The California Privacy Protection Agency drafted its rules to apply the rights allowed to residents under the California Consumer Privacy Act to automated decision-making technology used by businesses.
Adrianne Appel
Adrianne Appel writes regulatory news, policy, and trends for Compliance Week. She previously reported about policy developments for Bloomberg Law and Bloomberg Government.
Email: adrianne.appel@complianceweek.com
LinkedIn: Follow
First American fined $1M by NYDFS over 2019 cybersecurity breach
First American Title Insurance Company agreed to pay a $1 million fine and implement stronger compliance measures for not securing customersโ personal data, theย New York State Department of Financial Services announced.
Despite AI hype, compliance remains hesitant adopter
Most compliance professionals say their teams are not using artificial intelligence to assist with compliance obligations, according to our โInside the Mind of the CCOโ survey.
Australia seeks help from businesses under โbold and ambitiousโ cyber strategy
Australia released an updated cybersecurity strategy that will rely more heavily on public-private partnerships to support the countryโs cyber defense efforts.
Using AI? The SEC wants to know about it
The Securities and Exchange Commission has not yet implemented rules governing use of artificial intelligence but still expects regulated entities to adhere to commonly accepted practices, including disclosure, said an agency enforcement official.
Morgan Stanley settles with states for $6.5M over mishandled data
Morgan Stanley agreed to pay $6.5 million as part of a settlement with six states requiring the firm to strengthen its data security after actions it took compromised the personal data of millions of customers.
Nursing home chain, owner to pay $45.6M in kickbacks case
Prema Thekkek and the six skilled nursing homes she owned through her company, Paksn, agreed to pay $45.6 million in entering a consent judgment with the Department of Justice to resolve allegations employees paid kickbacks to doctors who brought patients to them.
N.Y. hospitals face stiff cybersecurity requirements under proposed rules
New York hospitals would be required to have a cybersecurity program that includes regular cyber risk assessments under newly proposed regulations.
A job never done: Tips for TPRM integration
Taking risk mitigation further and understanding your third parties and their risks can create value for your organization, practitioners discussed as part of a panel at CWโs virtual TPRM and Oversight Summit.
HHS publishes updated healthcare compliance guidance
New guidance from the Department of Health and Human Services is designed to apply generally to the healthcare industry, from doctors to pharmaceutical manufacturers, and help all such entities self-monitor their compliance and prevent waste, fraud, and abuse.


