21st Century Cures Act
The 21st Century Cures Act is a 2016 US law whose ONC Final Rule (2020) prohibits 'information blocking' — practices that interfere with the access, exchange, or use of electronic health informatio...
The 21st Century Cures Act is a 2016 US law whose ONC Final Rule (2020) prohibits 'information blocking' — practices that interfere with the access, exchange, or use of electronic health informatio...
APRA is Australia's prudential regulator for banks, insurers and superannuation funds, operating through binding Prudential Standards — notably CPS 234 on information security and CPS 230 on operat...
The Privacy Act 1988 is Australia's principal data-protection law, setting the Australian Privacy Principles that govern how personal information is collected, used, and disclosed. It is the privac...
The Telecommunications Act 1997 is the framework for Australian telecommunications regulation, administered by the Australian Communications and Media Authority alongside the Radiocommunications Ac...
The Consumer Financial Protection Bureau's Personal Financial Data Rights Rule, finalized in 2024 under Dodd-Frank Section 1033, requires covered financial institutions to make consumer financial d...
The UK Competition and Markets Authority's Retail Banking Market Investigation Order 2017 is the competition remedy that created UK Open Banking. It required the nine largest UK banks (the CMA9) to...
The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), finalized in 2024, requires impacted US payers — Medicare Advantage, Medicaid, CHIP, and ACA exchange plans — to build FHIR...
Australia's Consumer Data Right (CDR) is an economy-wide data-portability law that gives consumers the right to share their data with accredited third parties, beginning with banking (open banking)...
Canada's Consumer-Driven Banking framework is the federal open-banking regime legislated in the 2024 budget and fall economic statement, with the Financial Consumer Agency of Canada named as overse...
Section 1033 of the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act gives US consumers a statutory right to access their financial data in a usable electronic form. It is the legal a...
The Digital Technology Assessment Criteria (DTAC) is the NHS's national baseline that digital health technologies are assessed against before being adopted across the health and care system. Introd...
eIDAS is the EU regulation governing electronic identification and trust services — including the qualified website (QWAC) and seal (QSEAL) certificates that identify regulated third parties in ope...
The ePrivacy Directive governs privacy in electronic communications across the European Union, regulating the confidentiality of communications, traffic data, and — most relevantly for network APIs...
The EU Medical Device Regulation (Regulation (EU) 2017/745, MDR) governs the safety and performance of medical devices placed on the European market, and — critically for digital health — brings mu...
The United Kingdom regulates insurance through two bodies: the Financial Conduct Authority for market conduct and the Prudential Regulation Authority, part of the Bank of England, for prudential so...
The Fair Credit Reporting Act is the US law governing the collection, use, and sharing of consumer credit information, giving consumers rights to access and dispute their data held by credit report...
The General Data Protection Regulation is the EU's comprehensive data-protection law (retained in the UK as the UK GDPR), governing how personal data is processed, consented to, and ported. It is t...
The Gramm-Leach-Bliley Act is the 1999 US law governing how financial institutions handle and protect consumers' nonpublic personal information, including the Privacy Rule and the Safeguards Rule. ...
HIPAA is the 1996 US law that governs the privacy and security of protected health information (PHI). Its Privacy Rule sets the terms under which PHI may be used and disclosed and grants patients a...
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009 as part of the American Recovery and Reinvestment Act, funded the nationwide adoption of electronic ...
The International Telecommunication Union is the United Nations agency for information and communication technologies, and its Constitution, Convention and Radio Regulations form the treaty framewo...
The McCarran-Ferguson Act is the 1945 US statute that delegated the regulation of insurance to the states and exempted the business of insurance from most federal law where a state already regulate...
The NAIC is the standard-setting and coordinating body of the United States' fifty state insurance regulators. It writes model laws and regulations that states may adopt, accredits state department...
The NHS Data Security and Protection Toolkit (DSPT) is an annual online self-assessment that organizations must complete to demonstrate they meet the National Data Guardian's data security standard...
The ONC Health IT Certification Program is the US voluntary-but-effectively-mandatory program under which health IT is certified against federal criteria. Its Cures Act Final Rule 'Standardized API...
OSFI is Canada's federal prudential regulator for banks and insurers, and Guideline B-13 sets its expectations for technology and cyber risk management, alongside Guideline B-10 on third-party risk...
The Personal Health Information Protection Act (PHIPA) is Ontario's health-sector privacy law, in force since 2004 and overseen by the Information and Privacy Commissioner of Ontario. It governs ho...
PIPEDA is Canada's federal private-sector privacy law, governing how organizations collect, use, and disclose personal information in the course of commercial activity. It is the privacy backdrop a...
PSD2 is the European Union directive that opened bank payment accounts to licensed third parties, mandating that banks provide access to accounts (XS2A) for account-information and payment-initiati...
PSD3 (the third Payment Services Directive) and the accompanying Payment Services Regulation (PSR) are the European Union's proposed successors to PSD2, intended to fix its uneven execution — tight...
Quebec's Law 25 is the province's modernization of personal-information protection, introducing consent requirements, breach notification, privacy-by-default, automated-decision transparency and a ...
The Retail Payment Activities Act is Canada's federal law bringing payment service providers under supervision by the Bank of Canada, requiring registration and operational-risk and safeguarding st...
Strong Customer Authentication (SCA) is the security requirement mandated by PSD2's Regulatory Technical Standards, requiring multi-factor authentication (two of knowledge, possession, and inherenc...
TEFCA is a US framework, established under the 21st Century Cures Act and operationalized by the ONC with a Recognized Coordinating Entity, that creates a nationwide floor for health information ex...
The Communications Act 2003 established Ofcom as the United Kingdom's converged regulator for telecommunications, broadcasting and spectrum. It governs licensing, competition, universal service and...
The Communications Act of 1934, as amended by the Telecommunications Act of 1996, is the statutory basis for US telecommunications regulation and the Federal Communications Commission's authority. ...