• Home
  • News
    • Compliance
      • FCRA
      • FDCPA
      • TCPA
    • Daily Digest
    • Debt Buying
    • Economy
    • General News
    • Getting to Know
    • Healthcare
    • Student Loans
    • Technology
  • Webinars/Events
    • Upcoming Webinars & Events
    • Webinar Recordings
    • W.A.R.M. – Webinar Streaming Channel
  • Jobs
  • Videos
    • Ask The Credit Reporting Expert
    • Behind The Curtain
    • Between The Briefs
    • Customer Experience Week Videos
    • Demo Day Videos
    • Digital Debrief
    • Future Summit 2023
    • Legends of the ARM Industry
    • Q&ARM Videos
    • Teaching Tech
    • Tech Bytes: A Guide to AI
    • Training Bytes
    • Web Bytes
    • You Wanted a Rule; You Got a Rule
  • Premium Content Login
    • Subscribe Now
AccountsRecovery.net
  • Home
  • News
    • Compliance
      • FCRA
      • FDCPA
      • TCPA
    • Daily Digest
    • Debt Buying
    • Economy
    • General News
    • Getting to Know
    • Healthcare
    • Student Loans
    • Technology
  • Webinars/Events
    • Upcoming Webinars & Events
    • Webinar Recordings
    • W.A.R.M. – Webinar Streaming Channel
  • Jobs
  • Videos
    • Ask The Credit Reporting Expert
    • Behind The Curtain
    • Between The Briefs
    • Customer Experience Week Videos
    • Demo Day Videos
    • Digital Debrief
    • Future Summit 2023
    • Legends of the ARM Industry
    • Q&ARM Videos
    • Teaching Tech
    • Tech Bytes: A Guide to AI
    • Training Bytes
    • Web Bytes
    • You Wanted a Rule; You Got a Rule
  • Premium Content Login
    • Subscribe Now
No Result
View All Result
  • Home
  • News
    • Compliance
      • FCRA
      • FDCPA
      • TCPA
    • Daily Digest
    • Debt Buying
    • Economy
    • General News
    • Getting to Know
    • Healthcare
    • Student Loans
    • Technology
  • Webinars/Events
    • Upcoming Webinars & Events
    • Webinar Recordings
    • W.A.R.M. – Webinar Streaming Channel
  • Jobs
  • Videos
    • Ask The Credit Reporting Expert
    • Behind The Curtain
    • Between The Briefs
    • Customer Experience Week Videos
    • Demo Day Videos
    • Digital Debrief
    • Future Summit 2023
    • Legends of the ARM Industry
    • Q&ARM Videos
    • Teaching Tech
    • Tech Bytes: A Guide to AI
    • Training Bytes
    • Web Bytes
    • You Wanted a Rule; You Got a Rule
  • Premium Content Login
    • Subscribe Now
No Result
View All Result
AccountsRecovery.net
No Result
View All Result
Home Compliance

Compliance Digest – January 13

mikegibb by mikegibb
January 13, 2025
in Compliance
0 0
2
0
SHARES
15
VIEWS
Share on FacebookShare on Twitter

I’m thrilled to announce that Bedard Law Group is the new sponsor for the Compliance Digest. Bedard Law Group, P.C. – Compliance Support – Defense Litigation – Nationwide Complaint Management – Turnkey Speech Analytics. And Our New BLG360 Program – Your Low Monthly Retainer Compliance Solution. Visit www.bedardlawgroup.com, email John H. Bedard, Jr., or call (678) 253-1871.

Every week, AccountsRecovery.net brings you the most important news in the industry. But, with compliance-related articles, context is king. That’s why the brightest and most knowledgable compliance experts are sought to offer their perspectives and insights into the most important news of the day. Read on to hear what the experts have to say this week.

HHS Issues Proposed Cybersecurity Rule to Amend HIPAA

With more than 167 million individuals affected by healthcare data breaches in 2023 alone, the Department of Health and Human Services (HHS) is taking action to address increasing cyberattacks on healthcare systems. On Friday, it announced a proposed rule aimed at enhancing the HIPAA Security Rule, compelling healthcare entities to bolster protections for electronic protected health information (ePHI). More details here.

WHAT THIS MEANS, FROM LESLIE BENDER OF EVERSHEDS SUTHERLAND: 2024 was the worst-ever year in healthcare data breaches – up 9.4% over 2023’s record-breaking total to 184,111,469 breached records or a whopping 53% of the 2024 population of the United States.  677 major health data breaches were reported in 2024, most of which were hacking or IT incidents. The well-publicized Change Healthcare ransomware attack in February alone compromised the privacy of over 100 million Americans’ health information. HHS continues to warn all HIPAA-regulated entities about well-organized credential harvesting campaigns.

Against this backdrop and with an emphasis on nudging industry to adopt voluntary cybersecurity best practices and take greater cybersecurity accountability, the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”), released a Notice of Proposed Rulemaking on December 27, 2024, which was published in the Federal Register on January 6, 2025 (the “Proposed Rule”). Comments are due on or before March 7, 2025. 

With an upcoming Administration change you may be wondering what is important about OCR’s Proposed Rule and whether it has enough substance to merit an analysis and possible gap assessment of your organization’s cybersecurity program. Because the changes proposed for HIPAA’s Security Rule help align the regulation’s standards and specifications with modern best practices they are a valuable tool for addressing growing cyber threats and providing more concrete ways to meet HIPAA’s requirements for safeguarding the availability, confidentiality and integrity of patients’ data. Ensuring better protection of electronic protected health information (ePHI) against potential breaches should be near if not at the top of the list for organizations who are entrusted with consumers’ health data in 2025.

Here is a summary of six major features of the Proposed Rule that merit your attention, regardless of whether the Proposed Rule is finalized as published:

  1. Risk Assessments.  Among some of the walk-down-memory lane features of the Proposed Rule is emphasis on the frequency and accountability of risk assessments. When the originally proposed Security Rule called for regular risk assessments, industry scrambled to understand how frequently they should invest the time and resources in the conduct of these assessments. The OCR has clarified that more detailed and frequent risk assessments are a must in the Proposed Rule, and that healthcare entities and their trusted vendors or “business associates” need to be more vigilant in identifying potential vulnerabilities and implementing targeted mitigation strategies to address them effectively.
  2. Stronger Access Controls.  Because threat actors exploit weak credentialing controls, OCR proposes an increased emphasis on robust access controls, including multi-factor authentication, stricter user access management, and regular reviews of user permissions to minimize risks of unauthorized access to ePHI. To illustrate, the Proposed Rule expects HIPAA-regulated entities to be able to pivot and change or terminate users’ access to information systems housing ePHI immediately after they are separated from employment or move to roles that no longer require access.
  3. Improved Incident Response Plans. The Proposed Rule expects a more structured approach to incident response planning, including clear procedures for detecting, reporting, and responding to security breaches, with a focus on timely containment and remediation. 
  4. Network Segmentation. The Proposed Rule encourages HIPAA-regulated entities to adopt network segmentation to isolate sensitive systems and limit the spread of potential breaches within a healthcare network.
  5. Data Encryption Standards. Stricter requirements regarding the encryption of ePHI both at rest and in transit to protect data confidentiality even in case of unauthorized access.
  6. Vendor Management Oversight. The Proposed Rule calls for increased scrutiny on the security practices of third-party vendors handling ePHI, ensuring they adhere to robust security standards. If you are a business associate, be prepared to hear from your covered entity clients who need to ensure that your information security compliance program meets HIPAA’s standards.

Note: There is a publicly available tool for testing your HIPAA Security Rule compliance. A non-regulatory agency of the United States Department of Commerce called “NIST” or the National Institute of Standards and Technology issues special publications or “SPs” for informing the public and private sector in ways to improve cybersecurity, among other things, and publishes a detailed compliance guide for HIPAA’s Security Rule known as NIST SP 800-66.


THE COMPLIANCE DIGEST IS SPONSORED BY:

Bedard Law Group Logo

CFPB Targets Workplace Communications by Debt Collectors in Blog Post

The Consumer Financial Protection Bureau is back with another blog post warning consumers about unfair debt collection practices, this time surrounding being contacted while at work. This follows a post from a couple of weeks ago about junk fees that can be assessed by debt collectors. More details here.

WHAT THIS MEANS, FROM JESSICA KLANDER OF BASSFORD REMELE: The CFPB appears to be focusing its efforts on communications with consumers at the workplace. In particular, the CFPB expressed concerns over collectors apparently contacting employers for unnecessary location information. The CFPB is encouraging consumers to submit complaints regarding workplace contacts on their portal. This is usually a signal of where the CFPB’s enforcement or rule making efforts are headed, so be on the lookout for more on this in the future. In the meantime, now is a good time to revisit and update your policies and procedures related to debtor workplace communications.


Autopay Disruption Leads Judge to Deny MJOP in FCRA Case

A District Court judge in Illinois has denied a defendant’s motion for judgment on the pleadings in a Fair Credit Reporting Act case that stemmed from the defendant disabling the autopay feature on the plaintiff’s account, after it had been used to make 95 monthly payments in a row. More details here.

WHAT THIS MEANS, FROM BRENT YARBOROUGH OF MAURICE WUTSCHER: While it was technically true that the plaintiff missed two payments, the plaintiff alleged that those missed payments were the bank’s fault (and not his fault) because the bank unilaterally disabled his automatic payments. Based on this allegation, the court found that the information related to the missed payments was materially inaccurate. The court further found that determining who was at fault for the missed payments did not require a legal conclusion and was instead a factual question that was subject to the FCRA’s reasonable-investigation requirement.


AI in the Spotlight: Oregon AG Sets the Stage for Regulating Artificial Intelligence

Artificial Intelligence is revolutionizing industries, including credit and collections, but contrary to popular opinion, it’s far from unregulated. Ellen Rosenblum, who just retired as the attorney general of Oregon, issued guidance in late December clarifying that existing consumer protection, privacy, and anti-discrimination laws apply to AI, potentially reshaping how companies deploy this transformative technology. It’s likely that other states will follow suit with their own guidance or regulations as AI usage becomes more popular. More details here.

WHAT THIS MEANS, FROM HEATH MORGAN OF MARTIN GOLDEN LYONS WATTS MORGAN: We anticipate 2025 to be a busy year with potential AI regulations. Additionally, we should expect more notices from regulators like the one issued from Oregon, that regulators can and will apply existing consumer protection laws to Artificial Intelligence technology and tools. The Oregon AG calls out the Unlawful Trade Practices Act, Oregon Privacy Act, Oregon Consumer Information Protection Act, and Oregon Equality Act as statutes that will apply to AI technology.

For debt collection industry members, Oregon’s guidance should be nothing new for compliance requirements. But the notice does provide a good call out that both the Oregon Consumer Privacy Act and Oregon Consumer Information Protection Act both apply for the protection of consumer data. To be clear, companies requirements for the protection of data extend to use of AI technology and applications, so it is important for companies to make sure vendor oversight of AI technology is just as important as their internal use. 

If you have not yet created an AI Governance document to address AI technology in your company, 2025 is the year to do so.


Washington State Appeals Court Upholds Attorney Fee Award in Debt Collection Case

A state appeals court in Washington has affirmed an attorney’s fee award for the plaintiff in a debt collection case, agreeing with the lower court that counterclaims brought by the defendant, a collection operation, were frivolous. More details here.

WHAT THIS MEANS, FROM CAREN ENLOE OF SMITH DEBNAM: Trahan is an interesting decision in which a collection agency sued for debt collection violations took aggressive action in response and filed a third party complaint against opposing counsel, questioning his authority to file the suit and seeking damages for violations of the Credit Repair Organization Act (the “CROA”) and Washington’s Consumer Protection Act. Was this simply a misfire by the collection agency or is there a back story not reflected in the opinion?  I don’t know. What I do know is that the case provides two points worth reflecting upon. First and foremost, our courts expect a measure of civility and professional courtesy between counsel and are skeptical when a party’s initial move appears to be suing the other attorney. As succinctly put by the trial court -– “try the case, not each other.”  

Secondly, if you are going to sue opposing counsel, make sure your claims are well supported.  Here, the claims set forth in the third-party complaint were dismissed by the trial court as baseless, a conclusion which was affirmed by the appellate panel. The net result was the collection agency was taxed with fees and costs exceeding $25,000. The claims fell apart for a couple of reasons. While undeniably, the consumer law firm at issue here, Litigation Practices Group (“LPG”), has been described in other litigation as providing credit repair services, the collection agency did not have standing to bring a CROA claim. See Walker v. Phoenix Law PC, Case No. 1:23-cv-00745-DII, 2024 U.S. Dist. LEXIS 69785 (W.D. Tx. Apr. 17, 2024); Beech v. Litig. Prac. Grp.,  Civil No. 1:22cv57-HSO-BWR, 2024 U.S. Dist. LEXIS 103462 (S.D. Ms. June 11, 2024). The CROA only provides a civil cause of action to the party with whom the CROA contracted.  Here, that party, the consumer,  was represented by the alleged CROA in the instant litigation.  See 15 U.S.C. § 1679g. Secondly, the Consumer Protection Act claim likewise failed because the provision of legal services is generally exempt.


I’m thrilled to announce that Bedard Law Group is the new sponsor for the Compliance Digest. Bedard Law Group, P.C. – Compliance Support – Defense Litigation – Nationwide Complaint Management – Turnkey Speech Analytics. And Our New BLG360 Program – Your Low Monthly Retainer Compliance Solution. Visit www.bedardlawgroup.com, email John H. Bedard, Jr., or call (678) 253-1871.

Bedard Law Group Logo

Related

Previous Post

Daily Digest – January 10. Collector Facing FDCPA Class-Action for Different Payment Portal Addresses in Different Letters; ACA, Collection Agency, Sue CFPB to Block Medical Debt Credit Reporting Rule from Going Into Effect

Next Post

Experts Share Their Predictions for 2025

mikegibb

mikegibb

Next Post

Experts Share Their Predictions for 2025

Leave a ReplyCancel reply

Upcoming Events

Current Month

September, 2026

News

  • Compliance
  • Daily Digest
  • Debt Buying
  • General News
  • Getting to Know
  • Economy
  • Healthcare
  • Student Loans
  • Technology

Videos

  • Ask The Credit Reporting Expert
  • Behind The Curtain
  • Between The Briefs
  • Customer Experience Week Videos
  • Demo Day Videos
  • Digital Debrief
  • Future Summit 2023
  • Legends of the ARM Industry
  • Q&ARM Videos

Informational

  • Premium Content
  • Upcoming Webinars
  • Webinars Recordings
  • W.A.R.M. – Webinar Streaming Channel
  • Compliance
  • Daily Digest
  • Debt Buying
  • General News
  • Getting to Know
  • Economy
  • Healthcare
  • Student Loans
  • Technology

© 2025 All Right Reserved by Account Recovery.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
    • Compliance
      • FCRA
      • FDCPA
      • TCPA
    • Daily Digest
    • Debt Buying
    • Economy
    • General News
    • Getting to Know
    • Healthcare
    • Student Loans
    • Technology
  • Webinars/Events
    • Upcoming Webinars & Events
    • Webinar Recordings
    • W.A.R.M. – Webinar Streaming Channel
  • Jobs
  • Videos
    • Ask The Credit Reporting Expert
    • Behind The Curtain
    • Between The Briefs
    • Customer Experience Week Videos
    • Demo Day Videos
    • Digital Debrief
    • Future Summit 2023
    • Legends of the ARM Industry
    • Q&ARM Videos
    • Teaching Tech
    • Tech Bytes: A Guide to AI
    • Training Bytes
    • Web Bytes
    • You Wanted a Rule; You Got a Rule
  • Premium Content Login
    • Subscribe Now

© 2025 All Right Reserved by Account Recovery.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
This recording is available for Premium Members.

Please login or become a premium subscriber.

Login
Register
X