skip to main content

Data Privacy and Protection

Shipman & Goodwin’s Data Privacy and Protection Practice Group assists clients with the critical responsibility of securing data, complying with regulations for the proper use and disclosure of data and responding to breaches and other security incidents.

The firm’s Data Privacy and Protection Practice Group is led by attorneys who possess deep and wide-ranging national experience. Co-Chair William Roberts has advised clients in more than 100 national and international data breach matters and is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP). He has extensive experience with the specific privacy and security challenges faced by health care providers, insurance technology (“InsurTech”) firms and health care technology companies.

Co-Chair George Jepsen, former Connecticut Attorney General, and Perry Zinn Rowthorn, former Connecticut Deputy Attorney General vigorously pursued data privacy and protection matters as one of their priorities while serving as state officials. They also collaborated on the development of an innovative Privacy Task Force that became the Connecticut Privacy & Data Security Department, the first such department in a state attorney general’s office in the nation. (This department subsequently led nationwide multi-state investigations into the nation’s largest data breaches, resulting in sizeable settlements and working with industry to establish best practices and standards to protect the data of citizens and businesses.)

Our multi-disciplinary team of lawyers is experienced in all aspects of data privacy and protection and has a consistent record of representing leading companies in a variety of industries, including health care providers, insurers, technology firms, manufacturers and educational institutions as well as governmental and quasi-governmental entities.

We offer a comprehensive approach to counseling clients through prevention, compliance and crisis management.

Safeguarding Data. We counsel clients on all issues related to appropriately safeguarding data during collection, storage, maintenance and disposal. Our representation includes:

  • Evaluating data privacy and protection risk profiles
  • Developing strategies to build efficient privacy infrastructures
  • Drafting and implementing company data privacy and protection policies
  • Advising on retention, destruction and e-discovery of documentation
  • Advising on employee records issues and employee use of email and social media tools
  • Developing licensing and data-sharing agreements

Compliance. We work with clients to develop compliance programs to protect the confidentiality of data, which includes:

  • Establishing compliance programs for early detection of privacy issues
  • Establishing and maintaining compliance hotlines
  • Complying with domestic and international data protection laws and privacy laws and regulations), including:
    • Gramm-Leach-Bliley Act (GLB)
    • Telephone Consumer Protection Act (TCPA)
    • EU General Data Protection Regulation (GDPR)
    • New York Department of Financial Services (DFS) Cybersecurity Regulation
    • Children’s Online Privacy Protection Act (COPPA)
    • Federal Trade Commission Act (FTCA)
    • Providing training to privacy and security officers, staff and employees.

Data Breaches and Investigations. Our team has extensive experience handling all aspects of national and international data breach matters and other security incidents, including:

  • Conducting whistleblower and internal investigations
  • Guidance on conducting investigations and providing required notifications when a breach has occurred
  • Providing representation during breach investigations before federal and state agencies, including the Department of Health & Human Services (HHS), the Office for Civil Rights (OCR), the Federal Trade Commission (FTC), state attorneys general and state departments of insurance
  • Litigating privacy disputes in jurisdictions throughout the country.


February 4, 2019  NYSDFS Upcoming Deadlines Fast Approaching: Next Key Dates are February 15, 2019 and March 1, 2019
December 11, 2018  Expansion of CFIUS Oversight of Certain Non-Controlling Foreign Investments
August 28, 2018  NYSDFS Upcoming Deadlines Fast Approaching: Next Key Date is September 4, 2018
May 8, 2018  The GDPR is Coming: Keep Calm and Plan
February 6, 2018  NYSDFS Upcoming Deadlines Fast Approaching: Next Key Date is February 15, 2018
August 22, 2017  NYSDFS Upcoming Deadline Fast Approaching: First Key Date is August 28, 2017
October 3, 2016  Family Policy Compliance Office Issues FERPA Privacy Guidelines
August 29, 2016  Compliance Conundrum -- Unauthorized Exports v. Discrimination: Find a Win in a Lose-Lose Scenario
June 20, 2016  Governor Signs Student Data Privacy Law
January 27, 2016  If You Provide Behavioral Health Services, Do the New HIPAA Reporting Rules Apply to You?
October 14, 2015  Court of Justice of the European Union Declares the U.S.-E.U. Safe Harbor Invalid
June 22, 2015  Conn. Seeks To Tighten Data Privacy Requirements
January 2015  Going Live with a Patient Portal—Legal Risks and Operating Documents
December 12, 2014  Recent Data Breach Demonstrates the Importance of Attention to Software and IT Systems
July 14, 2014  Dan Schwartz quoted in LTN News article, "Hackers Are After Employee Data Now"
May 12, 2014  Health Law: HIPAA Breaches: Getting It Right
March 14, 2014  Dan Schwartz quoted in CT Law Tribune article, "Bill Would Ban Requests For Social Media Passwords"
March 6, 2014  Employers Be Forewarned: The Forms You Use to Obtain Applicant Background Checks May Violate FCRA
August 27, 2013  Recent Data Breach Demonstrates the Importance of Keeping Track of Your Sensitive Information
June 26, 2013  Amended Rule for the Children's Online Privacy Protection Act Takes Effect
July 1, 2013
June 25, 2013  FDA Releases Draft Cybersecurity Guidance for Medical Devices
January 3, 2013  HHS Announces Mobile Device Security Initiative
November 2012  Connecticut's HIE: A Look at the Nutmeg State's Approach to Sharing Patient Information
August 2, 2012  Breaches of Personal Information Must Now Be Reported to the Attorney General


February 22, 2019  Shipman & Goodwin Weighed in With Aetna on Data Security for New App
March 20, 2018  Bill Roberts Selected as InsurTech Hartford Mentor
January 13, 2018  Bill Roberts Quoted on Issues in Law Firm Data Breaches
August 1, 2017  Bill Roberts Appointed to CT Health Data Collaborative
July 28, 2017  Bill Roberts Explains Health Care IT Balancing Act in Huffington Post
June 5, 2017  International Trade Attorneys Featured in U.S. Dept. of Commerce Webinar Series
April 4, 2017  Joan Feldman and Bill Roberts Highlight Key Health Care Compliance Issues at Nat'l Conference
March 6, 2017  Cyber Security Program and Panelist Bill Roberts Emphasize Preventive Measures
January 23, 2017  Bill Roberts Quoted on Importance of Cybersecurity Risk Management Plans
January 10, 2017  Bill Roberts Weighs in on Increased Attempts to Steal W-2s
October 26, 2016  Bill Roberts Suggests Quick Response to Student Data Breaches
August 19, 2016  Bill Roberts Offers New Guidance on Health Care Data Privacy
July 25, 2016  Bill Roberts Provides Commentary in Report on Medicare Compliance
July 20, 2016  Health Law Daily Recaps HCCA Vendor Privacy Webinar Presented by Bill Roberts
July 11, 2016  Bill Roberts Quoted in Part B News on Recent HIPAA Breach
June 10, 2016   Bill Roberts Featured in Q&A on Data Privacy, Information Security and Preventing Breaches
March 9, 2015  Dan Schwartz Offers Commentary on Password Bill for WNPR News
March 5, 2015  Bill Roberts Joins HIPAA Website as Commentator
November 14, 2014  Bill Roberts Comments on Medical Records Ruling
October 17, 2014  CT Attorneys Recognized as 2014 Super Lawyers
September 17, 2014  ABA Appoints Bill Roberts as Business Law Section Envoy
September 15, 2014  October Data Privacy Summit
November 4, 2013  Roberts Recognized as New Leaders in the Law
October 21, 2013  CT Attorneys Recognized as 2013 Super Lawyers
May 11, 2012  Panel Explores Risks and Rewards of Social Media for Health Care Providers


May 8, 2019  Webinar: Privacy and Data Security: US/Brazilian Cross-Border Issues and Trends
March 5, 2019  28th National HIPAA Summit
November 30, 2018  CLE Event: Professionalism Boot Camp
November 20, 2018  CEN Education and Development Advisory Council Workshop
October 25, 2018  Privacy and Data Security in a Globalized World: Cross-Border Issues and Trends
September 14, 2018  Annual Risk Management Day
August 7, 2018  CLE Event: Webinar: Compliance Checkup: NY DFS Cybersecurity Regulations
June 13, 2018  CLE Event: Webinar: Export Controls in the Cloud
May 22, 2018  Model Agreements & Guidelines International (MAGI) Clinical Research Conference
April 3, 2018  Independent School Webinar: Safeguarding Data - Developing a School Data Privacy and Security Program
March 27, 2018  Data Privacy for Public and Charter Schools: What Lies Ahead - Stamford
March 15, 2018  Data Privacy for Public and Charter Schools: What Lies Ahead - Hartford
January 25, 2018  Digital Health - InsurTech With Benefits
November 30 - December 2, 2017  2017 TABS Annual Conference
August 17, 2017  Webinar: Export Controls in the Cloud
July 18, 2017  Health Care Compliance Association Web Conference
May 23, 2017  Cybersecurity Threats: Are You Next?
May 18, 2017  WorkSmart Hartford 2017: Annual IT, Business & Security Conference
May 12, 2017  2017 Connecticut Education Network Annual Conference
March 28, 2017  Is Your HR Data Going Rogue? Practical Steps for HR to Take
March 26-29, 2017  Health Care Compliance Association's 21st Annual Compliance Institute
March 1, 2017  The Next Generation of Cyber Security: It's Not Just About Firewalls and Antivirus Software Anymore
February 23, 2017  Recent Privacy and Security Developments in Human Subjects Research
February 22, 2017  CLE Event: Webinar: Safeguarding Your Business: Preventing and Responding to Data Breach and Cyber-liability
November 30 - December 2, 2016  OCR Audits Phase 2 With Real Life Experience - How to Navigate?
October 23-26, 2016  MAGI's Clinical Research Conference - 2016 West
October 20, 2016  CT Technology Council 2016 IT Summit
October 11, 2016  Webinar: Compliance Conundrum--Unauthorized Exports v. Discrimination
July 19, 2016  Vendor Privacy: Due Diligence and Contracting Solutions
June 27, 2016  Briefing on Public Act 16-189: An Act Concerning Student Data Privacy
June 15, 2016  Webinar: Managing HIPAA Data Breaches
May 2, 2016  HR's New Challenge: Cyber Security
April 9, 2016  American Bar Association Business Law Section Spring Meeting
March 23, 2016   Webinar: Telemedicine & eConsults - Where We Are Today and Where We're Going
December 11, 2015  Update on Data Privacy and Human Resources Law
December 2, 2015  Webinar: Business Associates: How to Differentiate Your Organization Using HIPAA Compliance
November 18, 2015  CT Technology Council 2015 IT Summit
November 9, 2015  Capitol Region Education Council - Technology Conference
September 29, 2015  IAPP: The Intersection of Information Governance and Privacy
September 24, 2015  Data Security and Privacy Risk Management in a New World of Big Data Collection and Sharing
September 24, 2015  Webinar: How to Effectively Negotiate a Business Associate Agreement: What's Important/What's Not
September 18, 2015  American Bar Association Business Law Section Annual Meeting
July 14, 2015  Webinar: HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Practices
April 30, 2015  Webinar: Legal Consideration and Best Practices for Developing an Effective Cybersecurity Strategy
March 13, 2015  Right to Privacy & HIPAA
February 12, 2015  CHCACT: Corporate Compliance Workgroup
January 15, 2015  IAPP: Transactional Aspects of Big Data and Related Privacy Issues
January 14, 2015  Stage 2 Meaningful Use Audit: What You Need to Know
October 16, 2014  Raiders of the Data Ark - Data Privacy & Cybersecurity Summit
October 9, 2014  CCPA: Establishing an Effective Compliance Program
June 12, 2014  International Association of Privacy Professionals KnowledgeNet
May 2, 2014  SHRM: Pirates of the Data Stream - HR's Role in Securing Corporate Information
January 8, 2014  CALPI: Investigations and Background Screening
November 15, 2013  Connecticut Technology Council: The IT Summit 2013
April 8, 2013  Family Opposition to First Person Consent
March 15, 2013  Complying With the New HIPAA Regulations - Part II
March 1, 2013  Complying With the New HIPAA Regulations - Part I
May 10, 2012  Catching the Social Media Bug: The Risks and Rewards of Social Media For Health Care Providers
© Shipman & Goodwin LLP, 2019. All Rights Reserved.