For Businesses
Business insights
Guidance for companies on data privacy, AI governance, contracts, and consumer-law compliance.

California Changed the Rules on Protected Health Information. Here Is What It Means for You.
If your medical information was caught up in a data breach, California courts used to ask a question that was almost impossible to answer: can you prove a hacker actually looked at your records? For most people, the answer was no, and their cases were dismissed before they ever got started. In May 2026, the California Supreme Court threw that requirement out. The decision, J.M. v. Illuminate Education, Inc., is the most consequential ruling on protected health information (PHI) in years, and industries from hospitals to ed-tech companies are still adjusting to it.
Read more
The $1.55M Mistake Healthcare Marketers Are Making Outside HIPAA
There is a category of company that has spent a decade believing it sits in a regulatory quiet zone. It handles health-adjacent data every day but is not a hospital, not a health plan, not a business associate. It runs HCP engagement programs, pharmaceutical brand media, condition-education publishing, patient-finder campaigns, and the advertising technology that measures all of it. Its privacy program, if it has one, was built around a single question: are we a HIPAA covered entity? The answer was no, and the analysis stopped.
Read more
Legal Theories Win Cases. Operations Win the Ones That Never Get Filed.
I spent four years as plaintiffs' counsel building TCPA, FCRA, and FDCPA cases. Today I sit on the other side twice over: as a General Counsel writing compliance playbooks, and as counsel to marketing companies reaching patients and healthcare providers through the very channels I used to build cases around.
Read moreSchedule a consultation
Tell us a little about your company and what you need. We'll respond within one business day.
Schedule a consultation