Validating Cyber Compliance in Light of the First DFS Enforcement Action

We recently reported on the New York State Department of Financial Services' (DFS) first enforcement action under its 2017 cybersecurity regulation ("Part 500"), which prescribes how financial services companies licensed to operate in New York should construct their cybersecurity programs. DFS' statement of charges provides important insight into the agency's priorities and expectations when assessing how a company has addressed and mitigated a data exposure, and offers a roadmap for how other regulators might interpret similar data security laws being implemented across the country. Given increasing regulatory scrutiny and the fact that inappropriate cybersecurity procedures and practices could result in significant financial liabilities, companies should proactively re-assess where they stand in relation to applicable cyber mandates.

We highlight here some key takeaways from the recent DFS enforcement action that entities subject to Part 500 should carefully consider when validating their current state of compliance. More ›

Another Cybersecurity Wake Up Call: Connecticut Insurance Department Issues Guidance on Cyber Law Set to go Into Effect

Covered entities received two cybersecurity wake up calls from insurance regulators this month. As we have reported, the New York State Department of Financial Services (DFS) issued its long-awaited first cyber enforcement action pursuant to its groundbreaking and first-in-nation cybersecurity regulation. In addition, the Connecticut Insurance Department issued a Bulletin to all licensees, providing guidance for compliance with the Connecticut Insurance Data Security Law (the Act), which goes into effect on October 1, 2020. The Act was modeled after the National Association of Insurance Commissioners Model Cybersecurity Law, which itself was modeled after the DFS cybersecurity regulation. More ›

New York Courts Lift Suspension of Foreclosure Proceedings, Add Additional Conference Requirement

On July 24, 2020, the New York State Courts issued Administrative Order 157/20 (AO/157/20). Effective July 27, 2020, AO/157/20 removes the formal suspension of all residential foreclosures, but keeps a limited suspension of commercial foreclosures in place until August 19, 2020. Under this new directive, foreclosure actions can be resumed by courts first scheduling at least one conference. Those conferences are expected to be the same as the mandatory CPLR 3408 settlement conferences—even if settlement conferences were previously held—because the courts were directed to consider all aspects of the case, including "the effects, if any, that the COVID-19 pandemic has had upon the parties." More ›

Long-Awaited DFS Cyber Enforcement Action Sees Charges Filed Against Title Insurer For Exposing Millions of Documents Containing Consumer Personal Information

After several years of anticipation, the New York State Department of Financial Services (DFS) has filed its first enforcement action under the agency's groundbreaking and first-in-the-nation 2017 cybersecurity regulation (Part 500 of Title 23 of the New York Codes, Rules, and Regulations), which prescribes how financial services companies licensed to operate in New York should construct their cybersecurity programs. This action is a wakeup call to covered entities to fully implement the directives of Part 500. More ›

SCOTUS Decides Federal Debt is not Exempted from TCPA, While FCC Autodialer Declaration Further Alters TCPA Landscape

With a major U.S. Supreme Court decision leading the way, recent developments continue to reshape the landscape of the Telephone Consumer Protection Act (TCPA). More ›

FCC Clarifies Autodialer Definition, Including in Bulk Text Message Context

The Federal Communications Commission (FCC) recently issued a Declaratory Ruling clarifying the definition of an autodialer. Exactly what constitutes an autodialer under the TCPA has been a burgeoning topic in consumer litigation. The TCPA prohibits any person from texting or calling a cellular telephone number using an automatic dialing system (“autodialer” or “ATDS”) without prior express consent. The TCPA defines an ATDS as equipment which has the capacity to (A) to store or produce telephone numbers to be called, using a random or sequential number generator; and (B) to dial such numbers. More ›

SCOTUS Holds CFPB's Single Director Structure Unconstitutional, Leaves Open Questions on Existing Bureau Matters

Earlier today, the United States Supreme Court issued a two part decision in Seila Law LLC v. Consumer Financial Protection Bureau. The Court first decided, in a 5-4 decision with Chief Justice Roberts authoring the Court's opinion, that the CFPB's leadership by a single Director removable only for inefficiency, neglect, or malfeasance violates the separation of powers doctrine. The Court next decided that the Director's unconstitutional removal protection is severable from the other provisions of Dodd-Frank that establish the CFPB and define its authority. The severability holding was also authored by Roberts, but drew a 7-2 split. More ›

New York State Enacts New Procedures for Residential Mortgage Forbearance Plans

On June 17, 2020, New York Governor Andrew Cuomo signed Senate Bills 8243C and 8428 into law, adding Section 9-x to the Banking Law. The section creates new procedures for mortgagors and servicers in relation to forbearances of residential mortgage payments affected by the COVID-19 pandemic. More ›

Rhode Island Supreme Court Demands Strict Compliance with Fannie Mae/Freddie Mac "Paragraph 22" in Foreclosures

In a case of first impression, the Rhode Island Supreme Court concluded in Woel v. Christiana Trust that mortgage default notices sent to borrowers must strictly comply with the notice requirements included in a mortgage. The Court held that a lender's notice of default does not strictly comply with the terms of the standard Fannie Mae/Freddie Mac mortgage Paragraph 22, if the notice fails to inform the borrower of the right to reinstate after acceleration. More ›

New York DFS Launches "FastForward" Program Aimed at Driving Innovative Financial Services and Products

In support of re-opening and adapting New York to the new economic and social normal caused by COVID-19, New York's Department of Financial Services (DFS) announced the launch of a program called "DFS FastForward" which will support innovators who can deliver novel digital solutions that advance the state's recovery from the pandemic. The program builds on the successful launch in February of an InsurTech pilot program by DFS, and promises to "reduce barriers and speed up" the regulatory process for qualifying services and products. More ›