Tag: Privacy

  • Pixel Litigation Tests Old Privacy Law

    Pixel Litigation Tests Old Privacy Law

    Pixel Litigation Tests Old Privacy Law featuring Myriah Jaworski

    Consumers are driving a wave of litigation against companies for allegedly sharing details of what videos they watch on their platforms. 

    •  Will litigation tamp down this activity?

    •  What harm is being caused?

    •  How will existing laws be interpreted?

    •  Are these organizations within their rights?

    Dozens of organizations — ranging from the rough-and-tumble NFL to the decidedly less rough-and-tumble NPR — are among the defendants in nearly 50 proposed class actions which claim Meta Platforms Inc.’s pixel tracking tool facilitated the sharing of personal video consumption data and identities from online platforms to Facebook without user consent. This, the plaintiffs say, violates the federal Video Privacy Protection Act (VPAA) of 1988.

    The rising number of VPAA cases demonstrates how plaintiff attorneys are creatively applying traditional causes of action to litigate modern privacy issues in the absence of a federal law. An act that far preceded the proliferation of online video streaming, it followed the publication of one-time Supreme Court nominee Robert Bork’s Blockbuster video rentals. The titles the judge rented disappointed anyone looking for scandal. They included nothing more salacious thanThe Man Who Knew Too Much  starring Jimmy Stewart and Doris Day.

    Listen to my interview with someone who knows plenty:   Myriah V. Jaworski, a member at Clark Hill PLC.  Myriah helps me explore the privacy issues raised by these cases and what the future holds for businesses and other parties who handle consumer data.

    Myriah represents clients in defense of data breach class actions, privacy torts and statutory claims (IRPA/BIPA), pixel tacking and commercial surveillance matters, internet defamation, technology disputes, and cyber subrogation claims. She defends them in response to regulatory inquiries and investigations arising out of data incidents and privacy practices, including before state Attorney General offices, the Federal Trade Commission and the Department of Human and Health Services – Office of Civil Rights. Myriah is a Certified Information Privacy Professional, United States (CIPP/US) and a Certified Information Privacy Professional, Europe (CIPP/E) as certified by the International Association of Privacy Professionals. She was also a Trial Attorney with the Department of Justice. She received her JD/MS degree from Syracuse University College of Law. And now, I am happy to say, she is a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

    I hope you enjoy the episode. If so, give us a rating!

    *******

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation. The Journal is a collaborative project between HB Litigation Conferences and the Fastcaselegal research family, which includes Full Court Press, Law Street Media, and Docket Alarm. The podcast itself is a joint effort between HB and our friends at Law Street Media. If you have comments or wish to participate in one our projects please drop me a note at Editor@LitigationConferences.com.

    Tom Hagy

    (actual size)

    Tom Hagy
    Litigation Enthusiast and
    Host of the Emerging Litigation Podcast
    Home Page
    LinkedIn

    Myriah V. Jaworski

    Myriah V. JaworskiClark Hill PLC

    Myriah represents clients in defense of data breach class actions, privacy torts and statutory claims (IRPA/BIPA), pixel tacking and commercial surveillance matters, internet defamation, technology disputes, and cyber subrogation claims.

    She defends them in response to regulatory inquiries and investigations arising out of data incidents and privacy practices, including before state Attorney General offices, the Federal Trade Commission and the Department of Human and Health Services – Office of Civil Rights.

    Myriah is a Certified Information Privacy Professional, United States (CIPP/US) and a Certified Information Privacy Professional, Europe (CIPP/E) as certified by the International Association of Privacy Professionals. She was also a Trial Attorney with the Department of Justice. She received her JD/MS degree from Syracuse University College of Law. And now, I am happy to say, she is a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

  • Digital Health Care Companies, Beware: Federal Agencies Are Tracking Your Use of Online Tracking Technologies

    Digital Health Care Companies, Beware: Federal Agencies Are Tracking Your Use of Online Tracking Technologies

    The Authors

    Patricia Markus

    Patricia MarkusNelson Mullins

    Patricia A. Markus (trish.markus@nelsonmullins.com) represents health care providers and health technology companies across the country on wide-ranging regulatory compliance, reimbursement, licensure, and operational matters, with a special focus on issues surrounding health information privacy, security, and technology.

    Shane Duer

    Shane DuerNelson Mullins

    Shane Duer (shane.duer@nelsonmullins.com) focuses his practice on healthcare regulatory and corporate matters, with an emphasis on data privacy, cyber security, and information management concerns within and beyond the health care industry.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Digital Health Care Companies, Beware 

    Federal Agencies Are Tracking Your Use of Online Tracking Technologies.

    Abstract: Health care industry stakeholders have regularly used online tracking technologies to help improve patient experience. However, growing scrutiny by the Office for Civil Rights, which enforces the Health Insurance Portability and Accountability Act of 1996 (HIPAA), requires covered entities and business associates to proceed cautiously in their use of such technologies. In addition, recent enforcement actions by the Federal Trade Commission make clear that a wide range of digital health companies, whether or not regulated by HIPAA, must tread carefully when collecting and disclosing personal information related to health, especially where consumers’ location data is to be used for a company’s advertising purposes, as they may be held accountable for failing to maintain the privacy and security of individuals’ protected and individually identifiable health information.

    The increasing number of lawsuits and news articles regarding use of these technologies demonstrates that third-party technology tracking vendors who receive PHI often are not operating under Business Associate Agreements (BAAs). The vendors in most instances disavow any need to collect PHI and accordingly instruct users to avoid sending PHI or other personally identifiable information. Under HIPAA, covered entities and business associates generally may not disclose PHI to third parties for health care operations purposes, unless such disclosure is to a business associate pursuant to a BAA, or the disclosure is made pursuant to an individual’s HIPAA-compliant authorization.

    Not only does sharing PHI through third-party tracking technologies without individuals’ authorizations violate HIPAA, but the FTC has asserted in two recent enforcement actions that the collection and sharing of individuals’ IIHI through these technologies without individuals’ “affirmative express consent” constitutes unfair and deceptive trade practices.

    Download the article now!

  • “Years of Deception” Behind Consumer Privacy Violations Alleged

    “Years of Deception” Behind Consumer Privacy Violations Alleged

    Mental Health Platform’s Data Sharing Practices Challenged.

    • BetterHelp allegedly shared personal identifiable info with third parties. 
    • FTC files administrative complaint asserting “years of deception.”
    • Days later, two class actions were filed in the Northern District of California.  

    Photo by Nik Shuliahin 💛💙 on Unsplash

    Online mental health company BetterHelp, Inc. is facing allegations on two fronts for allegedly sharing personal identifiable information with third parties and breaching consumer privacy.

    The Federal Trade Commission (“FTC”) initiated an administrative complaint against the California-based online mental health company on March 2, 2023, after what they call years of deceptive practices and blatant denial of a media report published by Jezebel in February 2020. The article cited evidence that BetterHelp shares sensitive patient information and email account information with third parties such as Facebook, Snapchat, Criteo, and Pinterest.

    Days after the FTC filed its complaint, consumers filed two class actions in the Northern District of California’s San Jose Division (C.M. v. BetterHelp, Inc., March 7, 2023, 5:23-cv-01033 and Jane Doe v. BetterHelp, Inc., March 11, 2023, 5:23-cv-01096). Both consumer privacy lawsuits state that their facts are largely supported by experts in the field of data privacy.

    BetterHelp is a Delaware corporation with its principal office or place of business in Mountain View, Calif. On its website the company claims it is the “world’s largest therapy platform” with more than 25,000 licensed therapists available. BetterHelp operates generalized mental health therapy services and operates specialized therapy services for members of the LGBTQ community, members of the Christian Faith, Spanish-speaking clients, and teen counseling with parental consent. BetterHelp founder Alon Matas stated in a Medium article published Oct. 8, 2018, that, “One of our core missions is to destigmatize mental health. We firmly believe that nobody should ever feel ashamed or embarrassed to reach out for help.”

    Explosive Growth

    The FTC complaint states that BetterHelp’s website and app “has seen explosive growth over the last few years,” adding more than 118,000 U.S. users in 2018, 158,000 in 2019, and 641,000 in 2020. BetterHelp required new users between August 2017 to December 2020 to fill out mandatory questionnaires. These intake questionnaires reportedly ask a user’s age, marital status, whether they’ve been in therapy before, how they rate their sleeping and eating habits, employment status, and whether they are experiencing overwhelming emotions such as sadness, grief, and depression, and whether they have suicidal ideation.

    BetterHelp repeatedly assured users filling out these questionnaires that their email addresses and information would be “kept strictly private” and “never shared, sold or disclosed to anyone.” However, FTC said its investigation revealed that the company used clandestine tactics to share health information of more than 7 million users with Facebook, Snapchat, Criteo, and Pinterest.

    The FTC has filed a proposed order that would require BetterHelp to pay $7.8 million as compensation to users who signed up for BetterHelp’s services between Aug. 1, 2017 and Dec. 31, 2020. The compensation is intended to recoup costs patients paid to BetterHelp. The average patient paid an average $60 – $90 per week for these counseling services. The proposed order would also prohibit BetterHelp from sharing consumers’ health data for advertising, sharing their personal information for re-targeting, or serving ads to consumers who had visited the company’s website or app. The FTC is pushing for BetterHelp to accept a settlement where the company agrees to limit their data sharing in the future and the company would be directed to contact affected consumers about the case and must also direct third parties such as Facebook or Pinterest to delete consumers’ health and other personal data shared with them.

    Consumer Privacy Investigative Report

    During the Covid-19 pandemic, Jezebel gathered information on how BetterHelp handles its users’ data by having Jezebel employees sign up for therapeutic services and monitoring the kinds of information BetterHelp was collecting and sending to third parties. When presented with the findings, BetterHelp said their methods were “standard and that they far exceed all applicable, regulatory, ethical and legal requirements.” Jezebel reported that BetterHelp slipped data to dozens of third parties, monitored their behavior online, and signaled to companies like Facebook, Google, Snapchat, and Pinterest that the applicants were considering BetterHelp services.

    The FTC’s investigation followed the investigative report. The Commission states that in December 2020 BetterHelp changed its privacy statement to say, “Rest assured – your health information will stay private between you and your counselor” which was in use until September 2021. Upon notice of the FTC’s investigation and public pressure from consumers, the company changed its privacy statement again in October 2021 to say that it does disclose visitors’ IP addresses and other personal identifiers for advertising, and offered visitors an opportunity to out of these disclosures. Users did not have the option to opt out prior to October 2021.

    The FTC describes two methods that BetterHelp used to send information to Facebook.

    • In the first, the company compiled visitors’ and users’ email addresses which they then uploaded to Facebook to match the individuals with their Facebook user accounts for the purposes of targeting them and others like them with advertisements.
    • Secondly, between 2013 and December 2020, Better Help shared visitors’ and users’ email address, their IP address, and records known as “events” to Facebook. These events automatically tracked when each visitor or user on the main website or affiliate websites answered certain questions on the intake questionnaire or when they enrolled in a certain service. BetterHelp automatically disclosed these events to Facebook through what are known as web beacons that were placed on every website they operated.

    With two consumer privacy class actions looming and the FTC’s administrative complaint, BetterHelp faces significant pressure to make serious changes.

    By Hunter Schmitz

    By Hunter SchmitzGuest Writer

    Hunter Schmitz is a freelance legal writer and paralegal with Focus on Property Law and Civil Litigation.

  • Pixel Litigation the Latest Craze in Privacy Law

    Pixel Litigation the Latest Craze in Privacy Law

    Meta, Google Face Barrage of Pixel Lawsuits in Digital Privacy War

    Photo by Amal S on Unsplash

    META PLATFORMS INC. AND GOOGLE  are currently facing nearly 70 lawsuits involving large companies and some hospital systems or individual health care providers utilizing Pixel tracking tools embedded on their websites and applications. Sensitive private data such as financial information gathered from filing tax returns online or patient healthcare information stored on patient portals is being actively tracked and sent to Meta and Google for both analytical and advertising purposes.

    Tracking pixels are a 1×1 Pixel graphic that serves as a snippet of code used for tracking user behavior, site conversions, web traffic, and other metrics generated from a site’s server. In 2018, Meta told Congress that there were more than 2 million Pixels across the web, which at the time, was one of the largest data-harvesting operations most internet users had ever seen. Meta makes their Pixel code freely available to anyone and any business – thus the amount of Pixel tracking has exponentially grown since Meta testified before Congress. The analytical information that companies gleam from Pixel tracking is paying off and is featured on everything from fast food companies such as Chick-Fil-A, media companies like iHeart Radio, and even tax-filing websites such as Tax Slayer or TaxAct.

    Pixel Tax Data

    On November 22, 2022, theverge.com co-published a report with The Markup, revealing that Pixel tracking tools located on several renown American tax-filing websites were sending individual tax filers’ contact and financial information to Meta and Google. From January to July 2022, The Markup tracked websites’ use of the Pixel as part of the Pixel Hunt in partnership with Mozilla Rally. Participants of the Pixel Hunt installed a browser extension that provided The Markup with a copy of all data shared with Meta through the Pixel. H&R Block, Tax Slayer, and Tax Act utilized Pixels on their websites and applications that sent financial data to Meta according to the data-driven report.

    TaxAct’s Pixel sent some of their users’ tax data to Facebook, including their filing status, adjusted gross income, and the amount of their tax return, if applicable. TaxAct says it has about “three million consumer and professional users”. The Pixel Hunt also revealed that TaxAct’s embedded Pixels were sending data to Google Analytics as well. The Pixel Hunt also revealed that Tax Slayer, H&R Block, and Intuit were also sending specific types of data to Meta and Google.

    The audit on Tax Slayer revealed that their embedded Pixel was gathering and sharing information such as phone numbers, the name of the user filling out the tax forms, and names of any dependent added to the return.

    An audit on Intuit, America’s largest online filing software, revealed that the company did employ a Pixel but did not send financial information to Meta, but instead sent usernames and information about the last time a device signed into the Intuit account. Whereas the audit into H&R Block revealed that information was being gathered and shared on filers’ health savings account usage as well as dependents’ college tuition grants and expenses.

    Tax filing is estimated to be an $11 billion industry in the United States with nearly 150 million individual returns filed electronically in 2021 according to this article. Free tax filing preparation and filing options do exist, but it’s limited to people making $73,000 or less and tends to be difficult to use.

    Utilizing the Pixel during their tracking, The Markup found that the Internal Revenue Service directs taxpayers attempting to file for free to some of these tax filing websites with embedded Pixels. TaxAct and Tax Slayer are part of an agreement known as the Free File Alliance. TurboTax (“Intuit”) and H&R Block had participated in this program in the past. Several days after this report was published, a class action lawsuit was filed against Meta in the Northern District of California, John Doe and Jane Doe v. Meta Platforms Inc., et al., 3:22-cv-07557.

    Pixel Healthcare and Patient Data

    Pixels are also utilized by some healthcare systems and individual medical providers in the United States. In another lawsuit regarding Pixel litigation against Meta in the Northern District of California, Jane Doe v. Meta Platforms Inc., et al., 3:22-cv-04293-AGT, the plaintiff alleges that at least 664 hospital systems or medical provider websites have sent data to Meta via its Pixel tracking tools. The plaintiff argues that this tracking of her private health information is in violation of the Health Insurance Portability and Accountability Act (“HIPAA”)

    HIPAA protects the privacy of individually identifiable health information by allowing only certain uses and disclosures of health data, such as for research purposes – but only if this data can’t be linked back to a particular patient. Currently under HIPAA, releasing data that is not properly de-identified could be considered a breach of HIPAA.

    Recently on January 30, 2023, a class-action lawsuit was filed in the Tenth Judicial District of Louisiana regarding a local health care provider, Willis-Knighton Medical Center using Pixel tracking tools to send sensitive patient health data to Meta. The plaintiff in Jacqueline Horton, individually and on behalf of others similarly situated v. Willis-Knighton Medical Center, 93767-B, brought action against Willis-Knighton Medical Center for ‘exposing highly sensitive personal information to third parties without their knowledge or consent.’ The Louisiana case differs from California’s because California is one of the handful of states that has passed a statute related to video privacy and consumer protection.

    In Jane Doe v. Meta Platforms Inc., the website allegedly shared information related to scheduling appointments with a doctor and reviewing test results. The California suit is seeking damages paid to consumers under the Video Privacy Protection Act (“VPPA”) 18 U.S.C. § 2710. This case was also brought under the California Confidentiality of Medical Information Act, that allows for damages of $1,000.00 per violation. In addition, the California court could potentially force hospital systems named in the suit to clearly disclose that their website uses Pixels to share data with Meta. The Plaintiff is also asking the judge to order that Meta delete sensitive health information that could be used to generate specific ads. This case will highlight misunderstandings of how HIPAA protects health information that’s in the hands of health care providers, insurers or any other entity currently subject to existing HIPAA provisions.

    Origins of Pixel Litigation Lawsuits

    The VPPA regulates the disclosure of information about consumers’ consumption of video content and imposes prescriptive requirements to obtain consumers’ consent to such disclosure(s). The law was originally enacted in 1988, a year after a journalist published Supreme Court Justice Robert H. Bork’s video rental history during his nominee process in 1987. The rental history contained no salacious details however and Congress quickly acted to pass the VPPA. The act reads:

    The VPPA prohibits a person or business that rents, sells, or delivers prerecorded “video cassette tapes or similar audio visual materials” from “knowingly disclos[ing], to any person, personally identifiable information concerning any consumer of such provider . . . .,” absent informed, written consent as defined by the VPPA. 18 U.S.C. § 2710(a)(3). If liability is found, the VPPA allows consumers to seek the following remedies – (1) statutory damages in the amount of $2,500 per violation, (2) punitive damages, and (3) recovery of attorneys’ fees. 18 U.S.C. § 2710(c).

    The VPPA was originally enacted to address the concept of a video tape service provider (“VTSP”). This was associated with traditional video rental stories and was rarely invoked as of lately. As online video services became more prevalent, the VPPA began to create legal barriers to major businesses and marketing opportunities for them. Prior to Congress amending the VPPA in 2013, the law created a strange legal paradigm: An organization’s business model involving the provisions to consumers, either on a standalone basis or as part of its broader online platform of online video content (such as a social media company), makes the organization qualify as a VTSP.

    Congress amended the VPPA in 2013 to provide that disclosure of consumer data to third parties is not wrongful if the consumer elects to give ‘informed, written consent in a form that is distinct and separate from any form setting forth other legal or financial obligations of the consumer at the time the disclosure is sought, or in advance for set period of up to two years.

    Under the amendment, the VPPA does provide a number exceptions that permit information being disclosed to third parties. Remarkably, one of those exceptions allows the sharing of information about the user ‘to any person if the disclosure is solely of the names and addresses of consumers and if: (i) the VTSP has provided the consumer with the opportunity, in a clear and conspicuous manner, to prohibit such disclosure; and (ii) the disclosure does not identify the title, description, or subject matter of any videos or other audio-visual material; however, the subject matter of such materials may be disclosed if the disclosure is for the exclusive use of marketing goods and services directly to the consumer.’

    These exceptions allow the VPPA to permit the disclosure of the name and address of the user together with the identify of the VTSP and subject matter of the video content so long as the intended purpose is for direct marketing. The VPPA has since been challenged in several distinguishable cases decided in 2015 primarily on the grounds of violation of privacy.

    Recent Developments in Pixel Litigation

    The VPPA has come under consumer and legal scrutiny in recent years. Several important legal rulings have largely curtailed individual and collective efforts to declare violations under the VPPA. In Ellis v. Cartoon Network Inc., 803 F.3d 1251 (11th Cir. 2015), it was opinioned that, Consumers who use free mobile applications do not quality as ‘subscribers’ under the VPPA. The Ninth Circuit Court also opinioned two cases in 2015 regarding exceptions to the VPPA.

    In Rodriguez v. Sony Computer Entm’t Am., LLC, 801 F.3d 1049 (9th Cir. 2015), an intra-corporate disclosure of personal information does not violate the VPPA. Then it was also decided by the 9th Circuit Court in another 2015 opinion Mollett v. Netflix Inc. 795 F.3d 1062 (9th Cir. 2015) that VTSPs cannot be held liable under the VPPA for circumstances where subscribers’ personal information was displayed on devices, such as televisions, that could potentially be viewed by third parties. This Court said that ‘viewing of such devices was beyond the companies’ control.’

    These recent rulings narrowed the scope of the VPPA and helped provide definitions for the outdated video-store era law. Civil lawsuits across the nation related to Pixel litigation continues to barrage the integrity of the VPPA.

    IHEARTMEDIA, Inc. is facing a lawsuit for allegations of violations of the VPPA in the Middle District of Florida Gloria Talley, individually and on behalf of herself and all others similarly situated v. IHEARTMEDIA, Inc., 8:32-cv-00215. Similarly the popular chicken chain, Chick-Fil-A is facing a similar class action lawsuit in the Northern District of California in Keith Carroll, individually and on behalf of all others similarly situated v. Chick-Fil-A, Inc., 3:23-cv-00314.

    As lawsuits continue to mount against Meta and Google, the integrity of the VPPA is thrown into question. It is likely that one of the pending actions across the nation will eventually land the law itself into further judicial review, or if Congress acts, could create an entirely new blanket law altogether to help address the rapid interference and sharing of consumer data.

    By Hunter Schmitz

    By Hunter SchmitzGuest Writer

    Hunter Schmitz is a freelance writer and paralegal with Focus on Property Law and Civil Litigation.

  • Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Authors

    Kathryn Rattigan

    Kathryn RattiganRobinson+Cole

    With deep experience in the law and regulation of unmanned aerial vehicles, Kathryn practices in the Providence, R.I., offices of Robinson+Cole. She is a member of the firm’s groups that focus on business litigation, data privacy and security, and drone compliance. Kathryn is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    Blair Robinson

    Blair RobinsonLaw Student

    Blair Robinson is a cybersecurity intern at Robinson+Cole. She will graduate in 2023 with a J.D. from the Roger Williams University School of Law to complement her Masters of Science degree in Cybersecurity also from Roger Williams University.

    Get CLE

    Drone Litigation

    Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Drones have rapidly transformed dozens of industries since hitting the commercial market. International aid groups use medical drones to deliver life-saving medications and vaccines to remote areas. Agricultural drones have revolutionized how farmers tend their fields. Film and television producers embrace drones for their ability to capture once prohibitively expensive or outright impossible camera shots. Hobbyists love the technology for a variety of recreational purposes. 

    However, as drones have become increasingly commonplace, lawmakers and policymakers have struggled with effectively regulating this emerging domain.

    In addition, no federal law, state law, or industry best practice adequately addresses the unique privacy and cybersecurity risks drone operations pose. Until federal regulation catches up with the technology, lawyers could move courts to mitigate the issue by arguing for strict liability for drone operators and manufacturers.

    Although drones may seem like traditional aircraft, they actually pose unique privacy concerns. Drone systems rely on real-time and simultaneous data exchanges between the operator, GPS positioning, cloud-based processing and telemetry, and the drone itself. Each facet in such a complex system presents a new opportunity for attackers. Besides the vulnerability of data traveling between the drone and its control systems, drones are also physically vulnerable. Researchers at the University of Texas Austin successfully hijacked a drone using commercially available equipment. The researchers used a local GPS transmitter to send the drone false GPS coordinates, causing it to fly off its preprogrammed path. The criminal and terror applications are evident – terror groups could use this technique to hijack drones and cause them to fly into buildings, thieves could intercept consumer drone deliveries, and militant groups could capture and ransom critical medical deliveries. Before they can enjoy widespread use, drone operators (and manufacturers) must adequately secure their devices.

    Courts and policymakers have sought to address the obvious and highly publicized issues associated with drone flight, such as irresponsible pilots harassing pedestrians and disrupting airports, while neglecting the novel threat that drones pose to personal privacy.

    Unlike crewed aircraft, drones often use remote cameras and other sensory inputs to guide their operators. In this way, drones are more akin to flying smartphones than traditional crewed aircraft. Additionally, drones can collect visual and other sensory data at a great distance and without alerting the data subject. As a result, individuals whose privacy is infringed will likely never know (or identify) the drone operator, regardless of whether they see the offending device. In addition, the growing ubiquity of drones, such as deliveries to consumers, may further obfuscate a voyeur’s identity.  Was that drone looking through my window or just delivering the neighbor’s package? 

    Surprisingly, the FAA doesn’t have authority to regulate data flow from drones; the Administration considers it outside of its congressional mandate. And while other federal statutes address specific drone data flows, no complete regulatory scheme exists. State-level regulations are similarly lacking. While some states regulate drone use by law enforcement and many smaller localities have piecemeal ordinances regulating drone activity, no state law entirely protects the privacy and security of data flowing to and from civilian drones. While the states have theoretical regulatory authority over drones, they are ultimately ill-suited to address the industry and, in most cases, lack the resources to meet the task. Finally …

    … common tort law falls short here as well. It may address intentional voyeurs, but there’s no common law “negligent invasion of privacy” cause of action to cover accidental disclosures. 

    The courts are the last body that may step in to regulate drone operations in the absence of effective bureaucratic, legislative, or industrial authority. While Supreme Court Associate Justice Samuel A. Alito, Jr. has indicated that legislative action is needed to handle changing technology effectively, the courts have a history of reining in maverick industries. For example, Judge Benjamin N. Cardozo, who would go on to serve on the Supreme Court, famously developed the concept of strict products liability to address unsafe practices in the burgeoning automotive sector. That industry shared many critical elements with today’s drone industry: the emergence of a disruptive new technology promised to both revolutionize human productivity while upsetting traditional notions of public safety. In case before Judge Cardoza, a manufacturer purchased a defective wheel from a third-party supplier. The injured driver had no legal recourse: the automotive manufacturer pointed the finger at their supplier, and the supplier owed no contractual duty to the consumer. Judge Cardozo came up with the legal innovation that underpins modern products liability law: he determined that a manufacturer that enters a product into the stream of commerce must reasonably foresee injury to the ultimate consumer. 

    Faced with another disruptive technology, courts today will likely develop case law that: 1) redefines the duty of care for drone operators for the audio or visual data that they collect in-flight which infringe on the seclusion of others, and 2) imposes strict liability on drone manufacturers for compromises in drone cybersecurity. Under this proposed liability theory, the law would expect drone operators to consider the entire data chain generated by their activities. A bird watcher using a drone to film into a lofty nest, for example, would be held responsible for the content of their video stream if it accidentally spied someone through their bedroom window. This would encourage drone operators to take reasonable care with their flying cameras. While accidental peeks into a neighbor’s home may not be highly offensive, drone-mounted cameras are risky enough to justify a heightened standard of care. This system would also draw attention to the current regulatory gaps and provide a stopgap measure until Congress broadens the FAA’s mandate or enables another regulatory authority. Similarly …

    … this type of strict liability scheme would compel drone manufacturers to consider the possible collateral damage caused by their products.

    For example, the manufacturer of a drone hijacked in a terror plot would be held responsible for failing to protect their product from hackers. Manufacturers are already liable for foreseeable injuries caused by their products, but this proposed modification to products liability law would broaden the definition of reasonably foreseeable injury to include widely publicized exploits such as UT Austin’s GPS spoofing. Again, this burden isn’t unreasonable – manufacturers are in the best position to implement some of the necessary protections and safeguards for widespread drone use. 

    Drones will inevitably become integral to our society; however, without proper regulation the novel legal issues that they raise will stunt the industry’s growth and dampen the many benefits it promises. 

    Congress will need to give the final word on drone use, but the courts – urged by persuasive attorneys – may offer stopgaps to foster sustainable growth in the meantime. Such a model would likely force every participant in the drone data chain to enter privity with the ultimate consumer and give injured individuals a temporary recovery mechanism until Congress empowers the FAA or another agency to regulate drone activity adequately. 

    Download the PDF

  • 7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation?

    By Jennifer M. Oliver

    The outcome of this case will have a dramatic impact on statutory damages.

    The Seventh Circuit U.S. Court of Appeals has certified a question to the Illinois Supreme Court over the accrual of claims under the Illinois Biometric Information Privacy Act (BIPA). The question, posed by the court in Cothron v. White Castle Systems, Inc., reads:

    “Do section 15(b) and 15(d) claims accrue each time a private entity scans a person’s biometric identifier and each time a private entity transmits such a scan to a third party, respectively, or only upon the first scan and first transmission?”

    The case was brought by an employee of the White Castle hamburger chain, which requires fingerprint scans for employees to access computer systems. The plaintiff charged that sharing her fingerprints with a third party vendor violated the law. Cothron v. White Castle Sys., No. 20-3202, 2021 U.S. App. LEXIS 37593 (7th Cir. Dec. 20, 2021).

    An accrual rule based on each collection, opponents to such a finding argue, would pose potentially existential damages — especially in the class action context — since BIPA provides for statutory damages of $1,000 or $5,000 per violation. Parties disagree on whether BIPA damages are mandatory or discretionary, however. Should the court determine that the first scan is the only scan that starts the statute of limitations clock ticking, opponents to that interpretation say,  anyone bringing a claim after five years would be out of luck, even if their private biometric data continued to be transmitted more than five years after the first occurrence.

    Preceding the federal court’s certification of this question by just five days, an Illinois appellate court ruled that, yes, claims under sections 15(a) and (b) accrue with each capture and use of a plaintiff’s biometric  information. Watson v. Legacy Healthcare Financial Services, LLC, et al., 2021 IL App (1st) 210279 No. 1-21-0279, Opinion filed Dec. 15, 2021.

    This is an important case to watch. Illinois was the first to implement such legislation, something several states have since emulated.

    Should the state Supreme Court come down in favor of an “all scans” interpretation, defendants may find themselves on the receiving end of devastating damages multipliers. Of course, the Illinois Supreme Court could determine that damage awards are at the discretion of a court, and are not mandatory under the law. Or it could rule that every scan or transmission restarts the statute of limitations clock, but that a claimant may only collect damages once for a series of transmissions of the same data, similar to how damages for defamation are not based on each publication of the same defaming remarks. Yet another possibility is that the court could determine that the clock starts to run when a claimant first learns of an alleged violation, which has precedent in litigation involving latent diseases caused by products, where individuals cannot know they were harmed until they developed a signature disease, i.e., one connected to a specific product.

    The ruling in this case is especially interesting as the COVID-19 pandemic has led to skyrocketing adoption of remote access tools that can collect biometric data for learning, court appearances, and work-from-home arrangements, and a corresponding uptick in BIPA lawsuits.

    Edited by Tom Hagy for MoginRubin LLP. Reposted with permission from the MoginRubin Blog. © 2022 MoginRubin LLP. 

    The Author

    Jennifer M. Oliver

    Jennifer M. OliverMoginRubin LLP

    Jennifer is a partner in the San Diego offices of MoginRubin LLP, where she focuses on antitrust, complex business, and investment litigation. Her experience includes active roles in several high-profile jury trials, serving as lead counsel in complex mediations, and arguing before courts at both the trial and appellate levels. Jennifer earned her B.S. (Business Administration), M.B.A., and J.D. degrees from the University at Buffalo, each with honors, where she also served as the Vice President of the undergraduate student body and was an editor of the Buffalo Law Review and Buffalo Intellectual Property Law Journal. Jennifer is also a certified information privacy professional.

    We are pleased to add that Jennifer is a member of the Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    More from Jennifer and her colleagues.

  • The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar
    Now on-demand at the West LegalEdcenter
    THE COMMERCIAL DRONE INDUSTRY
    Privacy, Security, Threats, and Mitigation of Risk

    Drones have become an increasingly valuable tool for businesses of all types and sizes.

    Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical.

    Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle.

    Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology.

    Topics:

    • Defining drones.
    • Current and future applications.
    • FAA Modernization and Reform Act of 2012.
    • FAA Part 107 Regulations and waivers.
    • Resources, e.g. the FAA Drone Zone and LAANC Portal.
    • Penalties for violations.
    • Privacy implications.
    • Drones as weapons.
    • Vulnerability to cyber attacks.

    Take it now!

    What you get:

    1+ CLE credits (subject to bar rules).

    Insights from an experienced professional who specializes in this area of the law.

    The complete PowerPoint presentation.

    Continued access to the complete recording for later use.

    Answers to your questions.

    Fee:

    No additional charge to subscribers to the West LegalEdcenter.

    Non-subscribers may take the course for $170.

    Meet the Speaker

    Kathryn Rattigan
    Robinson & Cole LLP

    Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and vendor management. She represents clients across all industries, such as manufacturing, insurance, health care, education, energy, and construction.

    Kathryn helps clients comply with all state and federal regulations related to data privacy and cybersecurity. She is also a member of the firm’s Drone Compliance Team. As such, she advises clients on all legal issues surrounding the use of commercial drones, including navigation of Federal Aviation Administration regulations, commercial registration requirements, and Part 107 waivers.

    She is committed to doing pro bono work and being involved in the community. Her recent efforts include assisting Inner Explorer, a non-profit which works to help students focus and succeed through mindfulness practice in the classroom, and College Visions, which helps low-income students pursue a college education.

    She writes for two of the firm’s blogs, Data Privacy + Security Insider and Health Law Diagnosis.

    More about Kathryn

    Also, listen to my interview with Kathryn for the the Emerging Litigation Podcast!

    –Tom Hagy

  • Does Data Sharing and Zoombombing Cause Actual Harm?

    Does Data Sharing and Zoombombing Cause Actual Harm?

    By Kirsten Errick

    Legal Writer
    Law Street Media

    FTC Settles Health Data Sharing and Privacy Suit With Fertility App Flo Health

    Nothing in this life is free. Or cheap. Free and low-cost apps. Free internet searches. Free email. Free iPhones. Yeah. We’re paying for it one way or the other. In this case, once again, it’s private health information some folks are paying with.  Here is an excerpt of a post shared with the permission of Fastcase and Law Street Media. —Tom Hagy, HB Litigation Conferences

    WASHINGTON, DC — Jan. 13, 2021 — The Federal Trade Commission (FTC)  announced that that it has reached a  proposed settlement with Flo Health, Inc., the “developer of a period and fertility-tracking app used by more than 100 million consumers,” over claims that the company shared user health information with third-party data analytics providers despite promising that this information would remain private.

    In the complaint, the FTC alleged that Flo promised users that it would keep their health data, which includes menstrual cycle tracking and a PMS symptom log, as well as ovulation, fertility, and pregnancy information, private because it would only use this information to provide the app’s services to users. However, the FTC averred that Flo disclosed millions of users’ health data from its Flo Period & Ovulation Tracker app to third-parties “that provided marketing and analytics services to the app, including Facebook’s analytics division, Google’s analytics division, Google’s Fabric service, AppsFlyer, and Flurry.”

    Read the complete story and more at LawStreetMedia.com.

    Safeguarding Against Financial Exploitation

    An on-demand CLE-eligible webinar Safeguarding Against Financial Exploitation   America’s senior population is growing. Nearly one in five U.S. residents will be 65 or older in 2030. Which means the average age of U.S. investors is climbing too. With that comes the risk that they will be exploited by people with access – or gain access through nefarious methods – to their investment portfolio. Seniors and vulnerable persons lose billions of dollars each year. Remarkably, 90% of the people to take advantage of senior investors are members of their own family. Attorneys who represent senior clients need to know the signs of vulnerability, red flags that their clients are being exploited, what laws apply, and rules lawyers must follow in these matters.   Questions our speakers answer: What is senior / vulnerable investor exploitation?   Who is protected by state and federal laws?   How prevalent is senior financial exploitation? What do the numbers tell us?  What is the pace of financial abuse SAR filings by securities firms?  What are the most popular scams?   What is diminished capacity?  What are the red flags indicating possible exploitation?  What are the laws, rules, and regulations governing law firms?  What are some best practices for law firms?  How can firms best protect their senior clients?   On Demand CLE Webinar What You Get PowerPoint and supplemental materials. Complete recording for later review. Answers to your questions via email. Invitation to contact speakers. 1.5 CLE credits (for licensed attorneys). CLE assistance.* *Subject to state bar rules. For licensed attorneys.  Register Meet the Speakers Joseph Calabrese Bressler, Amery & Ross, P.C. A 1991 Graduate of St. John’s University Law School, Mr. Calabrese brings 30 years of practice and 18 years of Securities Litigation/Regulatory experience to his role as principal in the New York office of  Bressler, Amery & Ross’s Financial Institutions Group. He began his career as a Wall Street litigator as an associate general counsel for Citigroup’s Smith Barney and […]

    Lien Resolution: Government & Private Plans Get Aggressive (Against Attorneys)

    Includes Nearly 75 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. What can you do to settle personal injury suits cleanly and avoid costly litigation and penalties? What recent cases can inform you about protecting your settlements and, as attorneys, yourselves, from post-settlement federal lawsuits? How can your firm set itself up to meet government expectations? What role might experts play in navigating these pitfalls? Medicare Advantage (42 USC § 1395w-22) Federal Medical Care Recovery Act (FMCRA) (42 USC § 2651) Armed Forces Act (10 USC §1095) Veterans’ Benefits (38 USC §1729) Third-Party Collection Rules (32 CFR 537.24; 38 CFR 17.101, etc.) Set-Asides under the Medicare Secondary Payer Act (42 USC § 1395y(b)(2)] On Demand Registration Lien Resolution Government & Private Plans Get Aggressive (Against Attorneys!) On Demand | Recorded September 2020 It is increasingly common these days. Personal injury attorneys settle a case, only to find themselves sued by a U.S. Attorney for failing to reimburse Medicare for conditional payments as required by the Medicare Secondary Payer Act. In some cases the attorney may be required to pay fines in addition to the reimbursements and interest, a costly proposition. Are you up to speed on issues surrounding Medicare Advantage, TRICARE, veterans’ claims, and Medicare set-asides? Join nationally recognized healthcare lien and resolution expert Franklin P. Solomon and go-to lien resolution provider Brett Newman as they offer a practical, in-depth CLE presentation. Franklin P. Solomon, Esq. Attorney & Founder, Solomon Law Firm  A graduate of Rutgers University School of Law at Camden, Franklin Solomon is based in Cherry Hill, NJ, with a practice focused on evaluation, litigation and resolution of healthcare “liens” and reimbursement claims. Mr. Solomon represents personal injury victims and their attorneys […]

    Telepsychiatry: Mitigating the Risks

    REGISTER Registration Includes Nearly 90 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. Understand the risks associated with telepsychiatry and how to manage them.  Telemedicine has emerged as an important solution for healthcare in general and psychiatric medicine specifically during the current global pandemic. Remote access for sub-practices including addiction counseling have been commonly used. Our panel of psychiatric professionals who have served as expert witnesses and attorneys who counsel and represent physicians have prepared a 90-minute session to share insights with attorneys, physicians, healthcare providers, risk professionals, and more. Agenda Examining procedures and best practices that exist for ensuring confidentiality in a telemedicine practice How do you draft a telepsychiatric consent form? What is the emerging standard of care for telemedicine? Will the standard of care for telemedicine become a national standard? (Should it?) Review the case law addressing telemedicine or telepsychiatry How do the HIPAA regulations and HITECH privacy laws impact telemedicine? How have the HIPAA regulations and HITECH privacy laws been relaxed during the pandemic? Will the relaxed HIPAA and HITECH regulations impacting telemedicine continue past the pandemic? Which technical platforms are preferred? Which ones to avoid? Panelists Mark Levy, M.D., Medical Director at fpamed David Kan, M.D., UCSF Psychiatry Department and the California Society for Substance Abuse Medicine Ayesha Ashai, M.D., associated with fpamed Stephen M. Fatum, J.D., Partner, Barnes & Thornburg LLP Angela W. Russell, J.D., Partner, Wilson Elser Moskowitz Edelman & Dicker LLP Meet our physician and attorney panelists. Mark Levy MD Medical Director fpamed Dr. Levy is a graduate of Columbia College (A.B. 1967) and the Columbia University College of Physicians and Surgeons (M.D. 1971) in New York. He is a Physician […]

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar Now on-demand at the West LegalEdcenter THE COMMERCIAL DRONE INDUSTRY Privacy, Security, Threats, and Mitigation of Risk Drones have become an increasingly valuable tool for businesses of all types and sizes. Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical. Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle. Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology. Topics: Defining drones. Current and future applications. FAA Modernization and Reform Act of 2012. FAA Part 107 Regulations and waivers. Resources, e.g. the FAA Drone Zone and LAANC Portal. Penalties for violations. Privacy implications. Drones as weapons. Vulnerability to cyber attacks. Take it now! What you get: 1+ CLE credits (subject to bar rules). Insights from an experienced professional who specializes in this area of the law. The complete PowerPoint presentation. Continued access to the complete recording for later use. Answers to your questions. Fee: No additional charge to subscribers to the West LegalEdcenter. Non-subscribers may take the course for $170. Meet the Speaker Kathryn Rattigan Robinson & Cole LLP Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and […]

    The Intersection of Privacy and Antitrust Webinar Now Available On-Demand on the West LegalEdcenter

    Available as part of your subscription to The Thomson Reuters West LegalEdcenter®. Don’t subscribe to the West LegalEdcenter? This webinar is still available directly from HB. Take it now! Questions for speakers Questions@LitigationConferences.com CLE questions CLE@LitigationConferences.com Check out the MoginRubin blog for more insights on antitrust and privacy law. What attorneys and companies need to know about the increasing interplay between these critical areas of the law.  Highly publicized cases and investigations in the U.S. and Europe of big technology, e-commerce, and social media companies demonstrate how anti-competition laws are being used to scrutinize and challenge not only how these corporations conduct themselves in the marketplace, but the very core of their colossal success: the mass collection and utilization of user data. Are the privacy and antitrust worlds beginning to cross over? Or do they simply run parallel while addressing entirely different types of conduct? Whatever the answer, data is the raw material that drives the likes of Google, Facebook, Apple and Amazon, so how it is handled is a critical question when counseling clients on mergers and acquisitions. Moderator Daniel J.  Mogin | Managing Partner, MoginRubin LLP Speakers Jennifer M. Oliver, CIPP/US | Partner, MoginRubin LLP Thomas N. Dahdouh | Director, Western Region, Federal Trade Commission Franklin M. Rubinstein | Partner, Wilson Sonsini Goodrich & Rosati Randi W. Singer, CIPP/US, CIPT | Partner, Weil, Gotshal & Manges Contributor Dina Srinivasan | Independent Researcher & Author of The Antitrust Case Against Facebook Dina was unable to present but we thank her for her content contributions.  Agenda Who should regulate privacy violations in the U.S.? Which antitrust issues implicate privacy concerns? What role does machine learning play on the competitive landscape? What is big data really? How is it different from “data”? What are the elements of effective merger reviews? What are the appropriate remedies? What are “notice-and-choice” versus “harms-based” approaches? Plus answers to your questions. Send them to Questions@LitigationConferences.com.

  • Does Data Sharing and Zoombombing Cause Actual Harm?

    Does Data Sharing and Zoombombing Cause Actual Harm?

    By Kirsten Errick

    Legal Writer
    Law Street Media

    Zoom Says Data Sharing, Zoombombing Doesn’t Cause Personal Harm

    Zoom is a good name for this company. It seems to have come out of nowhere to become the new verb for web meetings, robbing that distinction from many more established competitors like WebEx and GoToMeeting, maybe because they don’t have cool web-sounding names, although people don’t seem to be saying “let’s Skype later,” as much as they used to. Sure, we still “Facetime,” but Zoom really shot to the top when it comes to name recognition. According to CNBC’s Ari Levy, Zoom reported fiscal third-quarter revenue growth of more than 300% after seeing 355% expansion in the prior period. The company’s stock was up almost seven-fold this year but “pulled back in November on positive news surrounding a coronavirus vaccine,” Levy reported. And with success comes risk, especially when dealing with private data.  Here is an excerpt of a post shared with the permission of Fastcase and Law Street Media. –Tom Hagy, HB Litigation Conferences

    Dec. 4, 2020 (San Francisco) — On Wednesday [Dec. 2], in the Northern District of California, Zoom Video Communications filed a motion to dismiss the plaintiffs’ first amended consolidated class action complaint (FAC) on the grounds that the FAC failed to state a claim for which relief may be granted.

    The consolidated complaint alleged that Zoom engaged in unauthorized data sharing with third parties, such as Facebook, LinkedIn, and Google. Additional complaints included an alleged failure to prevent unwanted meeting disruptions by outside parties, called Zoombombing; and misrepresentation of its encryption protocols claiming it used end-to-end encryption when it purportedly did not provide such encryption.

    Zoom stated that it faced unprecedented growth resulting from the COVID-19 pandemic, as people began using Zoom for teleconferences and to communicate with friends and family, but it “worked tirelessly since the pandemic’s onset to keep its services operational and secure, while developing and deploying extensive privacy and security enhancements to address new challenges caused by the massive uptick in non-corporate usage.”

    In its motion to dismiss, Zoom stated “(i)n an effort to capitalize on Zoom’s explosive growth during the COVID-19 pandemic, Plaintiffs seek to hold Zoom liable on behalf of a nationwide class under a scattershot array of loosely related factual and legal theories, largely drawn from sensationalist news reports.” Zoom claimed that in the latest attempt, the plaintiffs still failed to state claims upon which relief may be granted; instead, the plaintiffs’ FAC supposedly “recycles the same flawed claims as Plaintiffs’ original consolidated complaint (CAC) … with a few minor additional factual allegations.”

    Zoom averred that all of the plaintiffs’ claims fail because they do not allege that they were harmed by the company. Zoom contended that the plaintiffs failed to claim personal harm from the purported data sharing, meeting disruptions, and alleged misrepresentations and omissions about encryption.

    Read this and more at LawStreetMedia.com.

    Safeguarding Against Financial Exploitation

    An on-demand CLE-eligible webinar Safeguarding Against Financial Exploitation   America’s senior population is growing. Nearly one in five U.S. residents will be 65 or older in 2030. Which means the average age of U.S. investors is climbing too. With that comes the risk that they will be exploited by people with access – or gain access through nefarious methods – to their investment portfolio. Seniors and vulnerable persons lose billions of dollars each year. Remarkably, 90% of the people to take advantage of senior investors are members of their own family. Attorneys who represent senior clients need to know the signs of vulnerability, red flags that their clients are being exploited, what laws apply, and rules lawyers must follow in these matters.   Questions our speakers answer: What is senior / vulnerable investor exploitation?   Who is protected by state and federal laws?   How prevalent is senior financial exploitation? What do the numbers tell us?  What is the pace of financial abuse SAR filings by securities firms?  What are the most popular scams?   What is diminished capacity?  What are the red flags indicating possible exploitation?  What are the laws, rules, and regulations governing law firms?  What are some best practices for law firms?  How can firms best protect their senior clients?   On Demand CLE Webinar What You Get PowerPoint and supplemental materials. Complete recording for later review. Answers to your questions via email. Invitation to contact speakers. 1.5 CLE credits (for licensed attorneys). CLE assistance.* *Subject to state bar rules. For licensed attorneys.  Register Meet the Speakers Joseph Calabrese Bressler, Amery & Ross, P.C. A 1991 Graduate of St. John’s University Law School, Mr. Calabrese brings 30 years of practice and 18 years of Securities Litigation/Regulatory experience to his role as principal in the New York office of  Bressler, Amery & Ross’s Financial Institutions Group. He began his career as a Wall Street litigator as an associate general counsel for Citigroup’s Smith Barney and […]

    Lien Resolution: Government & Private Plans Get Aggressive (Against Attorneys)

    Includes Nearly 75 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. What can you do to settle personal injury suits cleanly and avoid costly litigation and penalties? What recent cases can inform you about protecting your settlements and, as attorneys, yourselves, from post-settlement federal lawsuits? How can your firm set itself up to meet government expectations? What role might experts play in navigating these pitfalls? Medicare Advantage (42 USC § 1395w-22) Federal Medical Care Recovery Act (FMCRA) (42 USC § 2651) Armed Forces Act (10 USC §1095) Veterans’ Benefits (38 USC §1729) Third-Party Collection Rules (32 CFR 537.24; 38 CFR 17.101, etc.) Set-Asides under the Medicare Secondary Payer Act (42 USC § 1395y(b)(2)] On Demand Registration Lien Resolution Government & Private Plans Get Aggressive (Against Attorneys!) On Demand | Recorded September 2020 It is increasingly common these days. Personal injury attorneys settle a case, only to find themselves sued by a U.S. Attorney for failing to reimburse Medicare for conditional payments as required by the Medicare Secondary Payer Act. In some cases the attorney may be required to pay fines in addition to the reimbursements and interest, a costly proposition. Are you up to speed on issues surrounding Medicare Advantage, TRICARE, veterans’ claims, and Medicare set-asides? Join nationally recognized healthcare lien and resolution expert Franklin P. Solomon and go-to lien resolution provider Brett Newman as they offer a practical, in-depth CLE presentation. Franklin P. Solomon, Esq. Attorney & Founder, Solomon Law Firm  A graduate of Rutgers University School of Law at Camden, Franklin Solomon is based in Cherry Hill, NJ, with a practice focused on evaluation, litigation and resolution of healthcare “liens” and reimbursement claims. Mr. Solomon represents personal injury victims and their attorneys […]

    Telepsychiatry: Mitigating the Risks

    REGISTER Registration Includes Nearly 90 minutes of insights from experienced professionals. CLE credit: 1+ (subject to bar rules). For CLE questions: CLE@LitigationConference.com The complete Power Point presentation. Continued access to the complete recording for later use. Answers to your questions via email to the presenters or write to HB and we will be sure to contact the speakers. Understand the risks associated with telepsychiatry and how to manage them.  Telemedicine has emerged as an important solution for healthcare in general and psychiatric medicine specifically during the current global pandemic. Remote access for sub-practices including addiction counseling have been commonly used. Our panel of psychiatric professionals who have served as expert witnesses and attorneys who counsel and represent physicians have prepared a 90-minute session to share insights with attorneys, physicians, healthcare providers, risk professionals, and more. Agenda Examining procedures and best practices that exist for ensuring confidentiality in a telemedicine practice How do you draft a telepsychiatric consent form? What is the emerging standard of care for telemedicine? Will the standard of care for telemedicine become a national standard? (Should it?) Review the case law addressing telemedicine or telepsychiatry How do the HIPAA regulations and HITECH privacy laws impact telemedicine? How have the HIPAA regulations and HITECH privacy laws been relaxed during the pandemic? Will the relaxed HIPAA and HITECH regulations impacting telemedicine continue past the pandemic? Which technical platforms are preferred? Which ones to avoid? Panelists Mark Levy, M.D., Medical Director at fpamed David Kan, M.D., UCSF Psychiatry Department and the California Society for Substance Abuse Medicine Ayesha Ashai, M.D., associated with fpamed Stephen M. Fatum, J.D., Partner, Barnes & Thornburg LLP Angela W. Russell, J.D., Partner, Wilson Elser Moskowitz Edelman & Dicker LLP Meet our physician and attorney panelists. Mark Levy MD Medical Director fpamed Dr. Levy is a graduate of Columbia College (A.B. 1967) and the Columbia University College of Physicians and Surgeons (M.D. 1971) in New York. He is a Physician […]

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar Now on-demand at the West LegalEdcenter THE COMMERCIAL DRONE INDUSTRY Privacy, Security, Threats, and Mitigation of Risk Drones have become an increasingly valuable tool for businesses of all types and sizes. Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical. Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle. Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology. Topics: Defining drones. Current and future applications. FAA Modernization and Reform Act of 2012. FAA Part 107 Regulations and waivers. Resources, e.g. the FAA Drone Zone and LAANC Portal. Penalties for violations. Privacy implications. Drones as weapons. Vulnerability to cyber attacks. Take it now! What you get: 1+ CLE credits (subject to bar rules). Insights from an experienced professional who specializes in this area of the law. The complete PowerPoint presentation. Continued access to the complete recording for later use. Answers to your questions. Fee: No additional charge to subscribers to the West LegalEdcenter. Non-subscribers may take the course for $170. Meet the Speaker Kathryn Rattigan Robinson & Cole LLP Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and […]

    The Intersection of Privacy and Antitrust Webinar Now Available On-Demand on the West LegalEdcenter

    Available as part of your subscription to The Thomson Reuters West LegalEdcenter®. Don’t subscribe to the West LegalEdcenter? This webinar is still available directly from HB. Take it now! Questions for speakers Questions@LitigationConferences.com CLE questions CLE@LitigationConferences.com Check out the MoginRubin blog for more insights on antitrust and privacy law. What attorneys and companies need to know about the increasing interplay between these critical areas of the law.  Highly publicized cases and investigations in the U.S. and Europe of big technology, e-commerce, and social media companies demonstrate how anti-competition laws are being used to scrutinize and challenge not only how these corporations conduct themselves in the marketplace, but the very core of their colossal success: the mass collection and utilization of user data. Are the privacy and antitrust worlds beginning to cross over? Or do they simply run parallel while addressing entirely different types of conduct? Whatever the answer, data is the raw material that drives the likes of Google, Facebook, Apple and Amazon, so how it is handled is a critical question when counseling clients on mergers and acquisitions. Moderator Daniel J.  Mogin | Managing Partner, MoginRubin LLP Speakers Jennifer M. Oliver, CIPP/US | Partner, MoginRubin LLP Thomas N. Dahdouh | Director, Western Region, Federal Trade Commission Franklin M. Rubinstein | Partner, Wilson Sonsini Goodrich & Rosati Randi W. Singer, CIPP/US, CIPT | Partner, Weil, Gotshal & Manges Contributor Dina Srinivasan | Independent Researcher & Author of The Antitrust Case Against Facebook Dina was unable to present but we thank her for her content contributions.  Agenda Who should regulate privacy violations in the U.S.? Which antitrust issues implicate privacy concerns? What role does machine learning play on the competitive landscape? What is big data really? How is it different from “data”? What are the elements of effective merger reviews? What are the appropriate remedies? What are “notice-and-choice” versus “harms-based” approaches? Plus answers to your questions. Send them to Questions@LitigationConferences.com.

  • European Union’s Top Court Strikes Down EU-US Privacy Shield

    European Union’s Top Court Strikes Down EU-US Privacy Shield

    European Union’s Top Court Strikes Down EU-US Privacy Shield

    The Court of Justice for the European Union has invalidated the EU-US Privacy Shield as an approved mechanism for transferring personal data from the European Union to the United States. The Privacy Shield had been in place since October 2015, and enabled U.S. companies to more easily receive personal data from EU entities. The decision by the court “leaves many companies scrambling to implement alternative mechanisms to safeguard personal data transfers to the U.S.,” says Sten-Erik Hoidal of Frederikson & Byron, P.A. With the invalidation of the privacy shield, companies are essentially left to decide on their own how data will be lawfully transferred. Attorneys from Perkins Coie recommend companies “consider amending any data processing addenda (DPAs) which companies have signed with vendors or customers to incorporate the EU Standard Contract Clauses.” Moving forward, U.S. and European companies will now attempt to create a new deal that complies with the privacy standards for transferring digital information. The first large company to weigh in on the decision, Microsoft tells customers that they “can continue to use Microsoft services in full compliance with European law” and that the ruling “does not change the data flows of our services to Consumers.”  

    Photo by Tabrez Syed on Unsplash

    Send Us Your News