USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
implement reasonable security measures to protect consumers’ personal data. The California Consumer Privacy Act includes a private right of action for con - sumers whose unencrypted personal information is subject to a breach of security resulting from the busi - ness’s failure to implement reasonable security meas - ures. Additionally, in September 2025, the California Privacy Protection Agency (CPPA) finalised a rule that requires covered businesses to conduct annual inde - pendent cybersecurity audits, present the audit results to senior executives at the business and submit a certification of the audit to the CPPA. Compliance is phased for different parts of the rule, depending on the business’s gross annual revenue. 6.2 Cybersecurity and AI AI regulation is still nascent, but some government entities are starting to address the cybersecurity impli - cations of AI. Although Congress has not passed any comprehensive AI bill to date, there have been Presi - dential executive orders on AI that have emphasised deregulation. In July 2025, President Trump issued an AI Action Plan and several accompanying executive orders that encouraged deregulation, AI that is “free from top-down ideological bias,” and the develop - ment of domestic AI and data centre development. The AI Action Plan discusses bolstering the cyber - security of AI systems used in critical infrastructure, national security or other safety-critical applications. The Trump administration also released an execu - tive order in December 2025 that announces a plan to develop comprehensive federal AI regulation and directs the federal government to actively challenge state regulations perceived as overly restrictive to AI development. At the state level, the NYDFS’s 23 New York Codes, Rules and Regulations (NYCRR) 500 (“Part 500”) includes prescriptive requirements for covered finan - cial services companies to implement cybersecurity safeguards, such as implementing multifactor authen - tication. In October 2024, the NYDFS issued guidance on how companies can address the emerging security
threats from AI. It includes recommendations such as updating employee training to expand awareness of AI-powered social engineering and designing access controls to better withstand deepfakes and other AI-enhanced attacks. In October 2025, the NYDFS issued guidance on how companies can mitigate the cybersecurity risks posed by the use of third-party service providers. 6.3 Cybersecurity in the Healthcare Sector HIPAA is the primary law governing the privacy and security of healthcare data. HIPAA’s Security Rule includes prescriptive requirements for covered entities to implement specific safeguards to ensure the con - fidentiality, integrity and availability of ePHI, including through: • risk assessments; • encryption; • “minimum necessary” access controls; • a contingency plan to restore any loss of data; and • business associate contracts. In December 2024, the HHS published a Notice of Proposed Rulemaking and announced proposed changes to the Security Rule that would heighten the requirements for covered entities – for example, newly requiring annual penetration testing, as well as a written technology asset inventory mapping the data flows of ePHI within the covered entity’s systems. Additionally, the HIPAA Breach Notification Rule requires covered entities to provide notification of certain breaches of protected health information to: • affected individuals; • the HHS; and • the media. Through the Health Breach Notification Rule, the FTC separately requires vendors of personal health records and their third-party service providers to report certain breaches to affected individuals and the FTC.
472 CHAMBERS.COM
Powered by FlippingBook