Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

CLIENT ALERT: Ohio Incentivizes Cybersecurity Measures

Client Alert

On November 2, 2018, Ohio’s Data Protection Act (“DPA”) went into effect.  The DPA incentivizes Ohio businesses to proactively address cybersecurity and data protection by providing an affirmative defense/safe harbor for claims related to data breach. However, the safe harbor is only applicable if the organization can prove “reasonable compliance” to the DPA.

Brennan Manna Diamond (“BMD”) can assist your business by creating written policies that demonstrate compliance with Ohio law in the spirit of the DPA.  Additionally, BMD can educate your organization as to implementing and adhering to those policies.

The DPA is the culmination of Ohio’s efforts to foster a legal, technical, and collaborative cybersecurity environment to help businesses thrive. The only way to reap this benefit is to meet its requirements.

How to Comply

Any organization maintaining personal information of Ohio residents can be subject to Ohio’s breach notification laws and potential civil liability for data breach compromising such information.  The DPA rewards proactivity vs. reactivity by incentivizing businesses to implement policies and procedures to protect the security and confidentiality of personal/restricted information, protect against any anticipated threats or hazards to the security or integrity of the personal/restricted information and protect against unauthorized access of information that is likely to result in a material risk of identity theft or other fraud. Businesses should take the following steps:

  • Businesses must determine “reasonable” security measures. Such analysis must consider:
    •  The size of the business;
    • The nature, sensitivity and use of information;
    • The resources available to the business; and
    • The cost to implement and maintain the reasonable security measures to protect against a breach of security relative to the business’ resources.
  • Businesses must implement a cybersecurity framework and the DPA recognizes certain existing frameworks of which businesses can utilize in order to qualify for safe harbor. These include:
    • Industry recognized cybersecurity frameworks, (i.e., those recommended by administrative bodies, like the National Institute of Standards and Technology (NIST);
    • Regulatory frameworks required by federal or state law (i.e., HIPAA, Gramm-Leach-Bliley); or
    • A framework that combines the payment card industry (PCI) data security standard with a current version of an applicable industry recognized cybersecurity framework.
  • Businesses must create and maintain written cybersecurity policies and procedures. Such policies and procedures must contain administrative, technical, and physical safeguards for the protection of personal/restricted information.
  • Businesses must periodically review changes in regulations and framework updates and must likewise update its cybersecurity program.

BMD's Solution

In addition to implementing industry standard cybersecurity frameworks, prudent businesses will create and maintain written policies as it relates to cybersecurity and data protection. BMD can assist in crafting the policies and identifying proper security frameworks so that your business qualifies for the safe harbor. The Ohio legislature was mindful not to be hyper-technical with the regulations so that businesses can still qualify for the safe harbor by demonstrating reasonable efforts to comply. BMD can help navigate these regulations.

In today’s ever-changing cybersecurity landscape, data breaches are at times, inevitable. BMD can also provide post-breach solutions including meeting applicable reporting requirements and litigation defense. As now enacted by Ohio, perhaps the best defense involves proactively investing in front end compliance.

For more information, please contact Brandon T. Pauley. 


Valley National Bank/Trulieve Loan: A Big Step Out of the Shadows

In a late December press release, Trulieve announced that it had secured a $71.5 million commercial bank loan. In addition to the amount of the loan, which may be the largest commercial bank loan to date to a cannabis company, the release prominently identified Valley Bank and featured both a quote from Valley’s Senior Vice President, John Myers, and a description of the Bank’s service platform and commitment to the cannabis industry.

The End of Non-Competes? The Impact It Will Have on the Healthcare Industry

On January 5, 2023, the Federal Trade Commission (“FTC”) announced a proposed rule that, if enacted, will ban employers from entering into non-compete clauses with workers (the “Rule”), and the Rule would void existing non-compete agreements. In their Notice, the FTC stated that if the Rule were to go into effect, they estimate the overall earnings of employees in the United States could increase by $250 billion to $296 billion per year. The Rule would also require employers to rescind non-competes that they had already entered into with their workers. For purposes of the Rule, the FTC has defined “worker” to also include any employees, interns, volunteers, and contractors.”

2022 Healthcare Recap and 2023 Healthcare Check-Up

As the country begins to return to a new “normal” following the COVID-19 pandemic, there are many healthcare rules changing on both the federal and state levels as a result. Thus, it is important for healthcare providers and their employers to be aware of these changing rules, and any implications they may have on their practice. Look back on healthcare in 2022 and find a checklist for 2023.

Direct Support Professional Retention Payments

On December 15, the Ohio Senate and House passed House Bill 45, which authorizes the Department of Developmental Disabilities (DODD), in conjunction with the county boards of developmental disabilities, to launch their initiative to issue retention payments to Direct Support Professionals (DSPs). These retention payments will be distributed quarterly to participating home and community-based waiver providers to address the workforce crisis in the direct provider sector. Governor DeWine needs to sign the Bill to begin the payments, but he is expected to do so by the end of 2022.

Real Estate Investors Position for 2023 Opportunities

Real estate investors weathered another year in a post-pandemic world, with the year closing with yet another interest rate increase coupled with both uncertainty and heightened interest carrying into 2023. Just last Wednesday, the Federal Reserve raised its benchmark interest rate 0.50 percentage points, shifting the target range to 4.25% to 4.50%. The new level is the highest the fed funds rate has been since December 2007 and marks the seventh rate hike this year. So what does this mean to investors, brokers, lenders, and others in the real estate world? Read a few perspectives below from stakeholders familiar with our BMD clients and the markets in which they do business.