- Posts by Gregory J. Krabacher
Member of the FirmAttorney Greg Krabacher is a trusted adviser and skilled litigator who partners with health care organizations and other clients in a variety of industries to find solutions for their intellectual property, information ...
On September 2-3, 2026, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2026 conference.
This post shares takeaways in three key areas highlighted at the conference.
The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) gives consumers increasingly more control over their personal information when collected by businesses subject to the law. We have previously discussed the compliance requirements of these data privacy laws on organizations doing business in California.[1] Significantly, CCPA/CPRA defines the term “consumer” to mean any California resident; which from a business perspective, such a broad definition encompasses not only the business’s individual customers, but also its employees, job-applicants or even business-to-business (B2B) contacts. With the moratoriums currently in place for B2B and employee/applicant data sunsetting on January 1, 2023 and not likely to be extended, and the prospect for federal data privacy legislation with wide preemptive effect of state law looking less likely, businesses should be actively preparing to meet these expanded statutory obligations.
Recent Updates
- Comment Period Closes on California OHCA’s Proposed Emergency Regulations Expanding Private Equity, Hedge Fund, and MSO Reporting in Health Care Transactions
- DOJ Revises Justice Manual on Non-Binding Guidance and Qui Tam Dismissals: Practical Considerations
- Additional SBA Crackdown on Pandemic-Era Fraud Leads to Program and Loan Suspensions, Possible FCA Enforcement
- Federal Regulatory Views on Cybersecurity and AI Amidst a Growing Threat Landscape
- Remote Monitoring Services Under the 2027 PFS Proposed Rule: Epstein Becker Green Submits Comments to CMS