Remove privacy-policy
article thumbnail

Weekly Roundup: December 23-29, 2022

Harvard Corporate Governance

ISS Issues Benchmark Policy Updates for 2023. Trust, Risk, and Opportunity: Overseeing a Comprehensive Data and Privacy Strategy. Tags: Cyber-risk , Cybersecurity , Data Governance , Data Privacy , Databases , Privacy. Posted by Cydney S. Posner, Cooley LLP, on Friday, December 23, 2022. Posted by Matthew C.

189
189
article thumbnail

7 Ways Companies’ Cyber-Related Governance Disclosures Will Evolve Post-SEC Rule Change

Harvard Corporate Governance

Large investors and their stewardship teams, as well as proxy advisors, are rapidly evolving their expectations for Boards and management teams to demonstrate robust cybersecurity programs are in place: Glass Lewis’ 2024 Policy Updates included a new approach to cyber risk oversight which can lead to recommended votes against directors where a company (..)

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Ethical Dilemmas in the Age of Big Data: AI, Privacy Rights, and Key Considerations for Internal Auditors

Audit Board

Security and privacy are typically regarded as key risks from an internal audit perspective. However, out of the disruption of the pandemic emerged a new understanding of the interwoven nature of privacy, security, and trust. For example, while there is no overarching data privacy law in the U.S.,

article thumbnail

HIPAA Resolution Agreement Emphasizes the Importance of Proper Disposal of PHI

ThomsonReuters

HHS’s Office for Civil Rights (OCR) has announced a $300,640 settlement with a medical facility (a HIPAA covered entity) to resolve alleged violations of the HIPAA privacy rule. The facility must update the policies and procedures at least annually (subject to OCR review and approval). Available at [link].

article thumbnail

HHS Investigation of Business Associate Results in $350,000 Settlement

ThomsonReuters

The business associate must also investigate failures to comply with policies and procedures and report any material failure to HHS. The business associate in this situation might have been able to avoid the HIPAA breach and audit if it had a risk assessment and management plan, policies and procedures, and training.

article thumbnail

OCR Proposes Modifications to Strengthen HIPAA Privacy Rule for Reproductive Health Care

ThomsonReuters

Proposed Rule: HIPAA Privacy Rule To Support Reproductive Health Care Privacy, 45 CFR Parts 160 and 164, 88 Fed. 17, 2023); HIPAA Privacy Rule Notice of Proposed Rulemaking to Support Reproductive Health Care Privacy Fact Sheet (Apr. While OCR is undertaking this rulemaking, the current privacy rule remains in place.

52
article thumbnail

Privacy and Cybersecurity Due Diligence Considerations in M&A Transactions

Deal Law Wire

Privacy and cybersecurity practices of target companies are being increasingly scrutinized throughout the due diligence process in M&A transactions. Where the company does not have timely policies and related training in place, or conduct regular third party testing (e.g.