PrivacySignal
Healthcare

Vermont Enacts Privacy Legislation to Regulate Health-Related Information

Inside Privacy (Covington) · · International · Healthcare Privacy

Vermont has passed two health-focused privacy laws: H.639, which regulates direct-to-consumer genetic testing companies, and S.71, a broader privacy act that adds extra protections for consumer health data. Both measures expand the state's oversight of how sensitive personal health information is collected and used.

Why this matters: Genetic data is not like a password. You cannot change it, and it does not just describe you — it describes your relatives too. Direct-to-consumer DNA companies have had a rough few years on privacy, including a major breach and a bankruptcy that put customer data at risk. Vermont is now telling those companies that they have real obligations. The broader health data law matters because most people assume their health information is already protected. Often it is not, especially when it flows through apps and wellness platforms that fall outside federal health privacy rules.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Healthcare
HIPAA Journal · · US Federal

Casper Orthopedic Associates; Atlantic Digestive Specialists Announce Data Breaches

Data breaches have been announced by Casper Orthopedic Associates in Wyoming and Atlantic Digestive Specialists in New Hampshire. Casper Orthopedic […] The post Casper Orthopedic Associates; Atlantic Digestive Specialists Announce Data Breaches appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Many Medical Devices Incapable of Supporting Transition to Post-Quantum Cryptography

An analysis of medical devices found that most cannot support post-quantum cryptography, leaving healthcare organizations exposed to future attacks from quantum computing. Only a fraction of devices in use today have the hardware or software capacity to handle the transition to stronger encryption standards.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare Critical
HIPAA Journal · · US Federal

Citrix Patches Third Actively Exploited NetScaler Zero Day

Citrix has issued a patch for a third actively exploited zero-day vulnerability in its NetScaler product, releasing the fix within days of addressing two previous flaws that were also under active attack.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →
Healthcare
HIPAA Journal · · US Federal

Website Privacy: Your Privacy Policy Makes Promises But Does Your Website Keep Them?

Many organizations publish privacy policies that do not reflect what their websites actually do, because compliance teams often lack full visibility into the third-party tools running on their sites, what data those tools collect, and where that data goes.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · General readers · Policy

#healthcare#regulation#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

CISA Sends CIRCIA Final Rule for White House Review

CISA has completed its final rule under the Cyber Incident Reporting for Critical Infrastructure Act and sent it to the White House for review. The rule, once approved, would establish mandatory cyber incident reporting requirements for critical infrastructure sectors.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →