OVERVIEW
What you need
Our attorneys have provided data privacy and security representation since the earliest days of the Internet and the adoption of HIPAA. We bring our depth of knowledge and experience to bear in designing policies and procedures to mitigate corporate risks relating to data and information privacy and security; analyzing and negotiating contractual obligations between companies exchanging PII, PHI, or confidential data; and enabling compliance with E.U. and cross-border data transfer regulations. We constantly monitor evolving regulatory schemes, best-practice standards, and technology models to ensure that our clients remain at the forefront of compliance.
HOW WE DELIVER
We assess a client's privacy and security practices using tools and processes the firm developed, determine which regimes apply to the business and to the categories of data it holds, whether contractual, EU, worldwide, PCI DSS, or HIPAA, and then write and implement the policies that follow. Training is part of the engagement, because a policy nobody has read does not reduce risk.
For AI, the same discipline applies to systems the organization often did not procure as AI: an inventory that reaches models embedded in vendor software, approval gates before deployment, impact assessments that close with a documented decision, and diligence on the vendor and the model behind it.
When a breach occurs, we assess its extent, institute immediate remedies, handle required notifications across every jurisdiction that applies, and manage post-breach remediation. Counsel directs that work from the first call so the record is protected.
We’ve got you covered

