On July 20, 2026, Pennsylvania Governor Josh Shapiro signed SB 992, updating and expanding Pennsylvania’s Telemarketer Registration Act of 1996 and strengthening restrictions on unwanted telemarketing communications. The law reflects that telemarketing is no longer limited to live calls and that texts, prerecorded messages, and other automated tools are increasingly reaching consumers and businesses
Pennsylvania
When an AI Chatbot Calls Itself a Doctor
Pennsylvania’s lawsuit against Character Technologies, Inc., is a notable early test of how professional licensing laws may apply to consumer-facing AI chatbots. The Commonwealth, acting through the Department of State and State Board of Medicine, filed a Petition for Review in the Commonwealth Court of Pennsylvania seeking to restrain what it alleges is the unlawful…
Not Every Wiretap Claim Belongs in Federal Court: Federal Court Sends Pennsylvania Case Back to State Court
While California’s wiretapping statute, the California Invasion of Privacy Act (CIPA), tends to dominate the conversation about the recent rise in wiretapping litigation, plaintiffs are also turning to other states’ wiretapping laws to target web tracking and session-replay tools. The U.S. Court of Appeals for the Third Circuit recently held that a website visitor could…
New State Privacy Laws Expand Consumer Data Control in 2026
On January 1, 2026, broad new privacy laws will take effect in Kentucky, Indiana, and Rhode Island, granting consumers in those states greater control over their personal data. With these additions, 19 states now have comprehensive privacy laws in place, which is a significant shift in the data privacy landscape since California led the way in 2018 with the…
Pennsylvania Attorney General Announces Recent Cyber-Attack: What You Need to Know about Citrix Bleed 2
On August 11, 2025, the Pennsylvania Office of Attorney General (PA AG) issued a statement on its Facebook account regarding a cyber incident that had affected PA AG systems, including its website, email accounts, and phone lines.
The PA AG has not shared a specific cause of the incident. However, security researcher Kevin Beaumont recognized…
Pennsylvania Teacher’s Union Faces Class Action over Data Breach
The Pennsylvania State Education Association (PSEA) faces a class action resulting from a July 2024 data breach. The proposed class consists of current and former members of the union as well as PSEA employees and their family members. The lawsuit alleges that the union was negligent and breached its fiduciary duty when it suffered a…
EyeMed Pays Four State AGs $2.5M for Data Breach
EyeMed Vision Care, LLC has agreed to settle allegations lodged against it by four state Attorneys General for $2.5 million stemming from a data breach that occurred in 2020 and effected 2.1 million people.
The settlement is with the AGs of Florida, New Jersey, Oregon, and Pennsylvania. The breach occurred when threat actors infiltrated EyeMed’s…
At Least 22 States Have Consumer Privacy Legislation Pending – Will 2022 Be the Year for More State Privacy Laws?
California is the gold standard for state privacy laws, having recently enacted the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Virginia and Colorado also have enacted comprehensive privacy laws, which will take effect in 2023. Recently, the International Association of Privacy Professionals (IAPP) released its state privacy legislation tracker.…
Contact Tracing Vendor Loses State Contract Over Data Breach
Pennsylvania Governor Tom Wolf announced this week that the Commonwealth will not continue to do business with its contact tracing vendor following a security incident that potentially exposed the personal information of approximately 72,000 residents collected for the Department of Health’s (DoH) contact tracing program.
According to the (DoH), employees of the vendor created documents…
Crozer-Keystone Health System Data for Sale Online by Attackers
It is being reported by Cointelegraph that ransomware group Netwalker is offering for sale data it exfiltrated from Pennsylvania based Crozer-Keystone Health System after the system declined to pay the requested ransom.
According to the report, Netwalker offered to sell the data through its darknet website for six days and if no one buys it,…