In the latest episode of Regulatory Oversight, Gene Fishel and Mike Lafleur welcome Pat Moore and Jared Rinehimer from the Massachusetts Attorney General’s (AG) Office to discuss online sports wagering. They cover the recently enacted Massachusetts Sports Wagering Act, the associated role of the Massachusetts Gaming Commission, related rules addressing advertising and data privacy, and the overall concerns of the AG’s office.
The U.S. Environmental Protection Agency (EPA) has formally withdrawn cybersecurity rules it promulgated in March requiring that states report cybersecurity threats to their public water systems (PWS). The reversal comes in the wake of lawsuits filed in the Eighth Circuit in July by Missouri, Arkansas, and Iowa (the states), along with intervenors American Water Works Association and National Rural Water Association (the water associations). As a result of the withdrawal, the states and water associations filed to dismiss their suits.
Government regulators are seemingly as numerous as the stars nowadays, especially in the universe of data incidents. When organizations experience a data incident, they will need to quickly assess what happened, why it happened, and who (e.g., clients, consumers, vendors, employees) was affected. They will also need to chart a course by which they resolve the incident while limiting their legal exposure.
This article was originally published on August 24, 2023 in Reuters and is republished here with permission.
In the burgeoning realm of data incidents, it is a truism that such incidents are not created equal. Indeed, a data incident is not necessarily a data breach.
An incident is any “occurrence that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system,” or an event that constitutes a violation of an organization’s computer security or acceptable use policies. National Institute of Standards and Technology, Minimum Security Requirements for Federal Information and Information Systems, FIPS 200, at 7 (Mar. 9, 2006) (nist.gov). A breach is an incident that imposes statutory and regulatory obligations on an affected organization when it holds or controls certain consumer information.Continue Reading Data Protection: One of These Incidents Is Not Like the Other