{"id":4501,"date":"2023-02-20T08:58:42","date_gmt":"2023-02-20T13:58:42","guid":{"rendered":"https:\/\/lg-staging.lougcloud.com\/?p=4501"},"modified":"2026-07-14T22:16:29","modified_gmt":"2026-07-15T03:16:29","slug":"technology-compliance-and-regulatory-changes-coming-in-2023","status":"publish","type":"post","link":"https:\/\/lg-staging.lougcloud.com\/?p=4501","title":{"rendered":"Technology Compliance and Regulatory Changes coming in 2023"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-85bp3-f856194ef33e7bc72ec0d3bf98278fce\">\n.flex_column.av-85bp3-f856194ef33e7bc72ec0d3bf98278fce{\nborder-radius:0px 0px 0px 0px;\npadding:0px 0px 0px 0px;\n}\n<\/style>\n<div  class='flex_column av-85bp3-f856194ef33e7bc72ec0d3bf98278fce av_one_full  avia-builder-el-0  avia-builder-el-no-sibling  first flex_column_div av-zero-column-padding  '     ><p><br \/>\n<section  class='av_textblock_section av-k0pon615-893cfe61b16f1cf5ecc4ac5b8f5d4aed '  ><div class='avia_textblock' ><h1 style=\"page-break-after: avoid;\">Technology Compliance And Regulatory Changes coming in 2023<\/h1>\n<\/div><\/section><br \/>\n<section  class='av_textblock_section av-k0pop9td-399c35357da9cf26107da9a57de824c5 '  ><div class='avia_textblock' ><p>As if managing daily information technology (IT) operations, cybersecurity responsibilities and software and hardware lifecycles aren&#8217;t enough, organizations and technology professionals must also accommodate new government regulations and industry compliance requirements changes taking effect or likely to require adjustments in 2023. From new security compliance requirements for US Department of Defense (DoD) contractors to data privacy requirements becoming more restrictive in multiple states, there&#8217;s much to track.<\/p>\n<h2>Cybersecurity Maturity Model Certification 2.0<\/h2>\n<p>New Cybersecurity Maturity Model Certification (CMMC) requirements take effect this year that impact contractors and subcontractors working for the DoD and the Defense Industrial Base (DIB). Commonly referred to as CMMC 2.0, the updated program requirements are designed to protect the DoD, companies that service the defense industry and US military technologies and information.<\/p>\n<p><a href=\"https:\/\/lg-staging.lougcloud.com\/news\/\">As we noted in late 2022<\/a>, numerous new cybersecurity standards will be required of DoD contractors and subcontractors as soon as the corresponding rule making process completes and the new rules are in place, likely by May. Contractors and their subs could begin seeing the new cybersecurity requirements appearing in new contracts in just a few months.<\/p>\n<p>With CMCC 2.0, five cybersecurity compliance levels are being consolidated within three tiers. The Level 1 Foundational tier requires compliance with 17 fundamental cybersecurity practices and an annual self-assessment, whereas the Level 2 Advanced tier adds the requirement contractors and subs comply with some 110 <a href=\"https:\/\/www.nist.gov\/cybersecurity\">National Institute of Standards and Technology (NIST)<\/a>-aligned cybersecurity practices and obtain third-party assessment certification every three years. The Level 3 Expert tier also requires compliance with more than 110 NISP-aligned cybersecurity practices, targets highest priority initiatives, while requiring the entity to obtain government-led assessment certification every three years.<\/p>\n<p>For more information on CMMC 2.0\u2019s specific practices and requirements, visit <a href=\"https:\/\/dodcio.defense.gov\/CMMC\/Model\/\">the DoD website<\/a>.<\/p>\n<h2>Cybersecurity Risk Management Disclosure For Public Companies<\/h2>\n<p>A number of initiatives\u2014including <a href=\"https:\/\/www.federalregister.gov\/documents\/2022\/03\/23\/2022-05480\/cybersecurity-risk-management-strategy-governance-and-incident-disclosure\">a Securities and Exchange Commission (SEC) proposal<\/a>\u2014are moving to require companies to disclose, within specific and aggressive (potentially 72-hour) time periods, whenever they experience a ransomware attack. These requirements follow passage and signing into law of <a href=\"https:\/\/www.congress.gov\/bill\/117th-congress\/house-bill\/2471\/text\">the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)<\/a>. The new law requires <a href=\"https:\/\/www.cisa.gov\/circia\">the Cybersecurity and Infrastructure Security Agency (CISA)<\/a> &#8220;to develop and implement regulations requiring covered entities to report covered cyber incidents and ransomware payments to CISA.&#8221;<\/p>\n<p>Vendors are already working to prepare clients for corresponding cyber incident-reporting responsibilities. For example, <a href=\"https:\/\/unit42.paloaltonetworks.com\">Palo Alto Network&#8217;s Unit 42 cyber-security research lab<\/a> partnered with <a href=\"https:\/\/www.hardenstance.com\">HardenStance analysts<\/a> to produce their <a href=\"https:\/\/start.paloaltonetworks.com\/hardenstance-preparing-for-new-incident-reporting-requirements\">Practical Steps for CISOs to Make Cybersecurity Reporting Frictionless white paper<\/a>.<\/p>\n<p>For more information on the corresponding legislation, read the <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/Cyber-Incident-Reporting-ForCriticalInfrastructure-Act-o-f2022_508.pdf\">Cyber Incident Reporting for Critical Infrastructure Act of 2022<\/a>. Alternatively, you can review the corresponding <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CIRCIA_07.21.2022_Factsheet_FINAL_508%20c.pdf\">Fact Sheet<\/a>.<\/p>\n<h2>Small Business Credit Data Collection And Reporting<\/h2>\n<p>March 31st marks the deadline for the Consumer Financial Protection Bureau (CFPB) to issue final rules for lending institutions regarding small business data collection and reporting. The financial application information is to be collected from credit applications submitted by small businesses, including those that are women- or minority-owned, in efforts to assist fair lending.<\/p>\n<p>For more information on the small business lenders data collection rule and data collection requirements spawning from Section 1071 of the Dodd-Frank Act, check out the CFPB update or review the specific proposed rule changes.<\/p>\n<h2>Consumer Financial Data Accessibility<\/h2>\n<p>Lenders should also prepare for changes to way the CFPB will soon likely require them to respond to consumer requests for access to their own financial information, including payment and transaction histories. Authorized under <a href=\"https:\/\/www.federalregister.gov\/documents\/2020\/11\/06\/2020-23723\/consumer-access-to-financial-records\">Section 1033 of the Dodd-Frank Act<\/a>, the changes have been in the works for years. In late October 2022, the CFPB announced details of data rights rules to be implemented in a <a href=\"https:\/\/files.consumerfinance.gov\/f\/documents\/cfpb_data-rights-rulemaking-1033-SBREFA_outline_2022-10.pdf\">comprehensive outline<\/a>.<\/p>\n<p>Businesses tracking the changes can find more information on <a href=\"https:\/\/www.consumerfinance.gov\/\">the CFPB website<\/a>. Among the documents that could prove helpful are the <a href=\"https:\/\/files.consumerfinance.gov\/f\/documents\/cfpb_data-rights-rulemaking-1033-SBREFA-high-level-summary-discussion-guide_2022-10.pdf\">CFPB&#8217;s High-Level Summary<\/a> and <a href=\"https:\/\/www.consumerfinance.gov\/about-us\/newsroom\/cfpb-kicks-off-personal-financial-data-rights-rulemaking\/\">the bureau&#8217;s corresponding news release<\/a>.<\/p>\n<h2>Privacy Regulation Changes In Multiple States<\/h2>\n<p>Data privacy laws are tightening in multiple states in 2023, too. Organizations and their supporting technology departments must ensure compliance with the new requirements in an ever-increasing number of locations.<\/p>\n<p>Of particular importance is the fact 2023 marks the year in which US data privacy laws seemingly begin converting from a harm-prevention approach, as has essentially been the practice, to more expansive rights-based enforcement, as has been the European model. For example, <a href=\"https:\/\/coag.gov\/resources\/colorado-privacy-act\/\">Colorado<\/a>, <a href=\"https:\/\/portal.ct.gov\/AG\/Sections\/Privacy\/The-Connecticut-Data-Privacy-Act\">Connecticut<\/a>, <a href=\"https:\/\/le.utah.gov\/~2022\/bills\/static\/SB0227.html\">Utah<\/a> and <a href=\"https:\/\/law.lis.virginia.gov\/vacode\/title59.1\/chapter53\/section59.1-578\/\">Virginia<\/a> begin requiring more stringent consumer data privacy standards requiring shifts in data collection strategies.<\/p>\n<p>As of January 1, 2023, businesses must also comply with California Privacy Rights Act (CCPA) amendment provisions. The <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/codes_displayText.xhtml?division=3.&amp;part=4.&amp;lawCode=CIV&amp;title=1.81.5\">regulations<\/a> define changes to the specific responsibilities businesses must follow managing consumers&#8217; personal information. Provisions include honoring a consumer&#8217;s request to delete personal information a business has collected and correcting inaccurate personal information, when requested.<\/p>\n<p>Expect more states to follow suit. In the interim, you can tap a resource, such as <a href=\"https:\/\/www.auditboard.com\/blog\/updates-to-us-state-data-privacy-laws\/\">the AuditBoard<\/a>, for help tracking the status of new data privacy requirements.<\/p>\n<h2>HIPAA Changes<\/h2>\n<p><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html\">HIPAA privacy rules<\/a> are also expected to change in March 2023. New section 164.524(d) more clearly defines patients&#8217; rights and access routines for their personal health information (PHI), including a patient&#8217;s ability to direct electronic medical records (EMR) to third parties. Changes also address practitioners&#8217; charging reasonable fees for the corresponding work producing the corresponding records.<\/p>\n<p>Under new HIPAA rules, health care providers must provide a patient&#8217;s PHI within 15 days, too, when requested, whereas previous requirements provided health care practitioners 30 days. Patients also receive greater access to their PHI, including in-person rights and the option to take notes or photographs.<\/p>\n<h2>Keeping Current<\/h2>\n<p>Need help keeping current with compliance requirement changes? You&#8217;re not alone.<\/p>\n<p>Numerous businesses are likely to be impacted by legislation affecting <a href=\"https:\/\/www.cnbc.com\/2022\/12\/29\/new-salary-transparency-laws-going-into-effect-in-2023.html\">pay transparency<\/a>, <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2023\/01\/ftc-proposes-rule-ban-noncompete-clauses-which-hurt-workers-harm-competition\">noncompete agreements<\/a>, <a href=\"https:\/\/www.americanprogress.org\/article\/the-state-of-paid-family-and-medical-leave-in-the-u-s-in-2023\/\">family leave<\/a>, <a href=\"https:\/\/www.federalregister.gov\/documents\/2022\/10\/13\/2022-21454\/employee-or-independent-contractor-classification-under-the-fair-labor-standards-act\">independent contractor status<\/a> and similar topics as new laws and regulations take hold. Unfortunately, there&#8217;s no one source to follow for definitive updates.<\/p>\n<p>Organizations can, however, entrust HR departments to track changing labor and employment laws in states in which they operate. Firms can also track industry changes using trusted authorities and trade publications. As for federal legislation that could impact businesses, companies can monitor <a href=\"https:\/\/www.congress.gov\/\">Congress.gov<\/a>, <a href=\"https:\/\/www.brookings.edu\/interactives\/tracking-regulatory-changes-in-the-biden-era\/\">Brookings<\/a> and <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/legislation\/\">The White House&#8217;s Legislation website<\/a>.<\/p>\n<\/div><\/section><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":2,"featured_media":4529,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-4501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-geek-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Technology Compliance &amp; Regulatory Changes in 2023<\/title>\n<meta name=\"description\" content=\"Organizations and tech professionals should be aware of new government regulations and industry compliance requirements rolling out this year.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Technology Compliance &amp; Regulatory Changes in 2023\" \/>\n<meta property=\"og:description\" content=\"Organizations and tech professionals should be aware of new government regulations and industry compliance requirements rolling out this year.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lg-staging.lougcloud.com\/?p=4501\" \/>\n<meta property=\"og:site_name\" content=\"Louisville Geek\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-20T13:58:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-15T03:16:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2500\" \/>\n\t<meta property=\"og:image:height\" content=\"1700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"LouGeek Marketing\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"LouGeek Marketing\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Technology Compliance & Regulatory Changes in 2023","description":"Organizations and tech professionals should be aware of new government regulations and industry compliance requirements rolling out this year.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Technology Compliance & Regulatory Changes in 2023","og_description":"Organizations and tech professionals should be aware of new government regulations and industry compliance requirements rolling out this year.","og_url":"https:\/\/lg-staging.lougcloud.com\/?p=4501","og_site_name":"Louisville Geek","article_published_time":"2023-02-20T13:58:42+00:00","article_modified_time":"2026-07-15T03:16:29+00:00","og_image":[{"width":2500,"height":1700,"url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg","type":"image\/jpeg"}],"author":"LouGeek Marketing","twitter_card":"summary_large_image","twitter_misc":{"Written by":"LouGeek Marketing","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#article","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501"},"author":{"name":"LouGeek Marketing","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a"},"headline":"Technology Compliance and Regulatory Changes coming in 2023","datePublished":"2023-02-20T13:58:42+00:00","dateModified":"2026-07-15T03:16:29+00:00","mainEntityOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501"},"wordCount":1294,"publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg","articleSection":["Geek News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501","url":"https:\/\/lg-staging.lougcloud.com\/?p=4501","name":"Technology Compliance & Regulatory Changes in 2023","isPartOf":{"@id":"https:\/\/lg-staging.lougcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#primaryimage"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#primaryimage"},"thumbnailUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg","datePublished":"2023-02-20T13:58:42+00:00","dateModified":"2026-07-15T03:16:29+00:00","description":"Organizations and tech professionals should be aware of new government regulations and industry compliance requirements rolling out this year.","breadcrumb":{"@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lg-staging.lougcloud.com\/?p=4501"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#primaryimage","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2023\/02\/Shutterstock_1812646699.jpg","width":2500,"height":1700},{"@type":"BreadcrumbList","@id":"https:\/\/lg-staging.lougcloud.com\/?p=4501#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/lg-staging.lougcloud.com\/"},{"@type":"ListItem","position":2,"name":"Technology Compliance and Regulatory Changes coming in 2023"}]},{"@type":"WebSite","@id":"https:\/\/lg-staging.lougcloud.com\/#website","url":"https:\/\/lg-staging.lougcloud.com\/","name":"Louisville Geek","description":"Empowering Local Businesses and National Enterprises with Comprehensive IT Services","publisher":{"@id":"https:\/\/lg-staging.lougcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lg-staging.lougcloud.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lg-staging.lougcloud.com\/#organization","name":"Louisville Geek","url":"https:\/\/lg-staging.lougcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","contentUrl":"https:\/\/lg-staging.lougcloud.com\/wp-content\/uploads\/2019\/10\/lougeek_full_logo-black-1.png","width":1671,"height":506,"caption":"Louisville Geek"},"image":{"@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lg-staging.lougcloud.com\/#\/schema\/person\/a381cd0bd66b806f0da449297a82ce8a","name":"LouGeek Marketing","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/865f8a8b853c689f8443338c8f8d08b8e9a9f0bcab6dcd97b1cb63a5efeda3fa?s=96&d=mm&r=g","caption":"LouGeek Marketing"},"url":"https:\/\/lg-staging.lougcloud.com\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4501"}],"version-history":[{"count":3,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4501\/revisions"}],"predecessor-version":[{"id":10478,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/posts\/4501\/revisions\/10478"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=\/wp\/v2\/media\/4529"}],"wp:attachment":[{"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lg-staging.lougcloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}