top of page
logo-reverse.png
GET IN TOUCH

OVERVIEW

What you need

Our attorneys have provided data privacy and security representation since the earliest days of the Internet and the adoption of HIPAA. We bring our depth of knowledge and experience to bear in designing policies and procedures to mitigate corporate risks relating to data and information privacy and security; analyzing and negotiating contractual obligations between companies exchanging PII, PHI, or confidential data; and enabling compliance with E.U. and cross-border data transfer regulations. We constantly monitor evolving regulatory schemes, best-practice standards, and technology models to ensure that our clients remain at the forefront of compliance.

HOW WE DELIVER

We assess a client's privacy and security practices using tools and processes the firm developed, determine which regimes apply to the business and to the categories of data it holds, whether contractual, EU, worldwide, PCI DSS, or HIPAA, and then write and implement the policies that follow. Training is part of the engagement, because a policy nobody has read does not reduce risk.

For AI, the same discipline applies to systems the organization often did not procure as AI: an inventory that reaches models embedded in vendor software, approval gates before deployment, impact assessments that close with a documented decision, and diligence on the vendor and the model behind it.

When a breach occurs, we assess its extent, institute immediate remedies, handle required notifications across every jurisdiction that applies, and manage post-breach remediation. Counsel directs that work from the first call so the record is protected.

We’ve got you covered

AI Governance Advisory

Product Counsel

Technology Consulting

Breach Response

Cross-Border Transfer

Compliance Programs

REPRESENTATIVE MATTERS

AI governance program design and policy

Privacy program design and governance

Security and incident response

AI system and model inventories, including vendor-embedded AI

US state comprehensive privacy laws

Information security policies and workforce training

Deployment review and approval gates

EU and UK GDPR compliance

Vendor security diligence and contractual security terms

AI impact and risk assessments

Standard contractual clauses and transfer assessments

Incident response plans and tabletop exercises

Automated decision-making and profiling analysis

Latin American regimes, including LGPD

Breach analysis and scoping

EU AI Act readiness and risk classification

Data protection impact assessments

Breach notification across every applicable jurisdiction

US state AI statutes and federal government requirements

HIPAA compliance and business associate agreements

Ransomware and extortion counsel, including sanctions screening

NIST AI RMF and ISO/IEC 42001 alignment

State health privacy laws beyond HIPAA

Regulator investigations and state attorney general inquiries

Training data, licensing, and output ownership

Biometric and sensitive data, including BIPA

SEC cyber disclosure and materiality analysis

Vendor and model diligence

Children and teen privacy, including COPPA

PCI DSS compliance

Board and committee reporting

Consumer rights request processes

Cyber insurance coverage review

AI-specific incident and misuse response

Adtech, pixels, and session replay exposure

Post-incident remediation

bottom of page