Privacy and Cybersecurity Specialist with proficiency in online security research, planning, execution and maintenance. Skilled at training users on security procedures and preventive measures.
Overview
26
26
years of professional experience
1
1
Certification
Work History
Principal
Private Practice
12.2015 - Current
Counsel business executives on corporate compliance with privacy, cybersecurity and information management
Develop client specific tools, internal training materials and corporate procedures (guidance documents, consent forms, privacy impact assessments, risk assessment, data transfer and processing agreements, complaint handling and employee training materials)
Formulate compliance programs and procedures for privacy laws and regulations including GDPR, CCPA, CPRA, TCPA, FCPA, CAN-SPAM, HIPAA, COPPA, and State privacy laws
Prepare and negotiate technology agreements, including software licenses, MSAs, cloud computing agreements, collaboration, joint development, data protection, and data security service agreements
Advise clients, draft and negotiate contract language relating to data governance, privacy, data protection and cybersecurity operation provisions for technology transactions, global commercial agreements, marketing, advertising and corporate transactions, cross-border data transfer and vendor management, including standard templates for company wide use
Develop privacy and security guidance for businesses including online and digital media initiatives.
Coordinated with executives on strategic initiatives relating to privacy protections and alignment among data privacy and security activities.
Of Counsel
SRD Legal Group
11.2021 - 09.2022
Drafted, reviewed and negotiated contracts, including service agreements, cloud storage, technology vendor agreements and complex commercial arrangements and other legal documents to support client needs.
Researched and interpreted laws, rulings and regulations to advise clients on business and legal transactions.
Developed, maintaining, and updated boilerplate/standard forms in response to changing industry trends and practices
Of Counsel
Tenzer and Lunin LLP
09.2018 - 05.2022
Counsel healthcare clients on regulatory compliance matters, structuring transactions, and ongoing day-to-day operations, including compliance with Federal and state anti-kickback laws, Stark law, fraud and abuse, FDA regulations, CLIA and HIPAA
Drafted and negotiated agreements for health care institutions, including acquisitions, managed care and corporate governance documents, licensing and certificate of need documents.
Prepared and negotiated project financing, real estate financings and HUD insured mortgages.
Counseled health care providers on HIPAA and state privacy and cybersecurity regulations.
Interim Privacy Counsel
Sony Corporation of America
04.2018 - 08.2018
Provided legal management of Company's GDPR implementation
Prepared external and internal facing privacy policies, templates for privacy impact assessments, data incident response, breach notifications and remediation plans and records of processing
Developed training for employees on GDPR and related legal issues
Drafted intercompany cybersecurity agreements, including PEN testing.
Contract Attorney - Privacy
Cotiviti, Inc.
11.2016 - 04.2017
Worked with Company's Privacy Officer to implement company wide digital data and HIPAA compliance
Developed privacy policies and SOPs for Company's payment audit and overpayment recovery processes
Drafted privacy policies and procedures for digital advertising and marketing
Worked with business teams to develop standard provisions for vendor, partner and supplier agreements.
Contract Attorney
Mathematica Policy Research, Inc.
05.2016 - 09.2016
Advised Company on provisions of EU Privacy Shield, TCPA, FARs, DFARs, COPPA, and other international and Federal laws and regulations
Collaborated with grant proposal and program design teams preparing RFPs for DOL, DOE and other federal agencies and private research initiatives to secure research contracts
Worked with data security department to develop documentation of Company's privacy and security protocols for electronic transmission of data.
Represented healthcare, telecommunications, software and other technology, digital media, advertising, and financing companies
Advised on regulations including HIPAA, FCRA, EU Data Protection Directive, COPPA and GLBA, CASL and industry marketing and digital guidance
Drafted and negotiated agreements including technology development, data transfer, IT outsourcing, software maintenance, product licensing, distribution, co-marketing, and procurement agreements
Drafted and reviewed privacy and security policies and procedures, including enterprise-wide and department-specific policies and procedures
Conducted privacy and security risk assessments
Provided board and management oversight of privacy and security programs.
Education
Certificate, U.S. Healthcare Compliance -
Seton Hall University School of Law
Newark, NJ
Juris Doctor -
Brooklyn Law School
Brooklyn, NY
Bachelor of Arts -
Cornell University
Ithaca, NY
Skills
Corporate and Business Legal Issues
Legal Compliance
Strategy Development
Negotiation
Certification
CIPP/US - Certified Information Privacy Professional