Data Privacy + Cybersecurity Insider
CYBERSECURITY
Employees Hiding Use of AI Tools at Work
A new study by Ivanti illustrates that one out of three workers secretly use artificial intelligence (AI) tools in the workplace. They do so for varying reasons, including “I like a secret advantage,” “My job might be reduced/cut,” “My employer has no AI usage policy,” “My boss might give me more work,” “I don’t want people to question my ability,” and “I don’t want to deal with IT approval processes.” Read more
ENFORCEMENT + LITIGATION
The VPPA: The NBA and NFL Ask SCOTUS to Referee
On April 22, 2025, the National Football League (NFL) filed an amicus brief asking the United States Supreme Court to take on a Video Privacy Protection Act (VPPA) class action case against the National Basketball Association (NBA). In my last post, we covered a recent VPPA lawsuit against a movie theater company and reviewed the provisions of the Act. In recent years, we analyzed how plaintiffs have applied the VPPA outside of traditional video contexts. This week, we dive deeper into a VPPA case against the NBA and explore the NFL’s amicus brief supporting the NBA’s position, asserting why the Act should not apply in the modern video streaming context, particularly for sports leagues. Read more
DATA PRIVACY
California Privacy Protection Agency Releases Updated Regulations: What’s Next?
This month, the California Privacy Protection Agency (CPPA) Board discussed updates to the California Consumer Privacy Act (CCPA) draft regulations related to cybersecurity audits, risk assessments, automatic decision-making technology (ADMT), and insurance. Read more
Todd Snyder Fined for Technical CCPA Violations
The California Consumer Privacy Protection Agency (CPPA) Board issued a stipulated final order against Todd Snyder, Inc., a clothing retailer based in New York, requiring the company to pay a $345,178 fine and update its privacy program to settle allegations that it violated the California Consumer Privacy Act (CCPA). Specifically, Todd Snyder must update its methods for submitting and fulfilling privacy requests and provide training to its staff about CCPA requirements. Todd Snyder is also required to maintain a contract management and tracking process so that required CCPA contractual terms are included in contracts with third parties with access to or receipt of personal information. Read more
HIPAA
Ascension Notifies 430,000 Patients of Data Breach
Healthcare system Ascension has notified 437,329 patients of a data breach exposing “demographic information, such as name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers, as well as clinical information related to an inpatient visit.” Read more
ARTIFICAL INTELLIGENCE
Generative AI Training may not Qualify for the Fair Use Defense
Last week, the Copyright Office released the third and final part of its report exploring copyright-related issues posed by artificial intelligence (AI). Unlike the first two parts, the third was released as a “pre-publication” version. It was published less than a day after Dr. Carla Hayden, the Librarian of Congress, was fired by President Trump and a day before Shira Perlmutter, the Register of Copyrights, was fired by President Trump. Building off its earlier parts, the latest publication focuses on how copyright law and the fair use defense should be applied to companies that use copyrighted works to train AI models. Read more
Privacy Tip #443
Fake AI Tools Used to Install Noodlophile
Threat actors are leveraging the publicity around AI tools to trick users into downloading the malware known as Noodlophile through social media sites.
Researchers from Morphisec have observed threat actors, believed to originate from Vietnam, posting on Facebook groups and other social media sites touting free AI tools. Users are tricked into believing that the AI tools are free, and unwittingly download Noodlophile Stealer, “a new malware that steals browser credentials, crypto wallets, and may install remote access trojans like XWorm.”
Learn more in this week’s Privacy Tip so you can mindful of this threat while using social media. Read more
RECENT EVENTS AND NEWS
Linn Freedman Discusses Cybersecurity Law at CBA Litigation Section’s 2025 Spring Retreat
Data Privacy + Cybersecurity team chair Linn Freedman presented at the Connecticut Bar Association (CBA) Litigation Section’s 2025 Spring Retreat on May 15, 2025, in Chatham, MA. Linn’s presentation, titled “Cybersecurity Issues for Litigators,” focused on the intersections of cybersecurity and the law, specifically, law firms are targets for cybersecurity incidents, the risk to law firms of using AI tools, legal obligations following cyber incidents, and how cyber-liability insurance applies to responses to cyber incidents.
Kathryn Rattigan Presents Information Governance Program at ARMA Keystone PA 2025 Spring Seminar
Information Governance + Record Management team partner Kathryn Rattigan presented a program titled “Risks and Compliance: Is your InfoGov and Retention Program Up to Par?” as part of the ARMA Keystone Pennsylvania Chapter’s 2025 Spring Seminar, “The Modernization of a RIM Professional Essentials and Beyond,” on May 15, 2025. Kathryn’s presentation kicked-off the Seminar with a focus on information governance and retention program requirements and how to internally review compliance needs to avoid unnecessary risk or government intervention.



