HIPAA privacy and security
Financial and capital markets firms are sitting at an under-mapped intersection: HIPAA applies wherever they handle protected health information, including through employee benefit plans, fintech health-linked products, and certain data-sharing arrangements with covered entities. The U.S. Department of Health and Human Services Office for Civil Rights and the U.S. Federal Trade Commission have both taken enforcement positions that reach financial sector actors holding health data, and the 2024 HIPAA Security Rule proposed update from HHS would impose materially stricter technical safeguard requirements than the 2003 baseline most firms quietly inherited. Compliance teams are reviewing business associate agreements and third-party data vendor contracts now, not after a breach.
Watch
- HHS proposed HIPAA Security Rule update: new technical safeguard minimums pending finalization
- FTC health breach notification enforcement: penalties extending to non-HIPAA-covered data holders
- Business associate agreement gaps in fintech and embedded finance product structures
- State-level health data privacy laws (Washington My Health MY Data Act) layering onto federal baseline
Recent material activity in Financial & Capital Markets
A selection of recent published briefs; this is not a complete archive.
Federal Reserve proposes dual regulatory framework for payment stablecoin issuers under the GENIUS Act
The Federal Reserve Board released two proposals on September 24, 2026 to establish a supervisory framework for payment stablecoin issuers it oversees under the GENIUS Act. The proposals address reserve backing requireme…
Read a full sample brief →CFTC staff updates crypto FAQ guidance on tokenized customer fund investments and blockchain recordkeeping
Three CFTC divisions released updated FAQs on September 24, 2026, covering tokenized forms of permitted customer fund investments and blockchain-based recordkeeping for registrants. The update extends interpretive positi…
Read a full sample brief →Federal Reserve issues consent prohibition against former Sandy Spring Bank employee for embezzlement
On September 24, 2026, the Federal Reserve Board issued a consent prohibition order against Renee Nicole Brown, a former Sandy Spring Bank employee, for embezzlement. The order bars Brown from participating in the affair…
Read a full sample brief →NYSE National files immediately effective rule change amending clearly erroneous execution standards under Rule 7.10
NYSE National, Inc. filed a proposed rule change with the SEC on September 24, 2026, effective immediately upon filing, to amend Rule 7.10, which governs clearly erroneous execution determinations. The amendment adjusts …
Read a full sample brief →NYSE Texas amends clearly erroneous execution rule with immediate effectiveness
NYSE Texas, Inc. has amended its clearly erroneous executions rule, effective immediately upon filing. The amendment updates the procedures under which the exchange may review and nullify trades determined to be clearly …
Read a full sample brief →Texas Stock Exchange files immediate-effectiveness rule change modifying order processing during regulatory halts and auction mechanics
The SEC published a TXSE proposed rule change on September 24, 2026, effective upon filing. The rule modifies order handling during regulatory halts and adjusts mechanics for IPO auctions, halt auctions, and volatility c…
Read a full sample brief →SEC extends review period for Cboe proposed rule on stop-limit complex orders and stop complex order auctions
The SEC designated an extended review period on September 24, 2026 for a Cboe Exchange proposed rule change. The proposal would accommodate stop-limit complex orders and establish stop complex order auctions as a new auc…
Read a full sample brief →BaFin suspects BERLIN LIVING AG is publicly offering a bond without the required securities information sheet
BaFin suspects BERLIN LIVING AG of offering the "BERLIN LIVING 1 Anleihe 2026/2031" bond to the public in Germany without the legally required securities information sheet. The agency published a consumer notice to this …
Read a full sample brief →EBA submits MiCA review priorities to the European Commission, targeting gaps in crypto-asset regulation
The EBA published its response on September 24, 2026 to the European Commission's targeted consultation on the review of the Markets in Crypto-assets Regulation. The response identifies specific regulatory gaps the EBA r…
Read a full sample brief →Australia ASIC Securities & Investments release pending Cresthaven Analytics full analysis: 26-227MR Former financial services provider employee Emre Basar charged with misappropriation of client funds after ASIC investigation
Australia ASIC Securities & Investments published a regulatory release titled '26-227MR Former financial services provider employee Emre Basar charged with misappropriation of client funds after ASIC investigation'. Cres…
Read a full sample brief →