Matthew Fisher


Breach Notification Responsibility

By Matt Fisher – When the likely inevitable data breach occurs, who is responsible for sending the notice? Does the answer change when a breach is bigger? Does the answer change because a business associate is involved? Understanding ahead of time is informative, especially since the issue has been thrown into the spotlight by the big breach at Change Healthcare.


Do Apps Protect Female Health Data?

By Matthew Fisher – mHealth applications focused on women’s health are drawing a fair amount of attention when it comes to privacy practices. These FemTech applications are designed to help individuals personally track different aspects of their health. How does FemTech approach privacy?


FTC Continues Healthcare Action

By Matthew Fisher – On the heels of recent settlements concerning the use of personal and health information, the Federal Trade Commission is continuing its push on the healthcare front. The latest action is the finalization of changes to the Health Breach Notification Rule.


More FTC Privacy Action

By Matthew Fisher – The FTC recently reasserted itself into the privacy discussion when it comes to healthcare information. Given the defined scope of HIPAA that does not cover a number of growing areas where healthcare data can be found, it is important to remember that agencies beyond the HHS OCR can act to require protection.



Coming Together: Part 2 and HIPAA

By Matthew Fisher – HHS released a final rule that will establish greater alignment between Part 2 (privacy of substance use disorder treatment records) and HIPAA. They kicked off the process with a notice of proposed rulemaking that was published on 12/2/22.