1. Home
  2. |Insights
  3. |NISPOM Revised to Incorporate DSS and GCA Requirements

NISPOM Revised to Incorporate DSS and GCA Requirements

Client Alert | 1 min read | 08.08.18

On August 1, 2018, DoD published the National Industrial Security Program: Industrial Security Procedures for Government Activities (“Volume 2”), which finally replaces the 1985 Industrial Security Regulation much as the original National Industrial Security Program Operating Manual (NISPOM) had replaced the Industrial Security Manual applicable to contractors. Volume 2 prescribes security practices applicable to U.S. government activities and includes an extended discussion of facility security clearances (FCLs), including examples of documentation that sponsoring agencies can use to justify an FCL, an exception for continued FCL processing even if it cannot be completed in time to qualify the company for participation in a procurement action, and uniform criteria for identification of key management personnel for various business structures. Volume 2 also establishes detailed procedures for DSS oversight of contractor investigations of compromised information, DSS processing of limited access authorization, and DSS requirements for international security programs including foreign government and contractor access to U.S. classified information.

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....