In 18 daystakes effect
Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats
2026-09-29 · Federal Communications Commission
What organisations are now required to do about security and personal data, when each obligation starts, and what has happened to the ones that did not. Every entry is the issuing body’s own publication, linked to the original.
In 18 daystakes effect
2026-09-29 · Federal Communications Commission
Background information Date of final decision: 3 September 2026 National case Controller: Hôpital Privé de la Loire Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fine Keywords: Cybersecurity, Personal data breaches, Health and research Summary of the Decision Origin of the case In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR). Key findings Failure to ensure the security of personal data (Article 32 GDPR) The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in par
In the Report and Order, the Federal Communications Commission (the FCC or the Commission) seeks to preserve the public's trust in the Emergency Alert System (EAS) by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation's adversaries.
The Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, today sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy and deceives users about its billing and cancellation practices. In a complaint filed in federal court, the FTC and its state and local partners allege that Hims & Hers (Hims) fails to clearly disclose that it charges consumers for prescriptions almost immediately after they submit an intake form, despite telling consumers that they will be able to consult with a medical provider to find a treatment that is “right for them.” The FTC also alleges that the company has made it difficult for consumers to cancel subscriptions and misled consumers about keeping their health information private. The FTC alleges that Hims shared consumers’ health information with Meta, Snap and other third parties. “The FTC’s complaint lays out a troubling scenario—consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of con
This notice announces a revised town hall meeting schedule to allow external stakeholders a limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPRM) issued in the Federal Register on April 4, 2024. The proposed CIRCIA rulemaking seeks to implement the Cyber Incident Reporting for Critical Infrastructure Act of 2022, as amended, by implementing covered cyber incident and ransom payment reporting requirements for covered entities.
Sources: the US Federal Register, the Securities and Exchange Commission, the Federal Trade Commission, the European Data Protection Board and the UK National Cyber Security Centre. Dates are as published and are shown in UTC. This is a tracker, not legal advice, and an obligation that applies to you is a question for your own counsel.