PRIVACY + SECURITY BLOG

News, Developments, and Insights

HIPAA Enforcement 2018

Last year was a record-setting year for HIPAA enforcement.  On HHS’s website, OCR has touted its 2018 enforcement: OCR has concluded an all-time record year in HIPAA enforcement activity.  In 2018, OCR settled 10 cases and secured one judgment, together totaling $28.7 million. This total surpassed the previous record of $23.5 million from 2016 by […]

Increasing State HIPAA Enforcement: Highlights from 2018

There have been quite a number of state HIPAA enforcement cases this year, and one expert points out a trend toward increasing state enforcement of HIPAA. An article in Data Breach Today discusses a number of state HIPAA enforcement cases.  Here are some of the ones discussed: Massachusetts — $75,000 settlement with McLean Hospital for […]

Cartoon: Artificial Intelligence

This cartoon about artificial intelligence is based on something I often hear — that it is impossible to understand how certain decisions are made by certain algorithms.  I wonder whether this problem is due to the fact that not enough effort is being devoted to addressing ethical issues such as the transparency of the decisionmaking […]

The Trouble with Spokeo: Standing, Privacy Harms, and Biometric Information

A recent case involving the Illinois Biometric Information Privacy Act (BIPA), Rivera v Google (N.D. Ill. No. 16 C 02714, Dec. 28, 2018), puts the ills of Spokeo Inc. v. Robins on full display.  In Rivera, plaintiffs sued Google under BIPA, which prohibits companies from collecting and storing specific types of biometric data without people’s consent.  The plaintiffs alleged that Google […]

A Decade of Notable Privacy and Security Books

I’m pleased to announce that there is a newly-created archive of all of my notable privacy+security books posts – for years 2008-present.  Together, there are probably about 100 books featured.  The past decade has seen a tremendous abundance of scholarship on privacy and security topics, and there are some truly essential books discussed in these […]

Archive of Concurring Opinions Posts

It is sad to say goodbye to ConcurringOpinions.com, a law professor blog I co-founded in 2005.  The blog began when a group of us (Dave Hoffman, Kaimi Wenger, Nate Oman, and me) who were blogging at PrawfsBlawg decided we wanted more autonomy in blog governance, so we founded Concurring Opinions.   Over the years, we added […]

The Internet of Bots

Much Internet traffic is not human.  According to the NY Times: How much of the internet is fake? Studies generally suggest that, year after year, less than 60 percent of web traffic is human; some years, according to some researchers, a healthy majority of it is bot. For a period of time in 2013, the Times reported this […]

The Robocall Wars: The Rise of Robocalls and the TCPA Robocall Cops

Move over robocop, there’s a new constable in town — the robocall cop. In the past decade, robocalls have surged.  There has also been a dramatic rise in litigation about these calls under the Telephone Consumer Protection Act (TCPA). The TCPA litigation is led by a small group of serial litigators, people who have assumed the […]

HIPAA Enforcement: Employee Access and BAAs Matter

Pagosa Springs Medical Center (PSMC) has agreed to pay $111,400 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) for an alleged violation of HIPAA. OCR found that the company failed to deactivate a former employee’s access to a web-based calendar that contained the protected health information […]