Happy New Year. Here are a couple of interesting articles, courtesy of John Podvin: First, an article on the way securities firms and others are sharing and comparing their data security plans and processes, each attempting to learn best practices prevent themselves from being the next news story. Second, the definitive article on forming an incident response team in case you do suffer a data breach; it's tailored to companies subject to Gramm-Leach-Bliley, but the crossover applicability to HIPAA is damn near perfect. And, via Andrew Paur, a link to another law firm's article on new developments and trends in information security law (make sure you scroll to the end for an excellent listing of state and federal laws).

