Standardizing Federal PII Breach Response: OMB Updates Guidance for Agencies, Contractors, and Grant Recipients
Client Alert | 1 min read | 01.11.17
On January 3, 2017, the Office of Management and Budget (OMB) issued M-17-12, which updates and supersedes 2006 and 2007 OMB memoranda on preparing for and responding to breaches of personally identifiable information (PII) by imposing minimum standards on agencies for incident response programs, training and awareness, reporting, and documentation, coupled with requiring use of a flexible framework to assess and mitigate the risk of harm to individuals potentially affected by a PII breach. While making clear that a PII breach does not necessarily indicate an absence of adequate safeguards, the updated guidance also requires agencies to impose specific requirements, such as encryption, training, and incident-response obligations, on all contractors and subcontractors (at any tier); identifies PII-related requirements for federal grant recipients; and directs the FAR Council to “promptly… create appropriate contract clauses and regulatory coverage.”
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 04.08.26
Cosmetics Under the Microscope: FDA’s Expanding Regulatory Reach Under MoCRA
The Modernization of Cosmetics Regulation Act of 2022 (MoCRA) marked the most significant expansion of FDA’s authority over cosmetics in 80 years — and the agency is putting that authority to work. From the launch of a new adverse event reporting tool to forthcoming rules on fragrance allergens and good manufacturing practices (GMP), FDA is reshaping the regulatory landscape for manufacturers, packers, and distributors of cosmetic and personal care products.
Client Alert | 11 min read | 04.08.26
Client Alert | 3 min read | 04.07.26
Answering the Top Seven Questions About Pending Section 301 Deadlines
Client Alert | 3 min read | 04.07.26
EU Pharma Package: Fiscal Imports in the Supply Chain Compromise Proposal

