent by any reasonable means, fixed seven per se opt-out words for reply texts, capped the processing window at ten business days, and permitted one confirmation message. The cross-message-type portion of that rule has been waived twice and is now scheduled to take effect January 31, 2027.

Read more →
BIPA

How Illinois Decided When a BIPA Claim Accrues, and How Long It Lasts

August 31, 2026

Two 2023 decisions of the Illinois Supreme Court set the outer bounds of exposure under the Biometric Information Privacy Act, and the legislature answered one of them in 2024. The reasoning in each is more revealing than the result: both courts reached conclusions the statutory text compelled while acknowledging the consequences.

Read more →
BIPA

BIPA's Health Care Exemption After Mosby v. Ingalls Memorial

August 31, 2026

Section 10 of the Illinois Biometric Information Privacy Act carves health care information out of the definition of a biometric identifier. In Mosby v. Ingalls Memorial Hospital, the Illinois Supreme Court held that the carve-out is two clauses joined by "or" and that only the first is limited to patients. The second turns on purpose, whatever the source.

Read more →
BIPA

Why Workers' Compensation Exclusivity Does Not Bar a BIPA Claim

August 31, 2026

The Illinois Workers' Compensation Act makes its own remedies exclusive for injuries covered by it, and Illinois employers argued that a fingerprint timeclock claim was such an injury. In McDonald v. Symphony Bronzeville Park, the Illinois Supreme Court answered the certified question in the negative, on grounds that turn on what kind of injury the compensation scheme was built to price.

Read more →
Biometric Privacy

Two Cases: The Whole Enforcement Record Under Texas's Biometric Statute

August 31, 2026

Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.

Read more →
AI & Privacy

Automated Decision-Making Under Privacy Law: The Rules That Actually Bind

August 24, 2026

There is no general American law on algorithmic decisions. What exists is a set of narrow regimes reaching them from different directions: California ADMT rules attaching to decisions in named life domains, profiling opt-outs in the state comprehensive statutes, employment statutes imposing audits and notice, and an FTC remedy that reaches the model itself.

Read more →
Biometric Privacy

Biometric Privacy Statutes Outside Illinois, and Who Gets to Enforce Them

August 24, 2026

Illinois is not the only state with a biometric privacy statute — it is the only one where a private plaintiff can bring the claim. Texas, Washington and Colorado each regulate the capture and retention of biometric identifiers, and each reserves enforcement to a state official. This guide reads the three statutes against each other and traces what that enforcement design produces in practice.

Read more →