• HIPAA and its Business Associate Requirements;
• Federal Trade Commission (FTC) data security enforcement actions against company failures to oversee service providers with access to personal information;
• State information security laws requiring oversight of data- related service providers;
• The Gramm-Leach-Bliley Act; and
• Payment Card Industry Data Security Standards.12