The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will

California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

This post is co-authored by Seth Orkand, co-chair of Robinson+Cole’s Government Enforcement + White-Collar Defense Team, and Abigail Clarke, a 2026 Summer Associate at Robinson+Cole. Abigail is not admitted to practice law.

The Justice Department’s (DOJ) June 23, 2026, announcement of its annual Health Care Fraud Takedown makes clear that Medicaid and state health

This post is co-authored by Seth Orkand, co-chair of Robinson+Cole’s Government Enforcement + White-Collar Defense Team, and Abigail Salcedo, a 2026 Summer Associate at Robinson+Cole. Abigail is not admitted to practice law.

On June 23, 2026, the U.S. Department of Justice (DOJ) announced that it charged 11 defendants in connection with over two billion

A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims