Privacy and cybersecurity issues rarely arise in isolation, and neither does our advice. When matters involve health or patient data, our privacy and life sciences teams work closely together to ensure no issue is overlooked. 

Find an attorney

Adaptable, Practical Privacy Counsel for Life Sciences Companies

We advise life sciences and healthcare clients on evolving privacy and data protection laws, helping in-house teams get ahead of security risks and avoid costly compliance issues. When disputes arise, we represent clients in regulatory investigations, enforcement actions, and litigation involving privacy claims from consumers and employees. Our work spans a broad range of data-related matters, from healthcare information and MedTech to clinical research. 

Sector-Focused Privacy Counsel

Privacy, Security, and Regulatory Compliance

  • State, federal, and international privacy law compliance, including new consumer health privacy laws
  • HIPAA and HITECH Act compliance
  • Privacy and security advice on:  
    • Informed consent
    • De-scoping HIPAA
    • Automated decision-making, leveraging data sets for generative AI and training, and EU AI Act
    • Data breach and data transfer laws

Data Strategy, Governance, and Risk Management

  • Strategic and operational guidance on:
    • Data collection, storage, transfer, and analysis
    • Use of sensitive patient and health data
    • Data transfer and use rights across healthcare and research contexts
    • Al and digital health integrations (EMR feeds, APIs, mobile apps)
    • Compliant data-sharing arrangements and partnerships
  • Data governance for clinical trials and real-world research
  • Ongoing counseling on data security best practices

Regulatory Enforcement, Disputes, and Litigation

  • Government investigations and regulatory requests regarding the alleged compromise of confidential patient, customer and employee data
  • Data privacy and security disputes and litigation: Appearing in court and before government agencies.

Cybersecurity: Risk Management and Incident Response Strategy

  • Risk management to limit clients’ exposure to cybersecurity and privacy risks  
  • Development of
    • Data breach response plans
    • Incident response protocols
    • Employee training programs
  • Response management for data breaches, cyberattacks, and other privacy-related crises