The U.S. Department of Justice (“DOJ”) recently issued revisions to its Justice Manual that soften the impact of the September 2015 “Yates Memo,” named after its author, then-Deputy Attorney General Sally Yates. The Yates Memo instructed federal prosecutors not to give a corporate defendant any credit for cooperation unless the […]
Publications
OCR Asks for Your Feedback: The Request for Information on Reducing Regulatory Burdens to Improve Care Coordination
On December 14, 2018, OCR issued a Request for Information (“RFI”) asking how HIPAA can be revised to better promote care coordination and value-based care while preserving privacy and security protections. The RFI is relatively short, and easily digestible. It categorizes its requests into four topic areas, asking more specific […]
Testing the Extraterritorial Reach of the GDPR
A European privacy regulator has provided insight into a key feature of the General Data Protection Regulation (“GDPR”)—extraterritorial reach. Recall that Article 3(1) of the GDPR applies to EU-based organizations engaged in the processing of personal data (i.e., any information relating to an identified or identifiable natural person) belonging to […]
Revisiting the Right of Publicity
Advertisements commonly include images of individuals, where the individuals may endorse a product, or merely just be incorporated into the advertisement. But such use of an individual’s image, name, or likeness in a commercial advertisement may implicate an individual’s right of publicity. Almost half of the states in the United […]
What Can You do to Help Protect Yourself From Data Breaches?
On November 30, 2018, Marriott revealed that its Starwood reservation system had been hacked exposing the personal data of approximately 500 million guests. It appears that not only credit card information was compromised but also passport numbers, birth dates, cell numbers, arrival and departure dates, etc. The Marriott data breach […]

