1. Home
  2. |Insights
  3. |GAO Faults Corrective Action Reevaluation

GAO Faults Corrective Action Reevaluation

Client Alert | less than 1 min read | 08.27.15

In eAlliant, LLC (Jan. 14, 2015), GAO demonstrated that reevaluations based on "corrective action" must independently pass muster. Here, the record contained no rational basis or explanation for why the official who had previously credited the protester's technical proposal with multiple strengths had allowed the removal of all but one strength during subsequent reevaluations when there were no material revisions to the RFP's technical requirements or to the protester's proposal.


Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....