1. Home
  2. |Insights
  3. |DPAS Regs Updated and Expanded

DPAS Regs Updated and Expanded

Client Alert | less than 1 min read | 08.15.14

On August 14, 2014, Commerce's Bureau of Industry and Security issued a final rule revising the Defense Priorities and Allocations System (DPAS) Regulations. Among other changes, the final rule (1) expands the scope of DPAS coverage by adding homeland security and critical infrastructure protection/restoration activities as reasons that rated orders may be issued; (2) adds language clarifying that recipients of rated orders have delegated authority to place ratings on contracts or orders with lower-tier contractors, subcontractors, and suppliers; and (3) reduces the time for written follow-up if a party is unable to comply with a rated order. 

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....