Leech Tishman advises healthcare and life sciences clients nationwide on data privacy, cybersecurity, and information governance requirements affecting the creation, use, exchange, storage, and protection of health information. Working in coordination with the firm’s broader privacy and cybersecurity attorneys, our healthcare team counsels clients on the regulatory, operational, and enforcement issues that arise when patient data is used in clinical care, digital health, business operations, research, and emerging technologies.
Our attorneys advise hospitals, health systems, physician organizations, behavioral health providers, telehealth and digital health companies, clinical laboratories, life sciences companies, academic medical centers, and business associates, including revenue cycle management companies, software providers, and other service organizations. We counsel clients on compliance with federal and state privacy and security laws, including HIPAA, HITECH, 42 C.F.R. Part 2, the FTC Act, the Health Breach Notification Rule, state consumer and health privacy laws, cybersecurity frameworks, cross-border data transfer requirements, and emerging laws and guidance affecting artificial intelligence and machine learning systems.
Leech Tishman assists clients in developing, reviewing, and strengthening privacy and security programs that reflect the realities of healthcare operations. Our work includes HIPAA and Part 2 policies, risk analyses, mitigation plans, state privacy law assessments, workforce training, audit programs, data mapping, data minimization, lifecycle management, and information governance structures for organizations operating across multiple states. We also advise clients on AI governance frameworks and policies addressing the use of AI tools in healthcare environments.
Our attorneys regularly counsel clients on digital health, data sharing, and advanced analytics, including telehealth and virtual care platforms, health information exchanges, interoperability, the 21st Century Cures Act Information Blocking Rule, remote patient monitoring, AI-enabled clinical decision support, clinical research data, biospecimen governance, and de-identification and re-identification risk management. We also draft and negotiate data-related agreements, including business associate agreements, data use agreements, data licensing agreements, technology vendor contracts, cloud services agreements, and cross-border data transfer provisions.
Leech Tishman also assists clients in preparing for and responding to cybersecurity incidents across the healthcare ecosystem, including ransomware, vendor compromises, improper disclosures, insider threats, and cloud system vulnerabilities. Our attorneys support clients with incident response planning, tabletop exercises, forensic investigation oversight, HIPAA and state breach notification analyses, regulator communications, patient notifications, media disclosures, crisis management strategies, post-incident remediation, risk assessments, and compliance reporting.
When privacy, cybersecurity, or data governance matters give rise to regulatory scrutiny, our attorneys represent clients in investigations and enforcement actions involving the Office for Civil Rights, state attorneys general, the Federal Trade Commission, the U.S. Department of Health and Human Services, the Centers for Medicare and Medicaid Services, the Office of Inspector General, and other regulatory authorities. We also advise clients on Part 2 breaches, multi-state enforcement matters, FTC actions, and inquiries involving AI and other healthcare technologies.
Leech Tishman’s healthcare focus allows us to advise clients with a clear understanding of how privacy, security, and data governance requirements apply in clinical settings, digital health models, and provider-side business operations. Our attorneys help clients build and maintain programs that protect patient information, support compliant data use, and address the regulatory and operational risks that accompany healthcare innovation.
Services
- HIPAA and HITECH compliance
- 42 C.F.R. Part 2 compliance
- State consumer and health privacy law compliance
- Privacy and security policies and procedures
- Risk analyses, mitigation plans, and readiness assessments
- AI governance and model-risk management policies
- Workforce training and audit programs
- Data mapping, data minimization, and lifecycle management
- Business associate agreements and data use agreements
- Data licensing, technology vendor, and cloud services agreements
- Telehealth, digital health, and remote patient monitoring guidance
- Health information exchange, interoperability, and information blocking matters
- Clinical research data and biospecimen governance
- De-identification and re-identification risk management
- Cybersecurity incident response planning
- Ransomware and breach response
- HIPAA and state breach notification analysis
- OCR, FTC, HHS, CMS, OIG, and state attorney general investigations
- Post-incident remediation and compliance reporting
For more information about Leech Tishman’s Data Privacy & Cybersecurity industry, please click here.