Cases
Representative Work: Spearheaded health system's responses to over 35 different privacy-related inquiries
investigations from U.S. federal
state regulators seeking to enforce patient privacy
data privacy laws
these included lengthy
high-profile investigations with the potential for enforcement action.
Supervised the investigation, analysis, documentation, remediation,
, where appropriate, patient
regulatory notification in over 200 potential privacy incidents across a major U.S. health system.
Counseled start-up companies, hospitals, health systems, universities, a medical research institute, social service organizations,
medical technology companies on a wide range of U.S.
Canadian privacy
information security laws, institutional policies,
best practices.
Advised medical technology company on privacy incident management, privacy considerations with respect to smart devices that collect, use,
transmit health information,
privacy obligations under U.S. federal
applicable state laws.
Counseled post-acute care system on potential privacy incidents, including analysis under several applicable U.S. federal
state laws, remediation,
h
ling of regulatory investigation.
Spent several months on secondment to privacy office of a leading U.S. research university, where duties included advising on privacy incident investigation
h
ling, reviewing
formulating policies on privacy in clinical care
research contexts,
supporting privacy team generally.
Advised pharmaceutical companies on potential privacy issues arising out of multi-site, multinational research projects.
Counseled investment management companies
other institutional clients on privacy-
security-related diligence
disclosures in context of corporate transactions.
Advised large insurer on potential privacy questions involved in proposed genetic testing initiative.
Successfully represented large professional organization in complex complaint brought against it before Ontario Information
Privacy Commissioner.