ProductsIntelligenceLicensingAnalyst AccessPricingMethodologyContact
TECHNOLOGY, AI & COMPETITION

HIPAA privacy and security

For Technology, AI, and Competition sector companies, HIPAA privacy and security obligations are no longer limited to traditional healthcare adjacency. The U.S. Department of Health and Human Services Office for Civil Rights and the U.S. Federal Trade Commission have both expanded enforcement posture toward tech firms handling health-adjacent data, with OCR's 2024 updated guidance on tracking technologies directly implicating analytics platforms, ad-tech stacks, and AI inference pipelines that touch protected health information. Compliance teams are currently auditing pixel and SDK deployments against that guidance before exposure surfaces in the next round of OCR resolution agreements.

Watch

  • OCR's December 2024 tracking technology guidance: does your analytics stack qualify as a business associate?
  • FTC enforcement under Section 5 for deceptive health data practices in consumer-facing AI products
  • HIPAA Security Rule NPRM (proposed 2024): updated technical safeguard requirements for electronic PHI
  • State AG coordination with OCR on health data breaches involving third-party AI vendors
  • Right-of-access enforcement: OCR settlement pattern targeting patient portal delays at covered entities

Recent material activity in Technology, AI & Competition

A selection of recent published briefs; this is not a complete archive.

  • Sep 24, 2026MATERIAL

    CISA adds Adobe Commerce and Magento authorization flaw to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27 2026

    CISA added CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability allows unauthenticated privilege …

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CISA adds WSO2 path traversal vulnerability to Known Exploited Vulnerabilities catalog with federal remediation deadline of September 27, 2026

    CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, 2026. The vulnerability is a path traversal flaw affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gate…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    FTC amends Rules of Practice to align with the FTC Act and formalize the American Competition Enforcement Division

    The FTC approved amendments to its Rules of Practice on September 24, 2026, by a 2-0 vote. The amendments align procedural rules with the FTC Act, embed the newly created American Competition Enforcement Division by name…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    FTC opens rulemaking inquiry into platform ad-optimization tools that amplify impersonation scams

    The FTC published an Advance Notice of Proposed Rulemaking on September 24, 2026, seeking public comment on whether to amend its Rule on Impersonation of Government and Businesses. The inquiry targets social media platfo…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    FTC opens rulemaking inquiry into platform ad-optimization tools that amplify impersonation scams

    The FTC published an Advance Notice of Proposed Rulemaking on September 24, 2026, seeking comment on whether to amend its Impersonation of Government and Businesses Rule or issue a new rule. The ANPRM targets social medi…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    Canada Competition Bureau secures consent agreement with Kalibrate over retail fuel data-sharing competition concerns

    The Competition Bureau of Canada reached a consent agreement with Kalibrate on September 24, 2026, restricting how the company may collect, aggregate, and distribute competitor-sensitive pricing and operational data from…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CMA opens Phase 1 merger inquiry into Vivisol's acquisition of Air Liquide's UK home oxygen services business

    The CMA announced on September 24, 2026 that it is investigating the anticipated acquisition by Dolby Medical Home Respiratory Care Limited, trading as Vivisol, of Air Liquide Healthcare Limited's home oxygen services bu…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CMA issues first-ever civil penalties against individuals for concealing evidence during a competition inspection

    The CMA fined construction firm M&J Group and two of its staff members a combined £50,000 on September 24, 2026 for concealing a mobile phone and documents during a warranted inspection. These are the first civil penalti…

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CMA opens Chapter I investigation into suspected anti-competitive arrangements in roofing and construction services

    The Competition and Markets Authority (CMA) opened an investigation on September 24, 2026 into suspected anti-competitive arrangements in the supply of roofing and other construction services. The investigation concerns …

    Read a full sample brief →
  • Sep 24, 2026MATERIAL

    CNIL closes May 2025 injunction against Solocal Marketing Services after consent-verification measures accepted

    The CNIL's enforcement chamber closed its injunction against Solocal Marketing Services on September 17, 2026. The original injunction, issued May 15, 2025, required the company to verify the validity of consent collecte…

    Read a full sample brief →