On December 10, 2024, the Centers for Medicare & Medicaid Services (CMS) published a proposed rule with technical changes for the Medicare Advantage (MA) Program and the Medicare Prescription Drug Benefit Program for Calendar Year 2026 (Proposed Rule). Citing the growing use of Artificial Intelligence (AI) within the healthcare sector and reports that the use of AI may lead to “algorithmic discrimination” that exacerbates inequalities within healthcare, CMS proposes, for the first time, new guardrails that must be adopted by MA plans when using AI to manage patient care. CMS also proposes several reforms addressing utilization management (UM) techniques adopted by MA plans, including requirements for such plans to conduct and report detailed analyses on the use of prior authorizations. Notably, the Proposed Rule primarily modifies MA regulations, without direct application to the Medicare Part D prescription drug program.
Sidley thought leaders explored risks and opportunities of a second Trump administration in a “lightning round”, covering key practice areas. Change is coming and along with it, new and fast-paced risks and opportunities.
Check out the November edition of Spotlight on Women in Privacy! Esther Silberstein shares her views on why she loves being a privacy professional, the best professional advice she ever received, what she’s closely watching now, and how she unwinds.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.png00Data Matters Contributorshttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngData Matters Contributors2024-12-17 12:02:562025-09-30 13:05:23Spotlight on Women in Privacy: Esther Silberstein
The EU AI Act is the world’s first horizontal and standalone law governing the commercialization and use of AI, and a landmark piece of legislation for the EU. Among the various provisions of the EU AI Act, the “AI literacy” principle is an often overlooked but key obligation which requires organizations to ensure that staff who are involved in the operation and use of AI have the necessary skills, knowledge and understanding to adequately assess AI-related risks and opportunities (e.g., through training and hiring staff with the appropriate background and skillset). This obligation – which applies from February 2, 2025 – is one of the few obligations under the EU AI Act that applies to all AI systems i.e., irrespective of the level of risk that the AI system presents. Indeed, by introducing AI literacy as one of the first provisions of the AI Act (Article 4), the EU legislators appear to underscore the significance of this requirement.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2024/12/MN-24013-Data-Matters-Blog-Imagery-Refresh_A_13.jpg606833Francesca Blythehttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngFrancesca Blythe2024-12-16 10:40:352025-09-30 13:05:55EU AI Act: Are You Prepared for the “AI Literacy” Principle?
On October 28, 2024, the U.S. Department of the Treasury (Treasury) released the Final Rule for its new regulations prohibiting or requiring notification of U.S. outbound investments in certain Chinese-affiliated companies in the semiconductor and microelectronics, quantum information technology, and artificial intelligence (AI) sectors. The Final Rule will take effect on January 2, 2025.
Recent enforcement actions by both state and federal law enforcement signal that companies that make or use artificial intelligence products are facing increased scrutiny under existing unfair and deceptive acts and practices laws. Several late-2024 examples present important insights for companies navigating how to effectively and legally implement artificial intelligence technologies in their businesses.
https://datamatters.sidley.com/wp-content/uploads/sites/2/2022/10/MN-18359_Data-Matters_833x606-04-1.jpg607833Colleen Theresa Brownhttps://datamatters.sidley.com/wp-content/uploads/sites/2/2022/09/sidleyLogo-e1643922598198.pngColleen Theresa Brown2024-12-10 10:57:462025-09-30 13:06:52Rising AI Enforcement: Insights From State Attorney General Settlement and U.S. FTC Sweep for Risk Management and Governance
Enacted in 2008, the Illinois Biometric Information Privacy Act (“BIPA”) regulates the collection and possession of biometric data by private entities operating in Illinois. Biometric data includes, for example, fingerprints, voiceprints, eye scans, and face/hand scans. Notably, BIPA establishes a private right of action, allowing any person to seek damages, attorneys’ fees, and injunctive relief if the person has been aggrieved by a BIPA violation. The statutory damages for BIPA violations are steep, including $1,000 to $5,000 per violation, attorneys’ fees and costs, and the possibility of injunctive relief.
In its 2024 fiscal year, the U.S. Securities and Exchange Commission brought over 130 enforcement actions against investment advisers and their representatives. This post highlights the key areas of focus and notable actions and litigation from the past fiscal year.
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
CMS Proposes Artificial Intelligence Limits and Utilization Management Guardrails for Medicare Advantage
On December 10, 2024, the Centers for Medicare & Medicaid Services (CMS) published a proposed rule with technical changes for the Medicare Advantage (MA) Program and the Medicare Prescription Drug Benefit Program for Calendar Year 2026 (Proposed Rule). Citing the growing use of Artificial Intelligence (AI) within the healthcare sector and reports that the use of AI may lead to “algorithmic discrimination” that exacerbates inequalities within healthcare, CMS proposes, for the first time, new guardrails that must be adopted by MA plans when using AI to manage patient care. CMS also proposes several reforms addressing utilization management (UM) techniques adopted by MA plans, including requirements for such plans to conduct and report detailed analyses on the use of prior authorizations. Notably, the Proposed Rule primarily modifies MA regulations, without direct application to the Medicare Part D prescription drug program.
(more…)
Meenakshi Datta
Chicago
mdatta@sidley.com
Catherine Y. Starks
Chicago
cstarks@sidley.com
Mariya Denisko
Chicago
mariya.denisenko@sidley.com
Post-Election Landscape: New Risks, New Opportunities
Sidley thought leaders explored risks and opportunities of a second Trump administration in a “lightning round”, covering key practice areas. Change is coming and along with it, new and fast-paced risks and opportunities.
(more…)
Data Matters Contributors
sidleyprivacyblog@sidley.com
Spotlight on Women in Privacy: Esther Silberstein
Check out the November edition of Spotlight on Women in Privacy! Esther Silberstein shares her views on why she loves being a privacy professional, the best professional advice she ever received, what she’s closely watching now, and how she unwinds.
(more…)
Data Matters Contributors
sidleyprivacyblog@sidley.com
EU AI Act: Are You Prepared for the “AI Literacy” Principle?
The EU AI Act is the world’s first horizontal and standalone law governing the commercialization and use of AI, and a landmark piece of legislation for the EU. Among the various provisions of the EU AI Act, the “AI literacy” principle is an often overlooked but key obligation which requires organizations to ensure that staff who are involved in the operation and use of AI have the necessary skills, knowledge and understanding to adequately assess AI-related risks and opportunities (e.g., through training and hiring staff with the appropriate background and skillset). This obligation – which applies from February 2, 2025 – is one of the few obligations under the EU AI Act that applies to all AI systems i.e., irrespective of the level of risk that the AI system presents. Indeed, by introducing AI literacy as one of the first provisions of the AI Act (Article 4), the EU legislators appear to underscore the significance of this requirement.
(more…)
Francesca Blythe
London
fblythe@sidley.com
Lauren Cuyvers
Brussels
lcuyvers@sidley.com
Matthias Bruynseraede
London
mbruynseraede@sidley.com
U.S. Treasury Issues Final Rule Restricting Outbound Investments in Chinese-Affiliated Entities
On October 28, 2024, the U.S. Department of the Treasury (Treasury) released the Final Rule for its new regulations prohibiting or requiring notification of U.S. outbound investments in certain Chinese-affiliated companies in the semiconductor and microelectronics, quantum information technology, and artificial intelligence (AI) sectors. The Final Rule will take effect on January 2, 2025.
(more…)
James Mendenhall
Washington, D.C.
jmendenhall@sidley.com
Carys Golesworthy
Washington, D.C.
cgolesworthy@sidley.com
Lloyd Lyall
Washington, D.C.
lloyd.lyall@sidley.com
Rising AI Enforcement: Insights From State Attorney General Settlement and U.S. FTC Sweep for Risk Management and Governance
Recent enforcement actions by both state and federal law enforcement signal that companies that make or use artificial intelligence products are facing increased scrutiny under existing unfair and deceptive acts and practices laws. Several late-2024 examples present important insights for companies navigating how to effectively and legally implement artificial intelligence technologies in their businesses.
(more…)
Colleen Theresa Brown
Washington, D.C.
cbrown@sidley.com
Christina C. Koenig
Dallas
christina.koenig@sidley.com
Benjamin M. Mundel
Washington, D.C.
bmundel@sidley.com
Lauren Freeman
San Francisco
lfreeman@sidley.com
Garrett Lance
Washington, D.C.
glance@sidley.com
Biometric Litigation Risks Endure Even Post BIPA Amendment
Enacted in 2008, the Illinois Biometric Information Privacy Act (“BIPA”) regulates the collection and possession of biometric data by private entities operating in Illinois. Biometric data includes, for example, fingerprints, voiceprints, eye scans, and face/hand scans. Notably, BIPA establishes a private right of action, allowing any person to seek damages, attorneys’ fees, and injunctive relief if the person has been aggrieved by a BIPA violation. The statutory damages for BIPA violations are steep, including $1,000 to $5,000 per violation, attorneys’ fees and costs, and the possibility of injunctive relief.
(more…)
Kathleen Carlson
Chicago
kathleen.carlson@sidley.com
Lawrence P. Fogel
Chicago
lawrence.fogel@sidley.com
Colleen Theresa Brown
Washington, D.C.
cbrown@sidley.com
Andrew F. Rodheim
Chicago
arodheim@sidley.com
FY2024 in Review: SEC Enforcement Actions Against Investment Advisers to Private Funds, Registered Funds, and Retail Clients
In its 2024 fiscal year, the U.S. Securities and Exchange Commission brought over 130 enforcement actions against investment advisers and their representatives. This post highlights the key areas of focus and notable actions and litigation from the past fiscal year.
Please click here to view the full Sidley Update.
W. Hardy Callcott
San Francisco
wcallcott@sidley.com
Stephen L. Cohen
Washington, D.C., Boston, ...
scohen@sidley.com
Chuck Daly
New York, Boston
cdaly@sidley.com
Ranah Esmaili
Washington, D.C.
resmaili@sidley.com
Lara Mehraban
New York
lmehraban@sidley.com
Ashley C. Pfeiffer
New York
apfeiffer@sidley.com
Sarah K. Gromet
New York
sgromet@sidley.com
Upcoming Events
Resources