When sensitive health data is central to your business, the legal challenge lies in complying with privacy laws across multiple jurisdictions. Our privacy lawyers have guided in-house teams through exactly these questions, where the use of personal data, AI, and MedTech intersects with a patchwork of regulations.

Find an attorney

Key Contacts

Our Life Sciences AI, Data Privacy, and MedTech Attorneys

Adaptable, Practical Privacy Counsel for Life Sciences Companies

Our privacy lawyers advise life sciences and healthcare clients on evolving privacy and data protection laws. We help in-house teams take proactive steps to mitigate security risks and avoid costly compliance pitfalls. We also represent clients in regulatory investigations and enforcement actions, as well as in litigation involving privacy claims brought by consumers and employees. Our work spans a broad range of data-related matters, including those involving healthcare information, MedTech, and clinical research.

Privacy, Security, and Regulatory Compliance

  • State, federal, and international privacy law compliance, including new consumer health privacy laws
  • HIPAA and HITECH Act compliance
  • Privacy and security advice on: 
    • Informed consent
    • De-scoping HIPAA
    • Automated decision-making, leveraging data sets for generative AI and training, and EU AI Act
    • Data breach and data transfer laws

Data Strategy, Governance, and Risk Management

  • Strategic and operational guidance on:
    • Data collection, storage, transfer, and analysis
    • Use of sensitive patient and health data
    • Data transfer and use rights across healthcare and research contexts
    • Al and digital health integrations (EMR feeds, APIs, mobile apps)
  • Data governance for clinical trials and real-world research
  • Ongoing counseling on data security best practices

Commercial Transactions and Contracting Support 

  • Vendor and partner diligence for data integrations
  • Transactional data contracting and diligence: 
    • Data use limitations
    • Information protection provisions
    • M&A diligence reviews involving data assets
  • Compliant data-sharing arrangements and partnerships

Regulatory Enforcement, Disputes, and Litigation

  • Government investigations and regulatory requests regarding the alleged compromise of confidential patient, customer and employee data
  • Data privacy and security disputes and litigation: Appearing in court and before government agencies.

Cybersecurity: Risk Management and Incident Response Strategy

  • Risk management to limit clients’ exposure to cybersecurity and privacy risks 
  • Development of
    • Data breach response plans
    • Incident response protocols
    • Employee training programs
  • Response management for data breaches, cyberattacks, and other privacy-related crises