Privacy law increasingly imposes affirmative security duties rather than only notification duties after the fact. This hub covers what regulators mean by reasonable security and the disclosure rules now attaching to incidents.
Data Security Rules
September 21, 2026
The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.
Read more →
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
Data Security Rules
September 14, 2026
The SHIELD Act of 2019 did two things: it widened New York's breach notification statute, General Business Law section 899-aa, and it added section 899-bb, a standalone duty to maintain reasonable data security. This sets out the security requirement as enacted, the routes to deemed compliance, and the three later chapters that changed section 899-aa without touching section 899-bb.
Read more →
HIPAA
September 1, 2026
In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.
Read more →
GLBA
August 24, 2026
The Gramm-Leach-Bliley Act splits its privacy and security duties across several regulators, and the FTC's share lands on non-bank businesses that rarely call themselves financial institutions. This guide works through 16 CFR Part 314 as written: the coverage test, the nine enumerated elements, the exemption for smaller holders and the reporting duty that took effect in 2024.
Read more →
HIPAA
August 12, 2026
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.
Read more →