RadarFirst Blog

Have a Breach? Be Prepared to Notify the State Attorney General

Reports of data breaches fill today’s news feeds with alarming frequency. Given the inevitability of breaches—including high-profile ones—state attorneys general are taking a more active role in helping consumers deal with the repercussions of a data breach, investigate data security lapses, and enforce data breach notification laws.

Read more

As CCPA Effective Date Looms, Questions Remain

Last week, myself and members of the RADAR team were able to attend the IAPP CCPA Comprehensive in Fremont, California. This day-long program focused on the California Consumer Privacy Act (CCPA), with a special focus on the act’s scope, definitions, General Data Protection Regulation (GDPR) inspiration, and areas for further clarification.

Read more

Anatomy of a Privacy Incident: Webinar Q&A

The recent webinar Anatomy of A Privacy Incident: Data Breach Response and Investigation Best Practices dove into the best practices for designing an incident response program that encourages an organization-wide culture of compliance. Panelists Andrew Reeder from Rush University Medical Center and Asra Ali from Healthscape Advisors lead a lively discussion into the ins and [...] Read more

Too Much or Too Little? The Risks of Under- or Over-reporting Incidents

Data privacy and security incidents occur all the time; the 2018 Verizon Data Breach Investigations Report covers a mind-boggling 53,000-plus incidents. Incidents come in all shapes and sizes—electronic, paper, even verbal or visual. They can be as simple as an improperly mailed billing statement or as complex as a highly coordinated cyber-attack on millions of […]

Read more

OCR Enforcement Trends From 2017, and Areas of Concern for HIPAA Compliance

About this time last year, we predicted 2017 would see continued vigilance from the Department of Health and Human Services’ Office for Civil Rights (OCR) in regulating and issuing enforcement actions for HIPAA violations. The results are in, and there was sustained momentum from OCR in the last year, including 196 separate breach cases listed […]

Read more