Healthcare Privacy and Compliance

Overview

Healthcare providers, insurers and employer-sponsored health plan administrators, as well as the business associates with whom they do business, are particularly vulnerable to data security incidents because of the highly sensitive protected health information they maintain, including Social Security numbers, insurance information, payment records and confidential medical information. In addition, healthcare businesses must deal with the extensive state and federal regulations that are unique to the industry, including the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH).

Our diverse team has wide experience in counseling health systems, physician groups, insurers and employers across the country regarding risk assessments, developing comprehensive incident response plans, and responding in a timely and accurate manner to privacy and security incidents, from lost paper files and laptops to the largest cyber incident ever reported involving medical information. We aggressively defend our healthcare clients in investigations brought by the Office for Civil Rights (OCR) and state attorneys general following privacy and security incidents. We advise healthcare industry clients on HIPAA and state law compliance regarding privacy policies and procedures, release of medical information, and access to medical records issues.

We also advise healthcare clients on best practices for leveraging emerging technologies, managing data and structuring operations in compliance with relevant laws and regulations.

We are nationally recognized for our healthcare privacy litigation experience and have served as defense counsel in several of the largest data breaches in the healthcare industry. Our class action defense team has successfully represented major insurance businesses and health systems across the country, minimizing monetary and reputational damage and negotiating with state and federal regulators.

Representative Clients
  • Health systems.
  • Academic medical centers.
  • Healthcare providers.
  • Specialty treatment centers.
  • Long-term care facilities.
  • Schools, colleges and universities.
  • Health plans (self-funded and large insurers).
  • Healthcare technology providers.
  • Medical device manufacturers.

Select Experience

  • Led the incident response for approximately 50 percent of the largest healthcare data security incidents reported to date.
  • Successfully defended more than 500 investigations commenced by the Department of Health and Human Services Office for Civil Rights (OCR).
  • Negotiated more resolution agreements and corrective action plans with the OCR arising out of data security incidents than any other firm (more than 12 agreements negotiated and finalized).
  • Defended hundreds of investigations by attorneys general, including multi-state investigations, arising out of data security incidents.
More »

Professionals

Name Title Office Email
Partner Orlando
Associate New York
Associate Dallas
Counsel Atlanta
Counsel Atlanta
Associate Chicago
Partner Atlanta
Partner Los Angeles
Associate Atlanta
Associate Philadelphia
Associate Houston
Associate Atlanta
Partner Cincinnati
Partner Columbus
Staff Attorney Columbus
Partner Cleveland
Partner New York
Partner Los Angeles
Partner Atlanta
Counsel Seattle
Associate Chicago
Associate Los Angeles
Partner Cleveland
Partner Cleveland
Partner Philadelphia
Associate Atlanta
Partner Houston
Counsel Chicago
Associate Atlanta
Partner Houston
Partner Atlanta

Experience

  • Led the incident response for approximately 50 percent of the largest healthcare data security incidents reported to date.
  • Successfully defended more than 500 investigations commenced by the Department of Health and Human Services Office for Civil Rights (OCR).
  • Negotiated more resolution agreements and corrective action plans with the OCR arising out of data security incidents than any other firm (more than 12 agreements negotiated and finalized).
  • Defended hundreds of investigations by attorneys general, including multi-state investigations, arising out of data security incidents.
  • Negotiated numerous consent judgments and settlements with attorneys general, including some of the largest on record.
  • Defending a large public health system in a multi-state attorney general investigation. The matter arises out of a nation-state sponsored data security incident.
  • Advise health systems, physician groups, academic medical centers and long-term care facilities regarding all aspects of general privacy matters, including HIPAA compliance, the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and other state privacy laws. Our team provides guidance on the HIPAA Privacy and Security Program, state law requirements, breach analysis, regulatory reporting, policies and procedures, and general privacy advice, including best practices for safeguarding individuals’ protected health information and other personally identifiable information,
  • Because of our privacy and regulatory expertise, clients often look to us to conduct privacy assessments. We conduct gap analyses; review policies and procedures to assess HIPAA compliance, state law compliance, policy and procedure comprehensiveness; provide training and education on privacy matters, privacy awareness and readiness within the organization; and review processes in business agreements, breach notification protocols and investigation procedures, among other privacy issues.
  • We represent healthcare clients in connection with HIPAA audits conducted by federal regulators. Since 2016, we have helped several diverse healthcare entities prepare for audits across the privacy, security and breach notification rules under HIPAA in anticipation that they would be chosen for an audit. When the audits were sent later that year, we worked with selected entities to respond to the HIPAA audits and OCR findings. Because of this experience, in June 2018 we began working with large health system in the Midwest in preparation for an expected onsite OCR audit. Our work in this area represents our strong command of HIPAA laws, policies and procedures, a practical understand of healthcare operations, as well as our strong working relationship with the OCR, which allows us to guide the client’s response in such a way that it demonstrates compliance while advocating for a practical approach to HIPAA at healthcare organizations.
  • We advise medical device manufacturers on their obligations as business associates and data owners on general privacy matters, including HIPAA compliance, GDPR, CCPA and state privacy laws. Our team provides guidance on the HIPAA Privacy and Security Program, state law requirements, breach analysis, regulatory reporting, policies and procedures, and general privacy advice, including best practices for safeguarding individuals’ protected health and other personally identifiable information. A recent secondment of our attorneys at a device manufacturer presented the team with a real-time look into the complex and volume of privacy issues that these entities face, and we were able to successfully support the client through these issues.
  • As privacy and data protection issues have moved into the boardroom, we find our team of attorneys being requested to attend board meetings at healthcare organizations to explain the regulatory and risk environment and to provide real-time advice on responding to high-stakes cybersecurity incidents. These presentations range from tabletop exercises and breach workshops, risk assessment advice and compliance strategy to crisis management and strategy during a large data breach. Our clients include some of the United States’ largest and most well-respected healthcare providers and health insurers.

Recognition

  • Chambers Global: Privacy & Data Protection (USA) (2014 to 2019)
  • Chambers USA: Nationwide Privacy & Data Security (2013 to 2019)
    • Chambers USA Privacy and Data Security - Healthcare Spotlight Table (2018 to 2019)
    • Chambers USA Award: “Privacy & Data Security Team of the Year” finalist (2015, 2017)
  • Chambers Fintech: Legal – USA (2018 to 2019)
  • The Legal 500 United States (2016 to 2019)
    • Media, Technology and Telecoms: Data Privacy and Data Protection, Tier 1
    • Media, Technology and Telecoms: Cyber Law, Tier 2
  • Law360: Privacy "Practice Group of the Year" (2013 to 2015, 2018)
  • Recognized as one of the top law firms for client service, BakerHostetler was named to the 2020 BTI Client Service 30 for the sixth consecutive year.

News

News

Press Releases

Key Contacts

Blog

In The Blogs

Previous Next
Data Counsel
Welcome to Data Counsel
By Theodore J. Kobus III
June 14, 2020
Dear Friends, In January, we announced the creation of the firm’s 6th practice group—Digital Assets and Data Management. Since September 2010, members of our group have been covering privacy and security topics through our Data Privacy...
Read More ->
Data Counsel
DSIR Deeper Dive: Regulatory Investigation Landscape
By Kimberly C. Gordy, Patrick H. Haggerty, Lynn Sessions
May 26, 2020
HIPAA-covered entity and business associate breaches continue to draw attention from the Office for Civil Rights (OCR) and other regulators. In almost every HIPAA incident we handled in 2019 involving more than 500 individuals, OCR issued...
Read More ->
Data Counsel
Sixth Annual Data Security Incident Response Report Released – Managing Enterprise Risks and Leveraging Data in a Digital World
By Theodore J. Kobus III
April 30, 2020
We are excited to present our sixth Data Security Incident Response Report (DSIR). We hope this issue finds you safe and healthy while working from home (WFH). Each year, we talk about last year’s trends and where we think the current year...
Read More ->
Data Counsel
Due to the COVID-19 Pandemic, HHS Eases Restrictions on the Use and Disclosure of PHI by Business Associates
By Eric A. Packel
April 3, 2020
The COVID-19 public health emergency already has caused the U.S. Health and Human Services (HHS) Office for Civil Rights to announce various enforcement changes and waivers. On April 2, HHS issued another notification of enforcement...
Read More ->
Data Counsel
CARES Act Significantly Revises Part 2 Rules to Better Align with HIPAA
By Vimala Devassy, Kyle R. Gregory
April 2, 2020
On March 27, 2020, President Trump signed the Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) into law. While the focus of the CARES Act has been on direct financial aid to Americans, the Act also contains a number of...
Read More ->