Steptoe & Johnson’s Privacy Team is a vastly experienced, cross-section group of attorneys who represent various practice areas, including employment, litigation, business, and healthcare.



Employment-related privacy issues

  • Provide general counseling services
  • Provide advice regarding the collection and maintenance of employee information
  • Provide advice regarding employee monitoring issues

Family Educational Rights and Privacy Act (FERPA): Assist with issues involving the access and disclosure of education records

Financial privacy issues

Freedom of Information Act issues

General Litigation: Defend against claims of, for example, HIPAA violations, employment-related matters involving the use/disclosure of personal information, FERPA violations, and common law invasion of privacy claims

General Privacy

  • Assist with responding to requests for records (e.g., patient access, authorizations, subpoenas, warrants, court orders, etc.)
  • Assist with privacy issues in business transactions (e.g., ownership of medical records and access rights in physician practice acquisition)
  • Draft privacy policies for the collection, maintenance, use, and/or disclosure of individually identifiable information
  • Make presentations/provide training on privacy-related issues
  • Represented electronic privacy groups in appeal to D.C. Circuit seeking greater privacy protections in FCC rules implementing the Communications Assistance to Law Enforcement Act

Health Care

  • Assist with compliance with HIPAA regulations including drafting/reviewing privacy policies and procedures, Business Associate Agreements, authorizations, and Notices of Privacy Practices
  • Assist with internal investigations, responding to, and/or reporting security incidents/breaches
  • Assist with responding to HIPAA-related investigations and/or complaints from the Office of Civil Rights, U.S. Department of Health and Human Services
  • Conduct training on HIPAA-related topics
  • Defended electronic medical records vendor in lawsuit alleging faulty transmission of electronic prescription to pharmacy from physician
  • Represented healthcare insurer in civil action against physician for fraudulent scheme involving electronic medical benefits claims processing
  • Extensive experience producing documents containing protected health information consistent with HIPAA protections in litigation discovery
  • Advised clients regarding responses to inadvertent releases of protected health information