Health Privacy

Hintze & Partners Recognized by Chambers in 2025 USA Rankings

Hintze Law PLLC is delighted to announce the Chambers & Partners recognition of Susan Hintze, Mike Hintze, Sam Castic, and Mason Fitch in its USA Guide 2025. These recognitions include the firm’s sixth year being nationally ranked in Privacy and Data Security, and third year in Privacy & Data Security: Healthcare.

Susan Hintze, co-managing partner, and Mike Hintze, partner, have been recognized for their privacy and data security law expertise for seven years by Chambers & Partners. This is the first year Sam Castic, partner, and Mason Fitch, senior associate, have been ranked by Chambers & Partners.

Sam Castic is a partner with Hintze Law, chair of the firm’s Retail Group, and co-chair of the Cybersecurity and Breach Response Group and FinTech + Financial Services Group. As a former chief privacy officer, he helps companies build, scale, and right-size privacy programs and strategies. In Chambers’ review, clients are quoted, praising Sam’s “technical levels of expertise that impress the engineers as well as being hyper-focused on all applicable legislation.” Sam is known amongst clients for being “practical, knowledgeable and easy to work with,” and his “dead on and practical” advice that “provides exactly the right amount of awareness you need.” Clients also commended Sam’s “great expertise in the financial privacy space.”

Mason Fitch is a senior associate and a member of the firm’s Health & Biotech Team. Mason’s significant in-house experience allows him to provide clients with practical, actionable advice. This is his first year being recognized by Chambers & Partners as an Associate to Watch in the 2025 USA Guide—Healthcare: Texas. Mason’s clients praise his “excellent knowledge of the industry and where the industry is going,” and for “provid[ing] practical advice.” Clients also told Chambers & Partners that “Mason is great to work with and fully delivers what we need him to.”

Hintze Law’s Health & Biotech Team has been recognized by Chambers & Partners for three years. Led by Hintze Law partner Kate Black, the team is comprised of “experts who are in-house experienced advisors, able to distil complex matters into tangible and proportionate steps.” This team works with biotechnology, medical device, digital health, and consumer wellness companies, as well as data analytics and machine learning platforms that work with health information. The dedication and expertise the health & biotech team provides to clients makes Hintze Law a perfect “one-stop shop for tech companies.”

Susan and Mike have been recognized in the 2025 edition of Chambers & Partners in the Privacy & Data Security: Privacy area. Susan has a reputation for her “impeccable ability to explain the details of the law” and "her experience across a range of companies, keen awareness of the regulatory environment, and ability to distil complex topics into guidance.

Mike was also ranked for his work in Privacy & Data Security: Adtech. This is his second year being recognized in this area of expertise and clients’ praise. “Mike's extensive experience in-house ... makes his counsel not only expert but practical, risk-based, and actionable. He isn't afraid to weigh in and say what he would do in my shoes." Mike is now recognized in the Band 1 rankings of Chambers & Partners.

Chambers ranking bands are a way of organizing and recognizing law firms and individual lawyers based on their performance and reputation, with Band 1 representing the highest tier. Being ranked in any band is a significant achievement, as it indicates that the firm or individual has demonstrated strong technical legal ability, professional conduct, client service, and other qualities valued by clients.

Hintze Law’s lawyers work exclusively on privacy, cybersecurity, and AI issues. The firm is pleased to be recognized by Chambers & Partners as an Elite Law Firm for Privacy and Data Security.

Founded in 2014, Hintze Law has been honored to receive accolades showcasing the firm’s expertise and client service on privacy, data security, and AI matters. The firm and lawyers have been ranked for years by peers and colleagues as among the top legal professionals in privacy. Achievements include recognition in Chambers’ Global & USA Privacy and Data Security rankings, the Legal 500’s U.S. Cyberlaw rankings, Best Law Firms local and national rankings, and Global Data Review’s GDR 100 as one of the world’s best data law firms.

Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on global privacy, data security, and AI law. Its attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of privacy, data security, and AI law.

Virginia Governor Signs Reproductive Health Data Restrictions into Law

Virginia Governor Signs Reproductive Health Data Restrictions into Law

by Cameron Cantrell and Felicity Slater 

On March 24, 2025, Governor Youngkin (R) of Virginia signed SB 754—which amends the Virginia Consumer Protection Act (VCPA) to restrict the collection and processing of “reproductive or sexual health information” and is enforceable through a private right of action—into law. The law will take effect July 1, 2025. 

Read More

Fourth Circuit Publishes Landmark Ruling on 21st Century Cures Act “Information Blocking”

By Cameron Cantrell and Kate Black

On March 12, 2025, the Fourth Circuit Court of Appeals ruled that (1) the information blocking prohibition in the federal 21st Century Cures Act (“Cures Act”) was plausibly violated when an Electronic Health Record (EHR) provider blocked bot access to its systems without sufficient justification, and (2) this violation may support a Maryland state law unfair competition claim, despite the Cures Act not having its own private right of action. This decision notably appears to be the first Circuit Court decision concerning the information blocking prohibition and, for parties subject to the rule, raises the risk that information blocking may be enforceable through a de facto state privacy right of action.

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night

Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night

By Felicity Slater and Kate Black

The Maryland Online Data Privacy Act (“MODPA” or the “Act”), which takes effect October 1, 2025, establishes a set of novel requirements that will have a particular impact for companies operating in the health and wellness sectors. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Hintze & Partners Recognized by Chambers in 2025 Global Rankings

Hintze & Partners Recognized by Chambers in 2025 Global Rankings

Hintze Law and its lawyers have once again been recognized in Chambers & Partners for expertise in Privacy and Data Security in the 2025 Chambers Global Guide. These recognitions include Hintze Law’s fifth year being ranked as an Elite Law Firm for Privacy and Data Security as well as the firm’s second year receiving recognition for Privacy and Data Security: Healthcare.

Read More

New York Legislature Passes Extraordinarily Restrictive Health Data Privacy Bill

New York Legislature Passes Extraordinarily Restrictive Health Data Privacy Bill

By Mike Hintze and Felicity Slater

Last year, we wrote about a proposed New York State law that would have significant impacts for entities that process health and wellness related data. That bill failed to pass before the 2024 legislative session ended. But today, in the early days of the 2025 session, the New York State legislature has passed Senate Bill S929 (SB S929), which is essentially unchanged from last year’s bill.  

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

In ‘Holy Redeemer’ Settlement Agreement, OCR Continues to Prioritize Privacy Protections for Reproductive Health Information

In ‘Holy Redeemer’ Settlement Agreement, OCR Continues to Prioritize Privacy Protections for Reproductive Health Information

by Felicity Slater and Kate Black

On November 26, 2024, the Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced a resolution agreement and corrective plan with Pennsylvania’s Holy Redeemer Hospital (Holy Redeemer). The agreement settles OCR’s claim that Holy Redeemer disclosed a patient’s protected health information (PHI)—including intimate reproductive health details—without a permissible purpose or valid authorization from the patient in violation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule

Read More

A Last-Minute Push for a Reproductive Health Privacy Law in Michigan

A Last-Minute Push for a Reproductive Health Privacy Law in Michigan

By Mike Hintze and Felicity Slater 

On November 7, 2024, the Michigan legislature introduced Senate Bill 1082 / House Bill 6077, the Reproductive Data Privacy Act (the “RDPA” or the “act”). The act was introduced in the aftermath of the 2024 election cycle as Michigan Democrats brace to lose control of the House in 2025. At a hearing in the Senate Committee on Housing and Human Services, lawmakers backing the RDPA expressed a hope to pass the act before the year’s end. 

Read More

Washington My Health My Data Act - Part 4: Effective Dates

By Mike Hintze

Yesterday the amended Senate version of the Washington My Health My Data Act was approved by the Washington State Legislature. Now that it is a near certainty the Act will become law in its current form, entities subject to the Act need to start preparing to comply. The key factor in determining deadlines for having compliance measures in place is the effective date of the Act. The Act purports to come into effect on March 31, 2024 (and for small businesses, three months later on June 30, 2024). However, contrary to stated legislative intent, and due to what one can only conclude is, at least in part, a drafting error, some of the key substantive provisions of the Act may come into effect much sooner than expected - as soon as July 2023. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Washington My Health My Data Act - Part 3: The Scope of Entities and Consumers Captured by the Act

By Mike Hintze

The Washington My Health My Data Act applies to “regulated entities” that collect or process “consumer health information” from “consumers.” Part two of this series addressed the definition of “consumer health data” and how that definition results in a scope of applicability that is far beyond what we might typically think of as sensitive health data. But the other two above-quoted defined terms – “regulated entity” and “consumer” also result in a very broad (and in some ways surprising) scope and impact. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

Washington My Health My Data Act - Part 2: The Scope of “Consumer Health Data”

By Mike Hintze

The substantive requirements of the Washington My Health My Data Act apply to collection, use, and disclosure of “consumer health data.” While there are a few important exclusions, the stunning breath of that term's definition, means that it will be difficult to safely conclude that any category of personal data is out of scope of the Act. As a result, it is inaccurate to refer to the Washington My Health My Data Act as a “health data privacy law.” On the contrary, it is, in effect, a generally-applicable privacy law. 

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze

The Washington My Health My Data Act - Part 1: An Overview

By Mike Hintze

The Washington My Health My Data Act will become the most consequential privacy legislation enacted in 2023. The sweeping scope and extreme substantive obligations, combined with vague terms and with a full private right of action, make this Act extraordinarily challenging and risky for entities seeking to comply with its requirements.

Read More
Don’t Sleep on Maryland: The Maryland Online Data Privacy Act Will Keep Health and Wellness Companies Up at Night — Hintze