Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 33 results

Client Alert | 7 min read | 09.14.26

AI in Life Sciences: Ten Legal Considerations and Risks of AI Use in Drug Discovery and Development

Over the past several years, the biopharmaceutical industry has embraced artificial intelligence and machine learning (AI/ML) in near lockstep with the pace of AI/ML innovations. Today, industry leaders are using AI/ML to, among other things: discover and assess biological pathways, target chemical structures and sequences; design proteins; model pre-clinical and clinical trials; recruit and screen potential patient populations; evaluate clinical trial results and biomarker data; prepare regulatory filings; and manage supply chains. Deployment of new AI/ML models promises extraordinary advances in pharmaceutical development. However, as with any technological and scientific advances, the use of AI/ML also poses substantial legal risks that life sciences companies need to consider and proactively manage. 
...

Client Alert | 6 min read | 09.03.26

FDA Seeks Input for Regulating GenAI-Powered Medical Devices

The U.S. Food & Drug Administration (FDA) is seeking feedback on a regulatory framework that could be used to evaluate generative artificial intelligence (GenAI)-enabled medical devices. Such devices could create new types of risks because their outputs can vary and evolve, unlike more traditional software-enabled devices. An August 18, 2026, discussion paper (“Considerations for the regulation of GenAI-enabled medical devices”) discusses potential regulatory considerations for GenAI-enabled medical devices. 
...

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen.
...

Client Alert | 10 min read | 07.08.26

Proactive Compliance in Health Care: “Getting Ahead” of Enforcement in 2026 and Beyond

As federal and state regulators alike continue to tout holding health care organizations accountable for alleged fraud, waste, and abuse as a top priority, ensuring compliance and minimizing enforcement risk has never been more imperative — or more challenging. Health care organizations operate at the intersection of rapid technological changes and within an increasingly complex regulatory landscape, where the rules governing scrutinized areas such as privacy, AI, billing integrity, and strategic transactions are being written, rewritten, and enforced in real time. Treating compliance as a periodic documentation exercise is simply not an option. Today, an effective risk mitigation strategy must be grounded in two complementary elements: a thorough understanding of evolving regulatory obligations and a candid internal assessment of potential points of exposure.
...

Client Alert | 4 min read | 07.06.26

House Advances Bipartisan Kids' Online Safety Bill, But Senate Showdown Looms

On June 22, 2026, House Energy and Commerce Committee Chairman Brett Guthrie (R-Ky.) and Ranking Member Frank Pallone (D-N.J.) announced a bipartisan agreement on a revised version of the KIDS Act (H.R. 7757), marking the most significant congressional advance on children's online safety legislation in years. The House passed H.R. 7757, as amended, on June 29, 2026, setting up a potential showdown with the Senate. The revised KIDS Act consolidates elements of 14 pending legislative proposals — including KOSA and COPPA 2.0, both of which have previously passed the Senate and cleared the House Energy and Commerce Committee — into a single, comprehensive framework. The announcement, however, was met immediately with objections from Senate sponsors and civil liberties groups, underscoring the difficult legislative road ahead.
...

Client Alert | 5 min read | 05.12.26

NYDFS Ramps Up Health Care Cybersecurity Enforcement With $2.25 Million Settlement

On April 29, 2026, the New York Department of Financial Services (NYDFS) announced the finalization of a $2.25 million settlement with Delta Dental of New York and Delta Dental Insurance Co., resolving allegations that the affiliated companies failed to comply with the state’s stringent cybersecurity, consumer data protection, and incident reporting requirements. For health insurers, managed care organizations, and their third-party service providers operating in New York, the announcement comes as the latest signal that the NYDFS intends to aggressively enforce its cybersecurity regulations — which are widely considered the strictest in the nation following a 2023 overhaul. These regulations, codified at 23 NYCkRR 500 (Cybersecurity Requirements for Financial Services Organizations), apply to any entity licensed under New York insurance law, including health insurers, managed care organizations, and their third-party service providers.
...

Client Alert | 6 min read | 05.11.26

FDA’s AI in Early Phase Clinical Trials RFI: An Opportunity to Help Set the Rules of the Road

Consistent with recent FDA initiatives directed at leveraging AI technologies and improving early-phase clinical trial conduct, the FDA has issued a Request for Information (RFI) for input on a proposed AI-enabled optimization pilot program for early-phase clinical trials. The issues for which FDA is requesting information fall into two categories:  (A) Pilot program design and implementation and (B) Program evaluation metrics and success criteria.
...

Client Alert | 4 min read | 05.06.26

Genetic Data and Artificial Intelligence Training Following Acquisitions: Emerging Litigation Risk and a Rapidly Expanding State Regulatory Landscape

Several recent class actions filed against Tempus AI, Inc., a health care technology company that combines AI with molecular and clinical data to develop precision medicine services, are the latest in a series of cases illustrating a fast-growing legal risk: the repurposing of genetic and clinical data — collected for diagnostic or treatment purposes — for artificial intelligence (AI) model training, analytics, and downstream commercialization following corporate acquisitions. At the same time, state genetic privacy regulation is expanding rapidly, with Utah and South Dakota being the most recent states to enact new statutes, and legislation advancing in several additional states. Organizations holding genetic datasets need to treat data governance as a core enterprise risk issue, not a downstream compliance matter.
...

Client Alert | 5 min read | 04.09.26

U.S. State Privacy Enforcement: Key Priorities and Practical Guidance From State Regulators

At the International Association of Privacy Professionals’ (IAPP) annual conference March 30-31, 2026, enforcement officials from California, Connecticut, Indiana, and Delaware shared their current and upcoming enforcement priorities under U.S. state consumer privacy laws. This alert summarizes the key themes from the panel and offers practical guidance for companies navigating the evolving enforcement landscape.
...

Client Alert | 4 min read | 04.02.26

FTC Announces New Health Care Task Force

In a development likely to ramp up regulatory pressure on an industry already under significant federal scrutiny, Federal Trade Commission (FTC) Chairman Andrew Ferguson recently directed leaders across his agency to launch a team dedicated to cooperatively advancing enforcement and advocacy activities relevant to health care.
...

Client Alert | 6 min read | 03.11.26

White House’s New Cyber Strategy and Executive Order Seek to Deter Adversaries and Strengthen Resilience

On March 6, 2026, the White House released its National Cyber Strategy (Strategy) and issued an accompanying Executive Order, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens” (EO). These documents outline the administration’s priorities for combating cybercrime and call for coordination across the federal government and the private sector to invest in new technologies, continue innovation, and prioritize the United States’ cyber capabilities. Key sectors of concern include energy, financial services, telecommunications, data centers, water, and health care. The Strategy and EO encourage increased public-private coordination, signal greater latitude for private sector offensive cyber operations, prioritize securing critical infrastructure, elevate cybercrime as a national security priority, outline a path for victim compensation, and promote streamlining cyber regulations.
...

Client Alert | 6 min read | 12.17.25

Executive Order Tries to Thwart “Onerous” AI State Regulation, Calls for National Framework

On December 11, 2025, President Trump signed a much-anticipated Executive Order that seeks to forestall state regulation of artificial intelligence (AI) by threatening federal lawsuits and the withholding of some federal funds and calls for a national policy framework on AI. The Executive Order, Ensuring a National Policy Framework for Artificial Intelligence (EO), declares it the policy of the administration “to sustain and enhance the United States’ global AI dominance through a minimally burdensome national policy framework for AI.”
...

Client Alert | 6 min read | 11.24.25

Draft Executive Order Seeks to Short-Circuit AI State Regulation

President Trump is preparing to sign an Executive Order that would seek to forestall state regulation of artificial intelligence (AI) by threatening federal lawsuits and the withholding of some federal funds. The draft, unsigned six-page Executive Order, “Eliminating State Law Obstruction of National AI Policy” (EO), the text of which has been circulating publicly since November 19, would declare it the policy of the Administration “to sustain and enhance America’s global AI dominance through a minimally burdensome, uniform national policy framework for AI.”
...

Client Alert | 2 min read | 10.03.25

FDA Seeks Input on Real-World Performance of AI-Enabled Medical Devices: What Biotech and MedTech Innovators Need to Know

On September 30, 2025, the Food and Drug Administration (FDA) issued a Request for Public Comment (“Request”) inviting stakeholders to share practical experience and recommendations for measuring and evaluating the real-world performance of AI-enabled medical devices, including those powered by GenAI. According to FDA, the Request is not intended to communicate new guidance or regulatory expectations but aims to advance the conversation on how best to assure the safety, effectiveness, and reliability of AI-driven technologies in clinical practice.
...

Client Alert | 6 min read | 09.29.25

White House Seeks Industry Input on Laws and Rules that Hinder AI Development

On September 26, the White House invited the public to submit comments on Federal laws, rules, and policies that “unnecessarily hinder” the development or deployment of artificial intelligence (AI) technologies in the United States. This request marks one of the Trump Administration’s most substantial moves yet to reduce the regulatory burden on AI. Respondents may submit comments through a government website until October 27, 2025.
...

Client Alert | 5 min read | 08.26.25

Supreme Court Stays District Court Order Vacating NIH Grant Terminations, But Leaves Guidance Vacatur Intact

On August 21, the Supreme Court, in National Institutes of Health v. American Public Health Association, granted the government’s application for a stay of the district court’s order vacating NIH’s termination of various research grants. The Court denied the government’s application with respect to the district court’s vacatur of related internal guidance documents. The Court’s order impacts federal government grantees who wish to challenge grant terminations in federal court.
...

Client Alert | 3 min read | 08.06.25

Series of Major Data Breaches Targeting the Insurance Industry

Threat actors have targeted insurance companies in a recent string of cyber-attacks, exposing patients’ personal information, including Social Security numbers, claims information, and health reports.
...

Client Alert | 2 min read | 08.04.25

FDA Announces Availability of ICH Draft Guidance on Inclusion of Pregnant and Breastfeeding Women in Clinical Trials

On Monday, July 21, 2025, the Food and Drug Administration (FDA) issued draft guidance entitled “E21 Inclusion of Pregnant and Breastfeeding Women in Clinical Trials” from the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH). The guidance is currently in Step 2 of the ICH process and open for public comment until September 19, 2025.
...

Client Alert | 7 min read | 07.29.25

White House AI Action Plan: Potential Implications for Health Care

On July 23, 2025, the Trump Administration issued an artificial intelligence (AI) action plan titled “Winning the Race: America’s AI Action Plan” (the Plan) to guide AI innovation in the U.S. The Plan includes 90 policy recommendations that will shape future AI guidance and policies impacting a range of entities and industry sectors, including health care/life sciences and entities involved in clinical research.
...

Client Alert | 15 min read | 07.25.25

White House AI Action Plan Seeks to Establish “Dominance,” Boost Innovation, and Scrutinize Regulations

On July 23, 2025, the White House released Winning the Race: America’s AI Action Plan (“the Plan”) the Trump Administration’s most significant policy statement on artificial intelligence to date.
...