Skip to Main Content

A member of the Digital Assets and Data Management Group, Ashley Marcus brings her experience in data privacy matters to the Healthcare Privacy and Compliance team.

Ashley advises clients on a broad range of healthcare privacy, cybersecurity, data governance and emerging technology matters. Her practice focuses on helping healthcare organizations and other entities navigate complex regulatory requirements, assess innovative uses of data and technology, and develop practical compliance strategies.

Ashley counsels clients on HIPAA compliance, healthcare data use and disclosure issues, and enterprise data governance programs, including data classification, lifecycle management and controls designed to address evolving privacy and security obligations. She also advises organizations on issues related to artificial intelligence, including the development of governance frameworks, policies and risk management practices aligned with emerging regulatory expectations and industry standards.

In her cybersecurity practice, Ashley provides incident response counsel to organizations experiencing data security incidents, coordinating with forensic and notification vendors, assessing breach notification obligations, and drafting notifications to affected individuals and regulators. She regularly assists clients in responding to inquiries and investigations from federal agencies, including the U.S. Department of Health and Human Services Office for Civil Rights.

Ashley also works proactively with clients to strengthen cybersecurity and compliance programs, designing and leading customized incident response tabletop exercises and workshops focused on privacy, security and emerging technology risks.


Areas of Focus

Featured Insights