For the New Year, Out with Origin but In with New Definitions of Source & Nationality
Client Alert | 1 min read | 01.11.12
In a final rule published yesterday (but not effective until February 6), USAID revamped its source, origin, and nationality rules applicable to procurement of goods and services purchased with Foreign Assistance Act (FAA) funds both to implement the 1993 amendments to the FAA and to keep pace with the globalized economy. The new regulations adopt a single, presumptively authorized geographic code 937 (which includes the United States, the cooperating or recipient country, and developing countries, exclusive of advanced developing countries and prohibited sources) and eliminate the “increasingly obsolete and difficult to apply” origin requirement, while changing the definitions of source and nationality to ensure that “fly-by-night” entities cannot be set up somewhere within the authorized geographic region to evade the restrictions.
Contacts
Insights
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen.
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Client Alert | 4 min read | 08.13.26
Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach
Client Alert | 7 min read | 08.12.26
Developments in Canadian Investment Treaty Practice: New FIPA Between Canada and UAE in Force

