Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

CLIENT ALERT: The European Union's New Data Privacy Law Goes Into Effect

Client Alert

On May 25, 2018, the European Union’s (“the EU”) new data privacy law went into effect.[1]   The General Data Protection Regulation (“GDPR”) concerns the processing of personal data that can be searched according to specified criteria such as geographical scope. 

Who it affects

The GDPR applies to all organizations that maintain offices or store data in the EU.  It also applies to many of the core organizations on the web.  For instance, it applies to social media, apartment rental, e-commerce, and internet search sites.  If your website conducts business in the EU, then the GDPR will apply.  Additional factors that would require a company to be GDPR compliant include sales or marketing to EU citizens, accepting any EU country’s currency, an EU country domain suffix, shipping services to the EU, or language translation or website in an EU language.

General global marketing does not require GDPR compliance.  If you use Google Adwords, and an EU citizen and resident visits your webpage as a result of this ad, the GDPR would not apply because there was no targeted interface with EU citizens.  The fact that an unsolicited EU citizen can and does visit your website does not require your organization to be GDPR compliant.  If you take no steps to interface with EU citizens, GDPR compliance is not required. 

Steps you should take now if your organization must be GDPR compliant

  • Provide customers and website visitors with detailed information on how data will be collected and used.
  • Redesign consent forms so that users must affirmatively agree to all uses of their data, and they can select those uses to which they agree and those to which they decline.
  • Create forms that distinguish between consent versus agreement to general terms and conditions.
  • Store customer preferences.
  • Audit data regularly, including where data is stored, why data is collected, how data is obtained, and how much duplication of data exists across multiple sites.
  • Audit your service providers’ data, and review their data procedures.
  • Understand whether your organization is a data processor or data controller. A processor processes personal data on behalf of a controller, whereas a controller determines the purpose and means of how data is processed.
  • Ask for explicit consent from consumers anytime you want to use data for ad targeting purposes.
  • Use “group data” that isn’t precise enough to target individual consumers.
  • Implement procedures and technology that ensures data can be permanently erased.
  • Appoint a Data Protection Officer who is knowledgeable about the GDPR to oversee compliance with respect to data collection, storage, and data processing.
  • Train all employees that have access to personal data on the GDPR requirements, including the requirement that internal data on employees must comply with the GDPR.
  • Prepare for data breaches by creating internal processes to detect, report, and investigate breaches in compliance with the GDPR.

What organizations should NOT do if you are required to be GDPR complaint

  • Rely on the E.U.-U.S. Privacy Shield to avoid compliance with the GDPR. Companies are still required to comply with the GDPR in order to receive Privacy Shield coverage, and the scope of the GDPR is much wider than the scope of the Privacy Shield.
  • Create exposure to the hefty penalties imposed by the GDPR for non-compliance. Companies are liable for 4% of their annual turnover or 20 million Euros, whichever is greater.
  • Risk reputational damage by receiving attention for non-compliance. The first companies to be penalized are more likely to receive significant media coverage for their noncompliance. 

There may be legal challenges to GDPR regarding applicability to non-EU companies 

This is a new, unprecedented law. The previous European data privacy law, the Data Protection Directive, was implemented in 1998, and was much narrower in scope.  The GDPR’s applicability and requirements are vast, and non-EU companies are likely to bring legal challenges in terms of its applicability to them. 

Who to contact with questions

Should you have any questions concerning the General Data Protection Regulation, please contact Matthew A. Heinle, Esq. (maheinle@bmdllc.com), who is a partner at Brennan, Manna & Diamond.

 

[1] General Data Protection Regulation, https://gdpr-info.eu/.


HHS Provider Relief Funds Reporting Requirements: Important Updates Every Provider Should Know

HHS continues to revise its reporting requirements for the use of the Provider Relief Funds. Providers with more than $10,000 in Provider Relief Fund payments must report on the use of the funds through December 31, 2020. The reporting window will begin on January 15, 2021 and providers must complete reporting obligations for FY 2020 by February 15, 2021 through a portal designed by HHS. However, providers that have unexpended funds as of December 31, 2020, will have an additional 6 months to use the remaining funds through June 30, 2021. These providers must submit a second and final report no later than July 31, 2021.

Should I Apply for Phase 3 Funds? Important Considerations Every Provider Should Know

On October 1, 2020, the Department of Health and Human Services (“HHS”) announced an additional $20 billion in new funding for providers through a Phase 3 distribution. Importantly, providers that previously received HHS Provider Relief Funds or already received payments of approximately 2% of annual revenue from patient care are eligible to apply. Eligible providers have until November 6, 2020 to apply for these Phase 3 Funds. However, the question from providers continues to be: Should I Apply for Phase 3 Funds?

CISA Ransomware Practices

On October 28, 2020, the United States Cybersecurity and Infrastructure Security Agency (CISA) issued an alert warning of imminent threats to US hospitals and healthcare providers. The specific threat involves RYUK Ransomware attacks. RYUK is a novel ransomware that goes undetected by commercial anti-virus/malware detection programs. Once deployed, RYUK encrypts all data and disables systems. In short, it cripples all functionality down to phone systems and automated doors. Healthcare providers should alert their employees to remain hyper-vigilant and report any suspicious activity seen in email or on networks. It has been reported healthcare providers in New York, Pennsylvania and Oregon have been targeted in the last 48 hours. If your organization encounters issues, BMD can assist in mobilizing a response team and has contacts with forensic IT firms that are familiar with RYUK. It is advisable to engage professionals with experience dealing with this specific threat.

HHS Announces an Additional $20 Billion In Provider Relief Grants

The U.S. Department of Health and Human Services (“HHS”) announced an additional $20 billion in new funding for providers on October 1, 2020. Eligible providers include those that have already received Provider Relief Fund payments as well as previously ineligible providers, such as those who began practicing in 2020, and an expanded group of behavioral health providers confronting the emergence of increased mental health and substance use issues exacerbated by the pandemic. The new Phase 3 General Distribution is designed to balance an equitable payment of 2% of annual revenue from patient care for all applicants plus an add-on payment to account for revenue losses and expenses attributable to COVID-19.

DOL Proposes New Rule Regarding Independent Contractor Status - But How Will the Election Affect Its Future?

On September 22, 2020, the U.S. Department of Labor announced a new proposed rule regarding employee and independent contractor status under the Fair Labor Standards Act. The full text of the proposed rule is available here. The rule's drafters intend to reduce uncertainty and enhance the precision and predictability of the long-standing "economic reality" test, which currently relies on a multifactor balancing test.