Foley Hoag’s attorneys can help you understand and maneuver through issues and manage risks inherent in the maintenance, protection, use and disclosure of sensitive data. We are dedicated to keeping you a step ahead, using practical experience to guide your business through every facet of the privacy and data security challenges it may face. Members of our Privacy & Data Security team are widely sought-after for their expertise and experience, and have spoken at numerous programs and provided insights to media outlets including Bloomberg, The Washington Post, The Wall Street Journal, Politico and Law360.
Our Privacy & Data Security practice group provides a comprehensive suite of services that address the myriad legal and policy challenges:
Complying with state, federal and international laws – including the CCPA, CPRA, SHIELD and GDPR – that govern information security, identity theft and surveillance
Complying with HIPAA, and the FTCs and GLBA privacy and security requirements
Assisting with state and federal investigations (including by the FTC, SEC and OCR)
Developing privacy and information security policies
Negotiating third-party data security agreements
Investigating, litigating and resolving security incidents, including competitive espionage and proprietary data leaks
Counseling on corporate governance
Advising clients on safeguarding company records, financial information and other valuable information assets
Providing data privacy specific due diligence in mergers and acquisitions
Areas of Focus
Our Privacy & Data Security practice provides a comprehensive suite of services that address myriad legal and policy challenges:
Privacy and information security policies
Third-party data security agreements
Security incidents including competitive espionage and proprietary data leaks
Corporate governance
Company records, financial information and other information assets
Data privacy-specific due diligence in mergers and acquisitions
Security and privacy issues encountered by businesses often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.
Foley Hoag’s Cybersecurity Incident Response Team includes lawyers from a number of the firm’s practice areas with deep knowledge in the different substantive areas of law that cybersecurity issues can affect, such as finance and banking, securities, health care, and intellectual property.
Conducted a state-by-state survey on behalf of a software company, detailing existing consumer privacy laws or laws limiting the use of AI in businesses. Advised the company on issues relating to privacy, employment and other concerns based on requirements by state.
Provided an in-depth analysis of new comprehensive state data protection laws on behalf of a health insurance company, comparing them to HIPAA and the GDPR in terms of scope, definitions, and compliance requirements related to the use of AI
Assisted multiple companies in the tech, start-up, life sciences and health insurance spaces, among others, with assessing and structuring data privacy compliance protocols, including drafting privacy policies and reviewing third-party contracts.Compliance work involves both U.S. privacy laws and the European Union’s GDPR.
Assisted technology and telecommunications company in crafting government-mandated security policy to protect against unique security threats.
Data Breach Investigation and Response
Represented start-up tech company with data breach response arising from third-party vendor security breach affecting individuals in multiple states and in EU countries.
Represented social media company with a data breach response affecting individuals globally.
Represented health care provider in response to ransomware attack.
Represented vendor (and HIPAA business associate) to health care providers in responding to data security incident.
Litigation and Government Investigations
Defended mid-stage technology company, large manufacturing company and large investment company from breach of contract claims arising from respective “man in the middle” attacks that resulted, in each case, in the fraudulent diversion of millions of dollars.
Represented life sciences company with data breach response that affected hundreds of thousands of individuals nationwide and implicated HIPAA, requiring law enforcement engagement, response notification, and responses to requests from government agencies.
Events
We use cookies to enhance user experience, improve functionality and performance, and for analysis of website traffic. By clicking “accept”, you agree to the use of cookies. For more information about our cookie policy and the information we collect, please review our Privacy Statement.
Foley Hoag
Email Disclaimer
Transmitting information to us by e-mail unilaterally does not establish an attorney-client relationship or impose an obligation on either the law firm or even the receiving lawyer to keep the transmitted information confidential. By clicking "OK," you acknowledge that we have no obligation to maintain the confidentiality of any information you submit to us unless we already represent you or unless we have agreed to receive limited confidential material/information from you as a prospective client. Thus, if you are not a client or someone we have agreed to consider as a prospective client, information you submit to us by e-mail may be disclosed to others or used against you.
If you would like to discuss becoming a client, please contact one of our attorneys to arrange for a meeting or telephone conference. If you wish to disclose confidential information to a lawyer in the firm before an attorney-client relationship is established, the protections that the law firm will provide to such information from a prospective client should be discussed before such information is submitted. Thank you for your interest in Foley Hoag.