Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

FTC Increases Targeting of Companies Lacking Cyber Protection

Client Alert

Here is how businesses can develop cyber strategies to mitigate breaches and financial risk.

The Federal Trade Commission (FTC) recently released a comprehensive cybersecurity report outlining key findings and recommendations based on emerging threats, trends in data breaches, and strategies for businesses to enhance their cybersecurity posture observed over the last year. The FTC strives to protect consumer privacy and respond to the evolving ways that companies use consumer data such as in the development of artificial intelligence models and misuse of health data. 

Importantly, the report emphasized the need for proactive measures to mitigate risks and highlighted the FTC’s initiative in targeting companies that fail to implement reasonable data security measures to protect consumer data. 

Here are some key strategies for businesses: 

  1. Risk Assessment and Management: Conduct regular risk assessments (at least annually) to identify potential vulnerabilities and prioritize them based on their potential impact on the business. Develop and implement a risk management plan to address these vulnerabilities effectively.
  2. Cyber Security Policies and Procedures:  Implement basic cybersecurity policies to protect its assets, data, and operations from cyber threats.
  3. Employee Training and Awareness: Educate employees about cybersecurity best practices, such as recognizing phishing emails, using strong passwords, and reporting suspicious activity. Regular training exercises help reinforce awareness.
  4. Access Control and Privilege Management: Implement strong access controls to limit user privileges and restrict access to sensitive data and systems. Use multi-factor authentication (MFA) where possible to add an extra layer of security.
  5. Data Encryption: Encrypt sensitive data to protect it from unauthorized access. 
  6. Patching: Keep software and systems up to date with the latest security patches to address known vulnerabilities. Establish a patch management process to ensure timely deployment of patches across the organization.
  7. Network Security: Deploy firewalls, intrusion detection/prevention systems, and other network security measures to monitor and protect against unauthorized access and malicious activity. Segment networks to limit the spread of potential breaches.
  8. Incident Response Plan: Develop a comprehensive incident response plan that outlines procedures for detecting, containing, and mitigating cybersecurity incidents. Test the plan regularly through tabletop exercises and simulations.
  9. Vendor Risk Management: Assess the security practices of third-party vendors and service providers to ensure they meet your organization's security standards. Include contractual clauses that outline security requirements and responsibilities.
  10. 10. Cyber Insurance: Consider obtaining cyber insurance to mitigate financial risks associated with cybersecurity incidents, such as data breaches or business interruptions.

By adopting a proactive approach to cybersecurity and implementing these strategies, businesses can enhance their cybersecurity posture and better protect themselves against evolving threats and complying with ever increasing legal obligations.  

BMD assists companies design and implement a strategy to achieve technical and organizational controls to bolster cybersecurity and data protection.  

If you have any questions regarding this topic and how to protect your company's data, please contact BMD Member Brandon Pauley at btpauley@bmdllc.com.


Recent Litigation Challenges the Affordable Care Act Preventive Services Requirement

The Affordable Care Act (ACA) has been met with numerous legal challenges. The most recent legal challenge, Braidwood Management Inc. v. Becerra, could affect millions of people covered by private health insurance.

340C – Prospective Legislation to Protect Federally Qualified Health Centers

Advocates for Community Health (ACH), an organization created to implement policy and advocacy initiatives for health care systems across the United States, has begun drafting legislation that is geared towards protecting Federally Qualified Health Centers (“FQHCs”) enrolled in the 340B Program, which is being dubbed “340C.”

Getting Paid to Vote

Can you get paid to vote? Election Day is upon us and employees across the country are asking whether they can get paid to vote. Essentially, can they take paid leave of a few hours to go to the polling location to cast their vote in a midterm election or presidential election. Well, it depends on the state where the employee works.

BMD Makes 2023 U.S. News & World Report "Best Law Firms" Edition

Best Law Firms 2023

EEOC’s New “Know Your Rights” Poster to Replace “EEO is the Law” Poster

Under federal law, covered employers are required to post a notice in the workplace describing federal antidiscrimination laws. The Equal Employment Opportunity Commission (EEOC) prepares the mandatory posters summarizing antidiscrimination laws and explaining how employees and applicants can file a complaint if they believe they have experienced job discrimination. On October 19, 2022, the EEOC released a new poster: “Know Your Rights: Workplace Discrimination is Illegal,” replacing the “EEO is the Law” poster. Employers must now use the poster captioned as “Know Your Rights: Workplace Discrimination is Illegal – Revised 10/20/22.” Employers may be reprimanded for failure to appropriately and compliantly post the updated poster.