Robinson Cole LLP
High Contrast Mode

Kathleen E. Dion focuses her practice on providing counseling and dispute resolution advice to colleges, universities, independent schools, childcare centers, and organizations serving children and youths. In addition, she has a nationwide practice litigating complex civil cases and defending individuals and companies in white-collar criminal matters. Kate chairs our firm’s interdisciplinary Education Industry team and is a member of our firm’s Business Litigation group and Internal Investigations and Corporate Compliance team.

Education Law

Kate has a deep understanding of the present and future challenges facing educational entities and youth organizations, and thus is able to uniquely represent and counsel her clients on a variety of complex legal issues while also maintaining a focus on the institution’s larger, longer-term objectives. Because of her extensive experience serving as outside general counsel to universities and independent schools, she is well positioned to offer expert technical counsel to clients in a personable manner reflecting her appreciation of the complex and sensitive subject matters facing her clients. She works closely with an institution’s leadership team to solve problems in unique and creative ways to the maximum benefit of the institution.

Kate counsels education clients in a broad range of areas, including crisis management, protection of minors, sexual misconduct allegations and Title IX compliance, student discipline matters, disability accommodations, Clery Act compliance and campus security issues, Family Education Rights and Privacy Act compliance, reviewing, revising and implementing handbooks and necessary policies, contracts, NCAA compliance, and governance matters. She also serves as a Title IX investigator, advisor and decision-maker.

Kate assists childcare centers and organizations serving youth and children in responding to government investigations, conducting internal investigations, regulatory compliance, protection of minors, crisis counseling and development of policies and handbooks.

When it is not possible to avoid litigation, Kate is a skilled advocate representing clients in high-stakes, highly sensitive lawsuits in state and federal courts.

Complex Civil Litigation

Kate represents clients across the country in a variety of business disputes. Her courtroom experience ranges from federal and state jury trials to arbitrations and administrative hearings. She has represented financial services companies, health care organizations and defense contractors, among other clients. Kate’s successes include obtaining a favorable mid-trial settlement for a defense contractor in a dispute involving allegations of breach of contract and breach of the covenant of good faith and fair dealing. She has successfully argued appeals before the U.S. Court of Appeals for the Second Circuit, the Connecticut Supreme Court and the Connecticut Appellate Court.

Government Enforcement and White-Collar Criminal Defense

Kate assists public and private companies with internal investigations on a variety of matters, including financial wrongdoing and regulatory non-compliance. While investigating the embezzlement of hundreds of thousands of dollars from a health care organization, she obtained a full confession from the former chief financial officer and helped coordinate with federal agencies, which led to the CFO's criminal conviction. She has assisted with multiple corporate embezzlement investigations, helping to catch those responsible and recover stolen funds.

Kate has tried serious felony criminal cases in state and federal court and is active in the criminal defense bar. She is regularly court appointed to defend clients in criminal matters and has been recognized by the Federal District Court for the District of Connecticut for making substantial contributions in this area.

Pro Bono

Kate has devoted significant time to the representation of pro bono clients. She was part of a group of Robinson+Cole attorneys whose legal assistance ultimately allowed a soup kitchen and food pantry to remain open, despite attempts by the local municipality to close them. She participates in our firm’s Domestic Violence Restraining Order program, which provides free legal services to victims of family violence. Kate also successfully argued an appeal before the Second Circuit Court of Appeals for a prisoner on a civil rights claim. She was the recipient of the firm’s Pro Bono Service Award in 2013.

Kate is a member of the firm’s Data Privacy + Cybersecurity team, and regularly contributes to the firm’s Data Privacy + Security Insider publication, writing about Family Educational Rights and Privacy Act and Fourth Amendment issues. She also contributes to the Health Law Diagnosis blog. Prior to joining the firm, she served as a law clerk to the Honorable Robert E. Beach of the Connecticut Appellate Court.

  • Western New England University School of Law (Juris Doctor, magna cum laude)
    • Western New England Law Review, Editor
  • University of Massachusetts (Bachelors, magna cum laude)
    • B.A., History

  • Commonwealth of Massachusetts
  • State of Connecticut
  • U.S. Supreme Court
  • U.S. Court of Appeals, 2nd Circuit
  • U.S. District Court, District of Connecticut
  • U.S. District Court, District of Massachusetts

Ranked in Chambers USA: America's Leading Lawyers for Business in the State of Connecticut in the area of Litigation: White-Collar Crime & Government Investigations for 2025

Listed in Benchmark Litigation as a Local Litigation Star in Connecticut in the area of White Collar Crime for 2025 and 2026

Presented with the 2025 Dean’s Alumni Excellence Award  from Western New England University School of Law

Recognized by Massachusetts Lawyers Weekly as a 2024 “Massachusetts Go To Lawyer” in the area of Higher Education

Selected to the Connecticut Super Lawyers list for 2024 and 2025

Selected as a Rising Star to the Connecticut Super Lawyers list from 2016 to 2019

Recognized as a "40 Under Forty" winner by BusinessWest for 2018

Connecticut Law Tribune, recognized in 2017 New Leaders in the Law Yearbook

Presented with the Ascending Alumni Award and the Distinguished Law Review Alumni Award from Western New England University School of Law in 2019

Robinson+Cole Pro Bono Service Award Recipient, 2013

Named to the Connecticut Coalition Against Domestic Violence (CCADV) First 100 Plus Class of 2018 for demonstrating leadership and commitment to improving the lives of domestic violence survivors throughout Connecticut

United States District Court for the District of Connecticut
Appointee, Criminal Justice Act (CJA) Standing Committee

Connecticut Bar Association
Member, Education Law Section
Former Consumer Law Committee Co-chair, Young Lawyers Section Executive Committee
Former Education Law Committee Co-chair, Young Lawyers Section Executive Committee
Former Federal Practice Committee Chair, Young Lawyers Section Executive Committee

American Bar Association

Massachusetts Bar Association

Women's White Collar Defense Association

Connecticut Bar Foundation
James W. Cooper Fellow

Junior Achievement of Southwest New England
Board of Directors

KNOX
Board of Directors, Secretary (2015 - 2018)

Longmeadow Educational Excellence Foundation
Former President Emeritus

Longmeadow Montessori Internationale
Board Member (2014 - 2018)

Experience


Investigations + Criminal Defense: Criminal Justice Act Client Representation

Represented Criminal Justice Act client through all stages of federal prosecution by United States Attorney’s Office, including month long jury trial.

Investigations + Criminal Defense: IRS Investigations

Represented various clients as targets and witnesses in Internal Revenue Service investigations.

Investigations + Criminal Defense: Sexual Assault Acquittal

Obtained the acquittal of an individual who had been charged with sexual assault.



Publications


November 19, 2025

Here are 3 big AI-related legal issues for higher ed

University Business

As artificial intelligence rapidly transforms the landscape of higher education, college and university administrators are finding themselves on the frontlines of new, and sometimes unprecedented, legal challenges. While much of the public discourse has focused on students using AI tools to cheat, the legal implications for administrators are far broader. From data privacy laws to anti-discrimination requirements and the complexities of policy development, the legal environment is evolving just as quickly as the technology itself. This article identifies three significant AI-related legal issues facing higher education administrators—and provides actionable suggestions to navigate these challenges. Data privacy, security, and compliance The Challenge AI systems in higher education collect and process large amounts of personal and institutional data, including student records, behavioral analytics and, increasingly, biometric information. Administrators face overlapping data privacy laws, including the Family Educational Rights and Privacy Act, evolving state privacy statutes, and international regulations such as the General Data Protection Regulation. These laws establish strict requirements for how student and institutional data must be collected, stored and shared, and they are designed to protect individual privacy and prevent unauthorized access or misuse of sensitive information. As AI technologies become more pervasive, ensuring compliance with these regulations is crucial to avoid legal penalties and maintain trust within the academic community. AI-driven platforms often share data with third-party vendors, raising substantial questions about consent, control and oversight. As we enter a new year, the legal liability for data breaches or improper sharing is heightened by increased regulatory enforcement and class action litigation regarding student and employee data privacy. To protect against this liability: Ensure contracts with third-party vendors require compliance with all relevant privacy laws and set clear protocols for breach notification and data handling Provide clear, advance notice and obtain valid consent whenever personal data, especially sensitive or student/employee data, is collected or shared Collect and retain only the minimum amount of data necessary for the stated purpose Continually audit vendors and internal processes for compliance, and quickly address potential vulnerabilities Have robust response plans for breaches, and be prepared with documentation of compliance efforts. Practical steps for administrators Audit existing data practices: Proactively conduct an audit of all AI systems and third-party vendors to map data flows and ensure compliance with current federal and state laws and regularly review how institutional stakeholders use and input information into AI systems. Update contracts: Strengthen contract language with vendors to mandate compliance with privacy standards, notification protocols, and data protection requirements. Develop clear policies: Draft and disseminate clear institutional privacy and contracting policies tailored to AI tools and ensure ongoing training for staff and students. Algorithmic bias and discrimination risks The Challenge AI systems used for admissions, grading, advising and faculty hiring can inadvertently perpetuate or amplify bias, potentially running afoul of federal antidiscrimination laws such as Title VI, Title IX and the Americans with Disabilities Act. Algorithms trained on historical data may entrench past inequities, and lack of transparency can make it difficult to audit decision-making. Litigation and regulatory actions alleging disparate impact and failure to prevent discrimination are increasing, putting institutional reputation and accreditation at risk. Institutions adopting AI systems in admissions, evaluation and other critical processes must proactively address potential sources of bias and ensure compliance with relevant antidiscrimination laws. Key lessons include the importance of ongoing auditing and transparency in AI decision-making, involving diverse stakeholders in system design, and regularly updating algorithms to reflect current, equitable standards rather than outdated or biased historical data. Proactive risk management, including legal reviews and bias mitigation strategies, not only helps avoid liability but also upholds institutional values of fairness, inclusion, and integrity. Practical Steps for Administrators Assess and monitor AI systems: Require regular, independent testing of AI systems for evidence of disparate impact or discriminatory outcomes. Demand explainable AI: Insist that vendors provide audit trails and “explainability” features for all decision-making algorithms. Build diverse oversight panels: Establish interdisciplinary committees—including legal, ethics, IT and DEI representatives—to oversee adoption and review of AI tools. Academic integrity and AI-generated content The Challenge While AI-enabled cheating is top-of-mind, the legal issues go deeper: unclear policies about AI use, inconsistent enforcement and concerns about due process. Ambiguous rules expose institutions to challenges by students and faculty alike, particularly when disciplinary action is taken. Federal grant agencies are increasingly regulating the use of AI in applications, with some restricting or requiring disclosures where AI-generated content is included. Defining and enforcing what constitutes permissible AI use will be a central legal and reputational challenge for institutions next year and beyond. Practical steps for administrators Clarify codes of conduct: Update student and faculty codes of conduct to explicitly address AI and its varied uses in academic work. Ensure procedural fairness: Prepare due process protocols and hearing procedures for alleged AI-related infractions, to reduce the risk of successful legal challenges. Educate the community: Launch ongoing educational campaigns highlighting ethical AI use, provide guidance on distinguishing between collaboration and misconduct, and provide timely information on compliance with federal regulations and agency-specific guidance on the use of AI in sponsored programs. Leading in a new era For higher ed administrators, successfully navigating the legal landscape of AI in 2026 demands a proactive, multidisciplinary approach. By prioritizing data privacy, guarding against algorithmic bias and updating policies around academic integrity, institutions can mitigate risk while harnessing the benefits of AI. Implementing these practical measures will position universities not merely to comply with the law, but to lead in this new era of technology-enhanced education.

Legal Update: Federal Court Enjoins NCAA’s “Five-Year Rule” for JUCO Athletes teaser
November 4, 2025

Legal Update: Federal Court Enjoins NCAA’s “Five-Year Rule” for JUCO Athletes

February 11, 2025

AI is transforming higher ed: What you need for compliance and governance

University Business

As generative artificial intelligence (AI) is increasingly being integrated into higher education…it raises concerns about its ethical and effective use, including data privacy and security issues around the data input into these AI systems, and the potential for algorithm bias. Co-authors Kate Dion and Kathryn Rattigan suggest that as colleges and universities tackle this new era of generative AI, they may wish to consider implementing an AI governance program. The authors identify several key aspects that an AI governance program should encompass including data governance and privacy, risk management and continuous monitoring and improvement. “By integrating these components, a university can develop a robust AI governance program that aligns with ethical standards, ensures data protection, and fosters a safe and inclusive educational environment.” Read the article.

November 19, 2025

Here are 3 big AI-related legal issues for higher ed

University Business

As artificial intelligence rapidly transforms the landscape of higher education, college and university administrators are finding themselves on the frontlines of new, and sometimes unprecedented, legal challenges. While much of the public discourse has focused on students using AI tools to cheat, the legal implications for administrators are far broader. From data privacy laws to anti-discrimination requirements and the complexities of policy development, the legal environment is evolving just as quickly as the technology itself. This article identifies three significant AI-related legal issues facing higher education administrators—and provides actionable suggestions to navigate these challenges. Data privacy, security, and compliance The Challenge AI systems in higher education collect and process large amounts of personal and institutional data, including student records, behavioral analytics and, increasingly, biometric information. Administrators face overlapping data privacy laws, including the Family Educational Rights and Privacy Act, evolving state privacy statutes, and international regulations such as the General Data Protection Regulation. These laws establish strict requirements for how student and institutional data must be collected, stored and shared, and they are designed to protect individual privacy and prevent unauthorized access or misuse of sensitive information. As AI technologies become more pervasive, ensuring compliance with these regulations is crucial to avoid legal penalties and maintain trust within the academic community. AI-driven platforms often share data with third-party vendors, raising substantial questions about consent, control and oversight. As we enter a new year, the legal liability for data breaches or improper sharing is heightened by increased regulatory enforcement and class action litigation regarding student and employee data privacy. To protect against this liability: Ensure contracts with third-party vendors require compliance with all relevant privacy laws and set clear protocols for breach notification and data handling Provide clear, advance notice and obtain valid consent whenever personal data, especially sensitive or student/employee data, is collected or shared Collect and retain only the minimum amount of data necessary for the stated purpose Continually audit vendors and internal processes for compliance, and quickly address potential vulnerabilities Have robust response plans for breaches, and be prepared with documentation of compliance efforts. Practical steps for administrators Audit existing data practices: Proactively conduct an audit of all AI systems and third-party vendors to map data flows and ensure compliance with current federal and state laws and regularly review how institutional stakeholders use and input information into AI systems. Update contracts: Strengthen contract language with vendors to mandate compliance with privacy standards, notification protocols, and data protection requirements. Develop clear policies: Draft and disseminate clear institutional privacy and contracting policies tailored to AI tools and ensure ongoing training for staff and students. Algorithmic bias and discrimination risks The Challenge AI systems used for admissions, grading, advising and faculty hiring can inadvertently perpetuate or amplify bias, potentially running afoul of federal antidiscrimination laws such as Title VI, Title IX and the Americans with Disabilities Act. Algorithms trained on historical data may entrench past inequities, and lack of transparency can make it difficult to audit decision-making. Litigation and regulatory actions alleging disparate impact and failure to prevent discrimination are increasing, putting institutional reputation and accreditation at risk. Institutions adopting AI systems in admissions, evaluation and other critical processes must proactively address potential sources of bias and ensure compliance with relevant antidiscrimination laws. Key lessons include the importance of ongoing auditing and transparency in AI decision-making, involving diverse stakeholders in system design, and regularly updating algorithms to reflect current, equitable standards rather than outdated or biased historical data. Proactive risk management, including legal reviews and bias mitigation strategies, not only helps avoid liability but also upholds institutional values of fairness, inclusion, and integrity. Practical Steps for Administrators Assess and monitor AI systems: Require regular, independent testing of AI systems for evidence of disparate impact or discriminatory outcomes. Demand explainable AI: Insist that vendors provide audit trails and “explainability” features for all decision-making algorithms. Build diverse oversight panels: Establish interdisciplinary committees—including legal, ethics, IT and DEI representatives—to oversee adoption and review of AI tools. Academic integrity and AI-generated content The Challenge While AI-enabled cheating is top-of-mind, the legal issues go deeper: unclear policies about AI use, inconsistent enforcement and concerns about due process. Ambiguous rules expose institutions to challenges by students and faculty alike, particularly when disciplinary action is taken. Federal grant agencies are increasingly regulating the use of AI in applications, with some restricting or requiring disclosures where AI-generated content is included. Defining and enforcing what constitutes permissible AI use will be a central legal and reputational challenge for institutions next year and beyond. Practical steps for administrators Clarify codes of conduct: Update student and faculty codes of conduct to explicitly address AI and its varied uses in academic work. Ensure procedural fairness: Prepare due process protocols and hearing procedures for alleged AI-related infractions, to reduce the risk of successful legal challenges. Educate the community: Launch ongoing educational campaigns highlighting ethical AI use, provide guidance on distinguishing between collaboration and misconduct, and provide timely information on compliance with federal regulations and agency-specific guidance on the use of AI in sponsored programs. Leading in a new era For higher ed administrators, successfully navigating the legal landscape of AI in 2026 demands a proactive, multidisciplinary approach. By prioritizing data privacy, guarding against algorithmic bias and updating policies around academic integrity, institutions can mitigate risk while harnessing the benefits of AI. Implementing these practical measures will position universities not merely to comply with the law, but to lead in this new era of technology-enhanced education.

Legal Update: Federal Court Enjoins NCAA’s “Five-Year Rule” for JUCO Athletes teaser
November 4, 2025

Legal Update: Federal Court Enjoins NCAA’s “Five-Year Rule” for JUCO Athletes

February 11, 2025

AI is transforming higher ed: What you need for compliance and governance

University Business

As generative artificial intelligence (AI) is increasingly being integrated into higher education…it raises concerns about its ethical and effective use, including data privacy and security issues around the data input into these AI systems, and the potential for algorithm bias. Co-authors Kate Dion and Kathryn Rattigan suggest that as colleges and universities tackle this new era of generative AI, they may wish to consider implementing an AI governance program. The authors identify several key aspects that an AI governance program should encompass including data governance and privacy, risk management and continuous monitoring and improvement. “By integrating these components, a university can develop a robust AI governance program that aligns with ethical standards, ensures data protection, and fosters a safe and inclusive educational environment.” Read the article.

November 5, 2024

Where Are New Title IX Regulations Not Enforceable?

By August 1, 2024, educational institutions across the country were required to implement the Biden administration’s new regulations concerning Title IX of the Education Amendments of 1972, which contained numerous expansions on the law’s protections. As anticipated, litigation followed, resulting in district courts issuing preliminary injunctions barring enforcement throughout the country. As of now, the 2024 regulations are enjoined from being enforced in nearly 26 states. While the litigations play out in due course, institutions in affected states will want to be on the lookout for any changes to these preliminary injunctions, and consider whether any state laws weigh into their consideration to amend their policies consistent with the new regulations. Read the article.

August 16, 2024

Schools Need To Consider These Seven Key Questions/New Title IX Compliance

BusinessWest

With the start of this new academic year, schools in jurisdictions not covered by a Federal injunction or listed here were required to comply with the new Title IX regulations by August 1, 2024. In their article, Kate and Sabrina share a list of top questions federally funded institutions are urged to have answers for. “[A]s institutions ensure compliance with the new regulations, it would not be surprising to see schools continue to revise policies based on how the new procedures pan out in practice,” Kate and Sabrina write. “This is especially true given that the new regulations give schools more autonomy in deciding how to manage grievance procedures and related policies…Title IX teams should keep an eye out for how their chosen policies work in practice and consider any needed changes as the school year progresses.” Read the article.

June 28, 2024

With New Title IX Regs Come New Cost Implications

Massachusetts Lawyers Weekly

With the Aug. 1 implementation date fast approaching, the authors discussed potential increased costs associated with three areas of the new Title IX regulations: compliance requirements, the increased scope of applicability and grievance procedures. The revised regulations broaden the definition of sexual harassment and discrimination, remove barriers to reporting misconduct, and provide educational institutions with greater autonomy over their grievance procedures, including the option to revert to a single- investigator model and to choose whether to conduct live hearings. To ensure compliance with the new regulations by the Aug. 1 effective date, institutions can expect increased costs associated with updating their policies, procedures and training. While the authors recognize that these cost increases and compliance with the new regulations will affect schools differently depending on size and resources, schools can anticipate receiving more complaints and carrying out more investigations as a result of the broadened scope of Title IX applicability, both of which will require greater use of resources. Ultimately, individual schools can evaluate what procedures work best — both for the institution and the students. Read the article. Erica Whaley, candidate juris doctor at Roger Williams University School of Law and member of the firm’s 2024 summer associate class, contributed to the research, drafting and editing of the article.

June 3, 2024

Title IX coordinator: More than just a mandatory role

University Business

On the heels of recently released Title IX regulations, Kate and Sabrina identify how the role Title IX coordinator continues to ramp up as schools begin to implement the new regulations by August 1, 2024. All schools receiving federal financial assistance are required to designate at least one employee as their coordinator, with that person being “responsible for not only understanding Title IX’s evolving requirements but for ensuring the school’s compliance with them.” In addition, Title IX coordinators will be crucial in ensuring compliance in critical areas such as training of all employees about their obligations under the new regulations, policy drafting and grievance procedures. Read the article.

Legal Update: Department of Education Releases Issue Papers to Strengthen Program Integrity and Institutional Quality teaser
May 20, 2024

Legal Update: Department of Education Releases Issue Papers to Strengthen Program Integrity and Institutional Quality

Legal Update: The Department of Education Releases Significant Revisions to Title IX Regulations teaser
April 23, 2024

Legal Update: The Department of Education Releases Significant Revisions to Title IX Regulations



November 5, 2024

Where Are New Title IX Regulations Not Enforceable?

By August 1, 2024, educational institutions across the country were required to implement the Biden administration’s new regulations concerning Title IX of the Education Amendments of 1972, which contained numerous expansions on the law’s protections. As anticipated, litigation followed, resulting in district courts issuing preliminary injunctions barring enforcement throughout the country. As of now, the 2024 regulations are enjoined from being enforced in nearly 26 states. While the litigations play out in due course, institutions in affected states will want to be on the lookout for any changes to these preliminary injunctions, and consider whether any state laws weigh into their consideration to amend their policies consistent with the new regulations. Read the article.

August 16, 2024

Schools Need To Consider These Seven Key Questions/New Title IX Compliance

BusinessWest

With the start of this new academic year, schools in jurisdictions not covered by a Federal injunction or listed here were required to comply with the new Title IX regulations by August 1, 2024. In their article, Kate and Sabrina share a list of top questions federally funded institutions are urged to have answers for. “[A]s institutions ensure compliance with the new regulations, it would not be surprising to see schools continue to revise policies based on how the new procedures pan out in practice,” Kate and Sabrina write. “This is especially true given that the new regulations give schools more autonomy in deciding how to manage grievance procedures and related policies…Title IX teams should keep an eye out for how their chosen policies work in practice and consider any needed changes as the school year progresses.” Read the article.

June 28, 2024

With New Title IX Regs Come New Cost Implications

Massachusetts Lawyers Weekly

With the Aug. 1 implementation date fast approaching, the authors discussed potential increased costs associated with three areas of the new Title IX regulations: compliance requirements, the increased scope of applicability and grievance procedures. The revised regulations broaden the definition of sexual harassment and discrimination, remove barriers to reporting misconduct, and provide educational institutions with greater autonomy over their grievance procedures, including the option to revert to a single- investigator model and to choose whether to conduct live hearings. To ensure compliance with the new regulations by the Aug. 1 effective date, institutions can expect increased costs associated with updating their policies, procedures and training. While the authors recognize that these cost increases and compliance with the new regulations will affect schools differently depending on size and resources, schools can anticipate receiving more complaints and carrying out more investigations as a result of the broadened scope of Title IX applicability, both of which will require greater use of resources. Ultimately, individual schools can evaluate what procedures work best — both for the institution and the students. Read the article. Erica Whaley, candidate juris doctor at Roger Williams University School of Law and member of the firm’s 2024 summer associate class, contributed to the research, drafting and editing of the article.

June 3, 2024

Title IX coordinator: More than just a mandatory role

University Business

On the heels of recently released Title IX regulations, Kate and Sabrina identify how the role Title IX coordinator continues to ramp up as schools begin to implement the new regulations by August 1, 2024. All schools receiving federal financial assistance are required to designate at least one employee as their coordinator, with that person being “responsible for not only understanding Title IX’s evolving requirements but for ensuring the school’s compliance with them.” In addition, Title IX coordinators will be crucial in ensuring compliance in critical areas such as training of all employees about their obligations under the new regulations, policy drafting and grievance procedures. Read the article.

Legal Update: Department of Education Releases Issue Papers to Strengthen Program Integrity and Institutional Quality teaser
May 20, 2024

Legal Update: Department of Education Releases Issue Papers to Strengthen Program Integrity and Institutional Quality

Legal Update: The Department of Education Releases Significant Revisions to Title IX Regulations teaser
April 23, 2024

Legal Update: The Department of Education Releases Significant Revisions to Title IX Regulations


News


June 10, 2026

Kate Dion and Natale DiNatale Examine the Legal Questions Raised By Sorsby Injunction

Education industry team chair Kathleen Dion and Labor Relations group chair Natale DiNatale discussed the potential ramifications on the NCAA and college athletes in the article, “NCAA to appeal Brendan Sorsby injunction. What it means and how it can win,” published in USA Today, June 8, 2026. Kate pointed out that the injunction is a temporary measure. “This decision is only a preliminary ruling and is subject to appeal. Unless it is overturned, the injunction preserves Sorsby’s opportunity to compete this fall while the underlying case proceeds and allows him to continue preparing for a potential NFL career. For the NCAA, the ruling raises questions about the extent to which courts may review and potentially limit the enforcement of eligibility and competitive-integrity rules in individual cases.”  She continued, “It is also important to recognize that this is one state trial court decision, not a final decision on the merits, and thus its precedential value may be limited. While the court found that Sorsby demonstrated a probable right to the relief that he seeks on his breach of contract and other claims, which is a necessary element for obtaining a temporary injunction — the order does not appear to provide a detailed explanation of the court’s reasoning on that issue. As a result, many of the legal questions raised by the case are likely to remain the subject of further litigation and possible appellate review.” Discussing the foundation of the claim, Natale said, “The underlying dispute looks like a claim that the NCAA failed to accommodate a disability (e.g. an ADA claim based on a gambling addiction). But, it was brought as a breach of contract claim. A contract claim can be brought and maybe kept, in state court, which is likely a friendlier forum for this athlete.” Read the article.

USA Today
April 30, 2026

Kate Dion Named to 2026 “Women in Business” Class

Hartford Business Journal
Kate Dion Named to 2026 “Women in Business” Class teaser
December 4, 2025

Kate Dion Reappointed to Criminal Justice Act Standing Committee

United States District Court for the District of Connecticut
June 10, 2026

Kate Dion and Natale DiNatale Examine the Legal Questions Raised By Sorsby Injunction

Education industry team chair Kathleen Dion and Labor Relations group chair Natale DiNatale discussed the potential ramifications on the NCAA and college athletes in the article, “NCAA to appeal Brendan Sorsby injunction. What it means and how it can win,” published in USA Today, June 8, 2026. Kate pointed out that the injunction is a temporary measure. “This decision is only a preliminary ruling and is subject to appeal. Unless it is overturned, the injunction preserves Sorsby’s opportunity to compete this fall while the underlying case proceeds and allows him to continue preparing for a potential NFL career. For the NCAA, the ruling raises questions about the extent to which courts may review and potentially limit the enforcement of eligibility and competitive-integrity rules in individual cases.”  She continued, “It is also important to recognize that this is one state trial court decision, not a final decision on the merits, and thus its precedential value may be limited. While the court found that Sorsby demonstrated a probable right to the relief that he seeks on his breach of contract and other claims, which is a necessary element for obtaining a temporary injunction — the order does not appear to provide a detailed explanation of the court’s reasoning on that issue. As a result, many of the legal questions raised by the case are likely to remain the subject of further litigation and possible appellate review.” Discussing the foundation of the claim, Natale said, “The underlying dispute looks like a claim that the NCAA failed to accommodate a disability (e.g. an ADA claim based on a gambling addiction). But, it was brought as a breach of contract claim. A contract claim can be brought and maybe kept, in state court, which is likely a friendlier forum for this athlete.” Read the article.

USA Today
April 30, 2026

Kate Dion Named to 2026 “Women in Business” Class

Hartford Business Journal
Kate Dion Named to 2026 “Women in Business” Class teaser
December 4, 2025

Kate Dion Reappointed to Criminal Justice Act Standing Committee

United States District Court for the District of Connecticut
November 25, 2025

Kathleen Dion and Kathryn Rattigan Spotlight Three AI-related Legal Issues Facing Higher Education Administrators

University Business
November 14, 2025

Kate Dion Receives Dean’s Alumni Excellence Award

Western New England 2025 Law Alumni Awards
Kate Dion Receives Dean’s Alumni Excellence Award teaser
November 6, 2025

Robinson+Cole Commends 62 Attorneys Recognized in 2025 Super Lawyers®

Recognition spans key regions and highlights the firm’s seasoned practitioners and emerging leaders in many business transactions and litigation practices
Robinson+Cole Commends 62 Attorneys Recognized in 2025 <i>Super Lawyers</i>® teaser
June 5, 2025

Robinson+Cole Secures 45 Total Rankings in Chambers USA 2025 Guide

Chambers USA: America’s Leading Lawyers for Business
Robinson+Cole Secures 45 Total Rankings in <i>Chambers USA 2025</i> Guide teaser
February 14, 2025

Kate Dion and Kathryn Rattigan Co-Author Article on Artificial Intelligence Compliance and Governance in Higher Education

University Business
November 20, 2024

Robinson+Cole Participates in Annual Junior Achievement Program at Parkville Elementary School

Robinson+Cole Participates in Annual Junior Achievement Program at Parkville Elementary School teaser

November 25, 2025

Kathleen Dion and Kathryn Rattigan Spotlight Three AI-related Legal Issues Facing Higher Education Administrators

University Business
November 14, 2025

Kate Dion Receives Dean’s Alumni Excellence Award

Western New England 2025 Law Alumni Awards
Kate Dion Receives Dean’s Alumni Excellence Award teaser
November 6, 2025

Robinson+Cole Commends 62 Attorneys Recognized in 2025 Super Lawyers®

Recognition spans key regions and highlights the firm’s seasoned practitioners and emerging leaders in many business transactions and litigation practices
Robinson+Cole Commends 62 Attorneys Recognized in 2025 <i>Super Lawyers</i>® teaser
June 5, 2025

Robinson+Cole Secures 45 Total Rankings in Chambers USA 2025 Guide

Chambers USA: America’s Leading Lawyers for Business
Robinson+Cole Secures 45 Total Rankings in <i>Chambers USA 2025</i> Guide teaser
February 14, 2025

Kate Dion and Kathryn Rattigan Co-Author Article on Artificial Intelligence Compliance and Governance in Higher Education

University Business
November 20, 2024

Robinson+Cole Participates in Annual Junior Achievement Program at Parkville Elementary School

Robinson+Cole Participates in Annual Junior Achievement Program at Parkville Elementary School teaser

Events


Past

One Big Beautiful Bill

Mar 19 2026
Boston Bar Association 2026 Higher Education Conference
Past

Equity in Education: University Policies Through a Legal Lens

Nov 18 2025
The Knowledge Group Live CLE Webinar
Past

One Big Beautiful Bill

Mar 19 2026
Boston Bar Association 2026 Higher Education Conference
Past

Equity in Education: University Policies Through a Legal Lens

Nov 18 2025
The Knowledge Group Live CLE Webinar
Past

2025 WNE Law Alumni Awards

Nov 14 2025
Western New England University
Past

Equity in Education: University Policies Through a Legal Lens

Oct 16 2025
The Knowledge Group Live CLE Webinar
Past

Creating an Effective AI Compliance Program for Your Campus

Nov 15 2024
2024 CCIC Annual Member Forum "Partnering for Progress"
Past

Title IX: What You Need to Know About the Final Regulations

Apr 29 2024
R+C-Hosted Webinar
Past

2025 WNE Law Alumni Awards

Nov 14 2025
Western New England University
Past

Equity in Education: University Policies Through a Legal Lens

Oct 16 2025
The Knowledge Group Live CLE Webinar
Past

Creating an Effective AI Compliance Program for Your Campus

Nov 15 2024
2024 CCIC Annual Member Forum "Partnering for Progress"
Past

Title IX: What You Need to Know About the Final Regulations

Apr 29 2024
R+C-Hosted Webinar

Data Privacy + Cybersecurity Insider


Below is an excerpt of Data Privacy + Cybersecurity Insider blog posts authored by Kathleen.

Cyber Criminals Hone Attacks Against Schools

The FBI recently issued a Flash Alert warning higher education institutions, K-12 schools, and seminaries about increasing numbers of ransomware attacks affecting the education industry. According to the warning, “Since March 2020, the FBI has become aware of PYSA ransomware attacks against US and foreign government entities, educational institutions, private companies, and the healthcare sector by unidentified cyber actors.” The ransomware attacks are initiated by gaining unauthorized access to networks either by exploiting Remote Desktop Protocol (RDP) credentials or phishing. The PYSA ransomware then extracts sensitive information and encrypts files with the .pysa extension. In some circumstances, the attackers sell the extracted information on the dark web. The FBI reports that some criminals also remove the malicious files after deployment, thus making it even more difficult for the victims to discover what has happened. The FBI does not recommend paying any ransom as that emboldens and encourages more criminal conduct. Acknowledging that many educational institutions might choose to pay after determining few other options exist, the FBI points out that there is no guarantee paying any ransom will result in the return of the data. The FBI also suggests schools implement mitigation steps as follows: Regularly back up data, air gap, and password protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the system where the data resides. Implement network segmentation. Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location (i.e., hard drive, storage device, the cloud). Install updates/patch operating systems, software, and firmware as soon as they are released. Use multifactor authentication where possible. Regularly, change passwords to network systems and accounts, and avoid reusing passwords for different accounts. Implement the shortest acceptable timeframe for password changes. Disable unused remote access/RDP ports and monitor remote access/RDP logs. Audit user accounts with administrative privileges and configure access controls with least privilege in mind. Install and regularly update anti-virus and anti-malware software on all hosts. Only use secure networks and avoid using public Wi-Fi networks. Consider installing and using a VPN. Consider adding an email banner to messages coming from outside your organizations. Disable hyperlinks in received emails. Focus on awareness and training. Provide users with training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities (i.e., ransomware and phishing scams).

Visit Blog

Dealing with Two Schoolyard Bullies: Schools Are Forced to Contend with Cyber-attacks While Also Trying to Manage Covid-19 Crisis

Criminals are apparently not taking any time off during this pandemic, and in fact by all accounts have increased their attacks, particularly targeting entities whose attention is diverted to dealing with the fallout of the Covid-19 crisis. In particular, educational institutions across the country have faced a recent onslaught of ransomware attacks, often crippling an already vulnerable infrastructure just as classes were set to resume. Check Point Research recently published a report advising that cyber-attacks targeting academic institutions increased 30 percent between July and August (with upwards of 600 attacks per week). Although the research does not reveal why the surge occurred, it is likely not a coincidence that Covid-19 has compelled schools to utilize and vastly expand the use of new and unfamiliar technologies that allow remote learning, which in turn may have opened up new opportunities for cybercriminals to attack. In addition, although financial resources were spent on acquiring new technologies, the same expenditures were not necessarily invested in associated security. Often times cyber-attacks start with a phishing-email, that once opened allows cybercriminals to gain access to an organization’s infrastructure over time. As attention has been diverted to dealing with emergency Covid-19 issues, organizations have less resources focused on cyber-attacks. Accordingly, as the Covid-19 emergency persists, educational institutions must be sure not lose focus on monitoring cyber-attacks. Failing to expend the additional resources on cybersecurity prevention and monitoring, could very likely cost the school significantly more in the long run.

Visit Blog

FERPA and COVID-19 Virus DOE Guidelines

The COVID-19 virus is having an unprecedented effect on all aspects of our daily lives, and has hit the educational system especially hard with forced closures and cancellations.  Because educational institutions play such a vital role in our communities, the Department of Education (DOE) recently issued guidance in the form of Frequently Asked Questions (Guidance)  to assist school officials with how to address this public health concern while appropriately protecting student privacy. The Guidance first reminds school officials that generally they need to obtain consent before releasing a student’s personally identifiable information (PII).  However, given the threat posed by COVID-19, there are circumstances when the “health or safety emergency” exception to consent may apply.  The Guidance states that the “public health emergency” provision is not applicable if the circumstances are based on “a generalized or distant threat of a possible event or emergency for which the likelihood of occurrence is unknown.”  It goes on to list several specific situations where the health or safety emergency exception may or may not apply. First, if an institution determines, based on the totality of the circumstances, that there is an articulable and significant threat to the health or safety of a student, the institution may disclose to appropriate officials at a public health department PII without prior written consent to protect the health or safety of a student or other individual. Second, if an institution learns that a student in attendance at the school is out sick due to COVID-19 it may disclose this information to other students and parents in the school community, but only in a manner that prevents the student from being identified. In a rare situation, an institution may determine, in conjunction with health, law enforcement or other government officials, that parents or eligible students may need to be advised of the identity of a student with COVID-19.  The Guidance uses the example of a student wrestler with COVID-19 who has been in direct and close contact with other students or students who have higher health risks.  In these circumstances, school officials should determine on a case-by-case basis whether a disclosure of the student’s name is absolutely necessary to protect the health or safety of students or other individuals or whether a general notice is sufficient.  School officials should consider the totality of the circumstances, including the needs of students or other individuals to have the information in order to take appropriate precautions and the risks presented. Third, while directory information such as a student’s name, address and phone number can be released, it cannot be released in conjunction with nondirectory information such as a list of students absent from school.  The health or safety emergency exception may apply to give public health officials a list of students absent from school, but only if the school, with the concurrence or at the direction of local health authorities can determine that there is, in fact, a public emergency in the community.  The Guidance suggests that institutions prepare consent forms for parents or eligible students to sign to allow this information to be shared if the government institutes a tracking or monitoring system to identify an outbreak before an emergency is recognized.  If a parent refuses to sign the consent form, then the institution may not make the disclosure unless the health or safety emergency exception applies. Fourth, even if an institution determines that a health or safety emergency exists, it cannot disclose PII from a student’s education records to the media without consent.  Under the health or safety emergency exception, the disclosure can only be made to “appropriate parties” whose knowledge is necessary to protect the health and safety of students and other individuals, which are generally parties who provide specific medical or safety attention, such as health and law enforcement officials.  The media is not an “appropriate party” even though it may alert the community of an outbreak. Fifth, an institution may disclose to an eligible student’s parents that the eligible student has COVID-19 if the parents claim the eligible student as a dependent under section 152 of the Internal Revenue Code of 1986 or if the disclosure is in connection with the health or safety emergency exception. If an institution discloses PII from a student’s educational records to the public health department or other agency pursuant to the health or safety emergency exception, the institution is required to record the request and disclosure for each student as well as an explanation of the articulable and significant threat to the health or safety of a student or other individual that caused the institution to disclose the information.  Any disclosure made with the written consent of a parent or eligible student need not be recorded. For more information, click here.

Visit Blog

States Struggle with Regulating Risks Associated with College Closures

Based on an unprecedented number of college closures, along with complex demographic challenges showing continued reductions in the number of college-aged students, states are struggling to determine how to best protect both students and college employees. Currently, most states have been reactive, and have only taken action after a college has announced its intention to close, often with little notice to employees and students. On the other hand, requiring a college that is just starting to show signs of financial struggle to publicly announce that position would surely chill student applications, encourage transfers, limit financing, and send employees fleeing for other employment. In turn, this could exasperate the college’s financial condition, all but ensuring closure. In Massachusetts, where 18 colleges have closed or merged in the past five years, the legislature is looking at several options. Specifically, Massachusetts Governor Charlie Baker has proposed a bill that would require notification of “any known liabilities or risks which may result in imminent closure of the institution or jeopardize the institution’s ability to fulfill its obligations to current and admitted students,” with notice to the Massachusetts Board of Higher Education (MBHE). Because the proposed legislation allows the notification to be confidential, it is intended that colleges could still freely pursue financing, merger, and/or the continued enrollment of students in order to try to turn around its financial condition. When notifying the Board, the school must also put forth a contingency plan for notifying students and assisting with transfer in case closure becomes necessary. The bill also would allow the state to request financial data from schools.  If a school failed to provide the requested data, it could be sanctioned by the Board of Higher Education. The MBHE has issued proposed regulations consistent with this bill. Two or three hearings to allow for public comment on the regulations will be scheduled in early August.

Visit Blog

Has Investigative Genealogy Become the Wild, Wild West?

DNA technology has assisted law enforcement in identifying criminals for decades.  The U.S. National DNA Database System stores the DNA data of millions of criminals, and allows law enforcement officers around the country to compare and match forensic evidence in this central repository.  This closed universe of DNA only contains data from individuals arrested or convicted of a crime.  Law enforcement officials who seek to use this information are subject to numerous rules, regulations and procedures governing how and when it can be used. As we posted earlier, however, commercial DNA databases and civilian genetic genealogists also have become an attractive investigative tool for law enforcement.    Some commercial labs do not give law enforcement access to their database.  For example, 23andMe states on its website “23andMe chooses to use all practical legal and administrative resources to resist requests from law enforcement, and we do not share customer data with any public databases, or with entities that may increase the risk of law enforcement access.”  Other companies, such as Parabon NanoLabs, have focused their efforts on offering their genetic genealogy services to law enforcement.  Last year, Parabon identified William Earl Talbott, II as a suspect in the murders of Jay Cook and Tanya Van Cuylenborg.  Talbott’s trial, set to begin in July, will be one of the first to confront issues related to the use of these services. Generally, courts have yet to address questions about the implications of the use of familial DNA.  As is typical, the law needs to catch up with science.  Lawmakers should take up this matter soon, as the use of this technology continues to grow and the pressure to allow the use of the DNA profiles increases.  Many interesting ethical and legal issues have already been raised, including questions about Fourth Amendment protections and the privacy rights of individuals.

Visit Blog

Fourth Circuit Expands Title IX Liability for Harassment Through Anonymous Online Posts

The Fourth Circuit recently held that universities could be liable for Title IX violations if they fail to adequately respond to harassment that occurs through anonymous-messaging apps. The case, Feminist Majority Foundation v. Hurley, concerned messages sent through the now-defunct app Yik Yak to the individual plaintiffs, who were students at the University of Mary Washington. Yik Yak was a messaging app that allowed users to anonymously post to discussion threads.  Because of the app’s location feature, which  allowed users to see posts within a 5 mile radius, the Court concluded that the University had substantial control over the context of the harassment because the threatening messages originated on or within the immediate vicinity of campus. Additionally, some of the posts at issue were posted using the University’s wireless network, and thus necessarily originated on campus. The Court rejected the University’s argument that it was unable to control the harassers because the posts were anonymous. It held that the University could be liable if it never sought to discern whether it could identify the harassers. The dissent encouraged the University to appeal the decision stating that “the majority’s novel and unsupported decision will have a profound effect, particularly on institutions of higher education . . .  Institutions, like the university, will be compelled to venture into an ethereal world of non-university forums at great cost and significant liability, in order to avoid the Catch-22 Title IX liability the majority now proclaims. The university should not hesitate to seek further review.”

Visit Blog

Smile and Say “Cheese” — When is a Photo an Educational Record under FERPA?

As the myriad of Family Educational Rights and Privacy Act  (FERPA) interpretation issues continues to cloud many educators’ understanding of what is permissible and not permissible under the statute, some assistance was recently provided by the U.S. Department of Education. The Family Policy Compliance Office (FPCO) advises that as with any other “education record,” a photo or video of a student is an education record, subject to specific exclusions, when the photo or video is:  (1) directly related to a student; and (2) maintained by an educational agency or institution or by a party acting for the agency or institution. The issue has been in regards to defining when a record is in fact directly related to a student, and when it is not. This threshold is important because a record not related to a student is not subject to FERPA restrictions.  As this has been an ongoing point of confusion, FPCO’s policy requires a case-by-case analysis that focuses on whether the school photograph or video was directly related to a particular student or merely incidentally related.  Examples of videos or photos that are most likely deemed directly related are: (i) the photo or video is being used in a disciplinary capacity involving the student or victim; (ii) the photo or video shows the student involved in an illegal activity; (iii) the photo or video shows the student being injured or attacked, or having a health emergency; (iv) the person taking the photo or video is intending to take an image of that specific student (i.e., ID photos or recording a student presentation); or (v) the image otherwise includes personally identifiable information. It is important to remember that only images captured by the school agents have FERPA applicability, thus, parents photographing students playing in a school basketball game would not be covered by FERPA. Although these policies do provide some clarification for educators, the subjective case-by-case nature of the policy will continue to raise questions until the courts have an opportunity to consider and rule on the circumstances and applicability of these clarifications.

Visit Blog

EDUCAUSE Challenges the US DOE’s Guidance on Data Breach Reporting

On January 30, 2018, EDUCAUSE, a higher education technology association, submitted a letter to the U.S. Department of Education describing concerns that it had with the Federal Student Aid (“FSA”) ability to protect federal student financial aid data. EDUCAUSE’s members include IT professionals from over 1,800 colleges and universities as well as other organizations. First, EDUCAUSE expressed concerns about letters that various colleges and universities received from the FSA. These letters indicated that a data breach or suspected data breach occurred at educational institutions, and required the institutions to make a full accounting of their information security program. Some of the letters also indicated that the institutions failed to self-report alleged or suspected breaches. It appeared that the FSA identified these institution from news reports, but EDUCAUSE expressed concern that FSA did not confirm that the breaches or suspected breaches occurred prior to sending the letter. Second, EDUCAUSE expressed concerns that FSA did not have proper reporting procedures in place. In late 2017, the FSA stated that notifications could be made via text message to an FSA official’s cellphone number. It also indicated that blocked phishing attempts constituted a suspected data breach that must be “immediately reported,” (i.e. on the date of detection). Institutions were concerned that they would not have sufficient time to investigate a suspected breach and that institutional resources would be overly taxed. They were also concerned that the FSA did not have standardized, secure processes for receiving and storing sensitive information. EDUCAUSE requested that the FSA disclose the basis for its guidance, including the iteration of the FSA’s Program Participation Agreement or FSA Student Aid Information Gateway agreement. It also argued that the FSA should act collaboratively with institutions to developed reporting standards, guidance and processes. Finally, it challenged the FSA’s ability to require institutions to report all breaches or suspected breaches rather than limit their reporting obligations to those related to federal financial aid data. In a blog post written the following date, EDUCAUSE indicated that it expected a meeting to occur with FSA representatives in the following several days. However, it does not appear that any meeting has taken place yet.

Visit Blog

US Supreme Court Evaluates Privacy of Cell Phone Data

Last Thursday, the United States Supreme Court heard arguments in Carpenter v. United States.  At issue was whether the FBI violated the Fourth Amendment when it obtained the cellphone location records of Timothy Carpenter.  The FBI used these records to establish Mr. Carpenter’s whereabouts during time periods in which certain armed robberies occurred.  The government argued that Mr. Carpenter did not have an expectation of privacy in these records and, thus, no warrant was required.  Mr. Carpenter argued that “carrying a smartphone, checking for new emails from one’s boss, updating the weather forecast, and downloading directions ought not license total surveillance of a person’s entire life.” In recent years, the Court has limited the ability of law enforcement to gather information without a warrant in two other situations.  In 2012, the Court held that law enforcement could not install a GPS tracking device on a suspect’s car without a warrant in United States v. Jones.  Two years later, the Court held that a suspect’s phone could not be searched without a warrant in Riley v. California.  In Jones, Justice Sotomayor suggested that the Court might have to reconsider whether an individual has a reasonable expectation of privacy in information that is voluntarily disclosed to third parties.  Generally, the third-party doctrine holds that individuals do not have a reasonable expectation of privacy to information that they voluntarily give to third parties (such as banks, phone companies, internet service providers and e-mail servers.  Justice Sotomayor wrote, “[t]his approach is ill-suited to the digital age, in which people reveal a great deal of information about themselves to third parties in the course of carrying out mundane tasks.” During oral argument, several of the Justices appeared to be troubled by the government’s argument that the Fourth Amendment was not implicated in this case.  Their concerns ranged from trepidation that if the government were able to take advantage of the amount of data collected by evolving technology the Fourth Amendment may become meaningless to questioning whether property rights may be implicated.  The Court’s decision in Carpenter will have enormous import for not only how law enforcement can gather cellphone information, but also how the third-party doctrine applies to technology as more and more devices collect information on our daily lives.

Visit Blog

Empowerment or Intrusion? The College Transparency Act of 2017

Stating the obvious, college is one of the most important and expensive investments Americans make. In addition to tuition costs, from a consumer perspective, other factors should be important in deciding on a college, including graduate employment prospects, average student loan debt, and average number of semesters taken to complete a degree. If you were making a decision on buying a car, you would have access to a tremendous amount comparative information, some generated and collected by the federal government, and other information coming from the manufactures themselves. Despite the fact that vast amounts of very detailed consumer information exists regarding colleges that could be used by students for comparison purposes, the Higher Education Act currently prevents the collation and publication of this otherwise useful comparative data. As a result of the Higher Education Act, students are left with incomplete and inconsistent data to base their college decision on.  Accordingly, the College Transparency Act of 2017, backed by primarily state colleges, looks to remedy this gap by allowing data the federal government is already existing to be combined and published. The proponents of the bill argue that maximizing information availability both empowers students to choose the school that is best for them, while also holding schools accountable for their outcomes. Opponents of the bill (mainly private institutions) fear the risks of having the government amass such a large database of information which actually includes information about individual students. In addition to concerns about privacy and electronic security breaches, there are fears the collection of this data could also allow the government to target specific students, such as the undocumented students otherwise protected by the Development, Relief and Education for Alien Minors Act (“Dreamers”). Ultimately the benefits of using big data for consumer purposes creates tension for those concerned about privacy. Until the concerns about protecting privacy are overcome, it remains unlikely the bill will pass.

Visit Blog

State of Connecticut Provides Guidance on Changes to Education Records of Transgender Students

The Connecticut State Department of Education (DOE) recently published guidance on implementing civil rights protections for transgender students. The guidance, in part, provides information on issues related to requests that a school change a student’s education records to be consistent with their chosen name and gender identity. Notably, the guidance recognized tension that may arise in some circumstances over who is entitled to request a change to a student’s education records. Under the Family Educational and Privacy Act (FERPA), a student who is 18 years old or older, or the parents/guardians of students under the age of 18 have a right to request that misleading or inaccurate information in the student’s education record be corrected. The DOE concluded, however, that under civil rights laws a student under the age of 18 may have the right to change their education records even if their parent/guardian disagrees with the change. Recognizing that there was not clear case law on this issue, the DOE recommended that schools consult with legal counsel and counseling staff if such a disagreement arises. Until the disagreement is resolved, however, schools are directed to refer to the student in accordance with the student’s preference. Guidance was also provided as to the maintenance of education records. The DOE stated that under FERPA, in a circumstance where a student is using a chosen name, that student’s birth name and gender are considered private medical information and, thus, this information may not be disclosed unless the disclosure is permitted by one of FERPA’s exceptions. Any records containing this information must be kept separate from the student’s cumulative record to maintain the student’s privacy. The DOE also advised schools to develop a process for students and/or their parents/guardians to request that a student’s education records be changed to be consistent with the student’s chosen name and gender identity. The process should not require unique hurdles for requesting these types of changes, and should recognize that a student is not required to legally change their name before correcting their school record. Students and/or their parents/guardians should be advised by the school that if a student does not complete a legal name change, the discrepancy between the student’s education records and his/her college materials, driver’s license and other future documents may create an issue.

Visit Blog

Southern Oregon University Victim of Phishing Scheme

Last month, Southern Oregon University (SOU) announced that it was the victim of a $1.9 million phishing scheme. SOU received an email purportedly from their contractor, Anderson Construction, requesting the April payment for construction on the McNeal Pavilion and Student Recreation Center. An employee then sent funds to a bank account that the contractor did not control. SOU learned of the scheme three days later when the contractor reported that it never received the payment. Law enforcement are investigating and efforts are currently underway to recover the funds. SOU General Counsel Jason Catz stated that the school has learned from law enforcement sources that it is not the only victim to this particular scheme, which has targeted other higher education institutions.

Visit Blog

Illinois Court Rules That College Foundation Documents Subject to FOIA

On May 9, 2017, the Illinois Appellate Court held that the College of DuPage Foundation (Foundation), a fundraising organization for the public College of DuPage (College), is subject to the state’s open records law. In doing so, the Court rejected the Foundation’s argument that it was a charitable organization with no public role, and instead found that the Foundation was performing a government function for the College. In April 2015, the College and the Foundation received a series of Freedom of Information Act (FOIA) requests from the Chicago Tribune (Tribune) seeking, among other documents, any federal grand jury subpoena received by the Foundation. The College responded that it did not have any responsive documents, and the Foundation stated that it was not subject to FOIA. The College had, in fact, received a federal grand jury subpoena (Subpoena) directed to the Foundation, which was provided to the Foundation and then delivered to the Foundation’s outside counsel. After it was denied access to the Subpoena, the Tribune brought suit against both the Foundation and the College.  The Court’s decision that the Subpoena was a public record centered around the relationship between the Foundation and the College. The Foundation managed the College’s entire fundraising operation, the Foundation and the College shared employees, and these employees received state health and retirement benefits. While employees distinguished between the time spent on Foundation business and College business, any time allocated to the Foundation was deemed an “in-kind” donation from the College to the Foundation. The Court distinguished the facts of this case from a FOIA request issued to a parent-teacher association, booster club, or other volunteer organization that fundraises to support a school. Those organizations would be staffed by volunteers, not state employees, and would not manage the school’s entire endowment. This decision is the first time that an Illinois state appeals court has ruled in favor of releasing records possessed by a quasi-public organization that raises funds on behalf of a public institution. It could have broader implications for public agencies and their contractors who perform government functions.

Visit Blog

EFF Report Finds That Student Data is Not Adequately Protected By Ed Tech Companies

On April 13, 2017, the Electronic Frontier Foundation (EFF) published Spying on Students, a report detailing its investigation into school-issued devices and student privacy. EFF found that parents were overwhelmingly not informed about what educational technology (Ed Tech) their students were using. As a result, students and/or parents were the ones burdened with investigating what Ed Tech was used, what privacy policies were governed, and what privacy implications they may carry. Not surprisingly, parents were particularly concerned with what personally identifiable information was being collected and whether that information would be shared or sold. EFF also analyzed the privacy policies of every Ed Tech app, software, programs or services identified by its survey recipients. Of the 152 Ed Tech services reported, only 118 had privacy policies available online. Few policies addressed deletion of data after periods of inactivity. Less than a third stated that the vendor used encryption or mentioned de-identification or aggregation of user data. The report also concluded that parents and students had difficulty opting out of this Ed Tech. Forty percent of parents who responded to the survey did not know whether it was possible to opt-out. Thirty percent were sure that they could not opt-out. It was also apparent to EFF researchers that parents and students were not satisfied with privacy policies and legislation. They wanted to know what was actually happening to their student data. Many survey respondents did not think that teacher training was sufficient to implement adequate privacy protections. Many students also lacked education on privacy issues. EFF recommended that Ed Tech companies and schools should work together to inform students about their online data trails, privacy expectations and common-sense measures for protecting their privacy. EFF concluded that student privacy was not being adequately addressed by schools or Ed Tech vendors. In order to make meaningful improvements, EFF advised that changes in state and federal law, school and district priorities, and Ed Tech company policies and practices were necessary.

Visit Blog

IRS to Notify 100,000 Taxpayers That Their Information May Have Been Obtained Through Misuse of FAFSA Retrieval Tool

On Thursday, Internal Revenue Service (“IRS”) Commissioner John Koskinen testified that the personal data of up to a 100,000 taxpayers could have been compromised as a result of criminal use of the Free Application for Federal Student Aid Data Retrieval Tool (“DRT”). Last week, we posted that the IRS disabled the tool after it suspected that hackers were posing as students and using the DRT to gather students’ and parents’ tax information. This information could then be used to file fraudulent tax returns and steal refunds. The number of taxpayers who may have been affected still remains unknown, but the agency believes that fewer than 8,000 fraudulent returns were filed and processed. Another 14,000 fraudulent returns were spotted by investigators before refunds were issued, and another 52,000 filings were halted altogether. To be safe, the IRS announced that it plans to notify all 100,000 potentially affected taxpayers.

Visit Blog