On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect Nov. 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations for contractors handling Controlled Unclassified Information. The DoW simultaneously
Cybersecurity
AI-Assisted Billing Could Create FCA Pitfalls: How Healthcare Companies Can Get Ahead of Risk
Across the healthcare industry, providers are increasingly relying on AI-assisted billing tools to automate medical coding, prior authorization workflows, and the submission of claims to Medicare, Medicaid and other federal payors. The efficiency gains can be substantial, as can the heightened False Claims Act (FCA) exposure these systems can create. As AI continues to develop…
The Great American AI Act: What It Means — and Doesn’t Mean — for Companies Using AI
On June 4, 2026, Reps. Jay Obernolte and Lori Trahan released a discussion draft of the Great American Artificial Intelligence Act. The proposal has generated significant attention, but many organizations may be overestimating its practical significance for day-to-day operations. The bill is directed primarily at developers of “frontier” AI models, so its requirements will not…
GSA AI Procurement Rules Would Introduce New Disclosure and Use-Rights Requirements for Federal Contractors
The General Services Administration Federal Acquisition Service has released draft contract terms and conditions related to AI-related procurements through a new proposed GSAR clause 552.239-7001, “Basic Safeguarding of Artificial Intelligence Systems” (February 2026), that would impose material new requirements on contractors and service providers supplying AI capabilities to the federal government. If adopted, the clause…
Federal Court Blocks IPEDS Reporting Deadline for Public Universities in 17 States
On Friday, April 3, 2026, the U.S. District Court for the District of Massachusetts preliminarily enjoined the Trump administration from requiring public colleges and universities in 17 states to submit seven years’ worth of Integrated Postsecondary Education Data System (IPEDS) Admission and Consumer Transparency Supplement (ACTS) survey data. The reporting deadline for the members of…
Cyberattacks on Higher Education Institutions Underscore Urgency of Regulatory Compliance
Colleges and universities should assess their cybersecurity compliance posture and incident response readiness and harden their networks as soon as possible in light of elevated threats.
Since June 2025, the Cybersecurity and Infrastructure Security Agency has cautioned that Iranian government-affiliated actors routinely target U.S. networks and internet-connected devices. The war in Iran and recent Iranian…
White House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions Remain
On March 20, 2026, the White House unveiled its National Policy Framework for Artificial Intelligence, providing a blueprint on legislative recommendations and urging Congress to act. It recommends that Congress create a unified federal standard to reduce the regulatory friction of competing state AI regimes, promote AI innovation, and develop an AI-ready workforce, while ensuring the protection of children, consumers, and intellectual property rights.
Continue Reading White House Releases AI Legislative Recommendations—Congress Has the Blueprint, but Questions RemainCalPrivacy Ramps Up Privacy Enforcement
The California Privacy Protection Agency (CalPrivacy) is entering an aggressive new phase of privacy regulation and enforcement, of which companies doing business in California should be aware. CalPrivacy already brought enforcement actions against many companies, maintains over 100 active investigations and has signaled an increased pace of enforcement.
Continue Reading CalPrivacy Ramps Up Privacy EnforcementProtecting Employee Information From Tax Season Phishing Schemes
Overview
As we enter the 2026 tax filing season, organizations face a heightened risk of cyberattacks targeting employee information. Tax season is a busy time for cybercriminals, who ramp up efforts to trick businesses and individuals into sharing personal information. Bad actors can use stolen personally identifying information (“PII”) in a variety of harmful ways, including to file fraudulent tax returns and claim refunds. Below we provide an overview of the current threat landscape, key warning signs to watch for, practical prevention strategies, and guidance on legal obligations if your organization is targeted.
Continue Reading Protecting Employee Information From Tax Season Phishing SchemesSEC Voluntarily Dismisses Landmark Enforcement Action Against SolarWinds and its CISO
On November 20, 2025, the Securities and Exchange Commission and defendants SolarWinds Corp. and Timothy G. Brown filed a joint stipulation to dismiss with prejudice the SEC’s civil enforcement action pending in the Southern District of New York. The SEC would dismiss all claims concerning the conduct alleged in the SEC’s Amended Complaint and includes broad waivers and releases by the defendants of any related claims against the SEC and its personnel. This follows a July 2, 2025 letter to the court that stated that the parties had reached a settlement in principle, and sought time “to finalize the paperwork for the settlement, and for the Commissioners to then consider and determine whether to approve the settlement.” The stipulated dismissal does not address what may have changed, and why the matter ultimately resolved through a dismissal rather than a settlement.
Continue Reading SEC Voluntarily Dismisses Landmark Enforcement Action Against SolarWinds and its CISO