USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
Freshfields US LLP Freshfields US LLP 3 World Trade Center 175 Greenwich St- 51st Floor New York, NY 10007 USA Tel: +1 212 277 4000 Email: 3WTCHospitality@freshfields.com Web: www.freshfields.com/en
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy The USA does not regulate cybersecurity under a single, general, nationwide regime. Instead, multiple overlapping regulatory regimes at both the federal and state levels address cybersecurity in a sector- or jurisdiction-specific manner. The scope and substan - tive obligations imposed by each of these regulations address specific aspects of cybersecurity. These aspects can include: • technical measures that can be implemented to mitigate the risk of unauthorised access to data; • incident response procedures for when data breaches occur; and • transparency and reporting requirements. These regulations serve purposes such as protecting national security, safeguarding personal information (including specific regulations addressing sensitive financial data or health information), and promoting collaboration and innovation. For more information on sector-specific and national security-specific regula - tions, see 2. Critical Infrastructure Cybersecurity , 3. Financial Sector Operational Resilience Regulation and 6.3 Cybersecurity in the Healthcare Sector . 1.2 Cybersecurity Laws At the federal level, the main laws and regulations governing cybersecurity include: • the Gramm-Leach-Bliley Act (GLBA) of 1999, which imposes security and transparency require -
ments on financial institutions’ handling of non- public personal information of customers (see 3.1 Scope of Financial Sector Operational Resilience Regulation for more detail); • the Health Insurance Portability and Accountabil - ity Act (HIPAA), which regulates the protection of sensitive healthcare-related information (see 6.3 Cybersecurity in the Healthcare Sector for more detail); • the Cyber Incident Reporting for Critical Infrastruc - ture Act of 2022 (CIRCIA), which regulates disclo - sure of cyber-incidents by critical infrastructure companies (see 2.1 Scope of Critical Infrastruc- ture Cybersecurity Regulation for more detail); • laws and regulations imposing cybersecurity obli - gations on federal government agencies and con - tractors, such as the Defence Federal Acquisition Regulation Supplement (DFARS) and the Federal Information Security Management Act; and • the SEC’s Cybersecurity Risk Management, Strat - egy, Governance, and Incident Disclosure rules require some publicly traded companies to report certain cybersecurity incidents and make disclo - sures about their cybersecurity strategy, cyberse - curity governance and cybersecurity risk manage - ment in public filings. A number of federal laws and regulations criminalise hacking and otherwise regulate the use of information technology by individuals and law enforcement enti - ties alike. By way of example, the Computer Fraud and Abuse Act criminalises unauthorised access to computer systems, and the Stored Communications Act regulates ISPs’ ability to voluntarily provide stored electronic communications and data to the govern -
463 CHAMBERS.COM
Powered by FlippingBook