NIST Now "King of the Hill" on Cyber Standards
Client Alert | 1 min read | 05.14.13
Following its key cyber role in President Obama's Executive Order No. 13636 issued this February, the National Institute of Standards and Technology (NIST) again seized the reins on federal cybersecurity standards on April 30, issuing the 457-page tome, Security and Privacy Controls for Federal information Systems and Organizations, that not only provides the "most comprehensive update" of the core information security controls, but also cuts new ground for cybersecurity standards governing mobile and cloud computing technology, applications security, supply chain protection, advanced persistent threats, and privacy controls for federal agencies and contractors. While some critics have sought to brush back prior NIST standards as too voluminous and technically dense, this latest publication underscores NIST's increasing dominance over cyber standards, as shown by both DoD and the Office of the Director of National Intelligence embracing this NIST update, thus paving the way for federal agencies to flow down new and expanded security standards to government contractors consistent with the executive order's directive to the FAR Council.
Contacts
Insights
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
On August 13, 2026, the Centers for Medicare and Medicaid Services (CMS) published its final rule banning the use of federal funds — through Medicaid and the Children’s Health Insurance Program (CHIP) — to pay for gender-affirming care for children and youth. The final rule takes effect October 13, 2026 (“Prohibition on Federal Medicaid and Children's Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children”). While CMS finalized several key elements of its late-2025 proposed rule (Client Alert December 24, 2025), the proposed Medicare hospital Condition of Participation rule remains in proposed form.
Client Alert | 2 min read | 08.19.26
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

