Matt advises organizations on privacy, cybersecurity, data governance, and artificial intelligence from development and data collection through deployment and data disclosure. His clients include some of the world's most sophisticated data users and data-first companies, spanning technology, financial services, health care, and adtech/martech.
Effective counsel in privacy, cybersecurity, and AI requires more than legal knowledge. Matt works at the intersection of law, technology, and operations to help organizations understand where risk lives in their systems and processes and to build the governance structures and controls to manage and allocate risk between organizations and their counterparties. He counsels on program development and compliance, negotiates data-related contracts and transactions, and advises on the expanding body of U.S. and global law governing data, AI, and communication privacy and security. He regularly writes and speaks on privacy, cybersecurity, and AI issues.
In addition to his counseling work, Matt represents clients in data and privacy disputes in state and federal courts nationwide and handles security incident response when things go sideways. The vulnerabilities and decisions that lead to incidents, investigations, and litigation inform everything about how he counsels clients before any of that happens.
Earlier in his career, Matt worked at two national firms and served as senior privacy counsel at one of the world's largest financial institutions. He holds a CIPP/US certification and earned his JD, magna cum laude, from Boston College Law School.
Matt advises organizations on privacy, cybersecurity, data governance, and artificial intelligence from development and data collection through deployment and data disclosure. His clients include some of the world's most sophisticated data users and data-first companies, spanning technology, financial services, health care, and adtech/martech.
Experience
Privacy and Security Governance and Compliance
- Advising global leaders in chatbot and communication platforms and in data privacy management and governance solutions on proactive data and communication privacy considerations and compliance with US and global wiretapping laws.
- Counseling a global security-first IT solutions and services provider in managed services, cybersecurity, and cloud solutions with maturing and enhancing its privacy and security programs, including updating, aligning, and simplifying its contracting and privacy disclosures.
- Counseling professional sports and entertainment operators on maturing their privacy programs, including the use of facial recognition and biometrics within their facilities.
- Counseling a health care technology company operating at the intersection of health care plans, providers, and members on data privacy compliance in connection with the use of offshore resources.
- Counseling a global B2B data company on developing its product pipeline and on proactive compliance with the Federal Wiretap Act, the Stored Communications Act and state wiretap acts.
- Counseling a Big 4 advertising and public relations company in developing new tools to leverage health information to identify and generate audiences in order to improve advertising spend.
- Advising a leading S&P SmallCap 600 data connectivity company on enhancing and maturing its privacy program in response to changes in U.S. state privacy laws.
- Counseling a Fortune 250 consumer goods company on managing its privacy, data and security risk associated with vendors and affiliates, including establishing a privacy-by-design vendor tiering and data transfer program to permit international data transfers across multiple jurisdictions.
- Advising two Big 4 accounting firms on privacy and security considerations, including the movement of sensitive data subject to extensive restrictions, information security obligations and general privacy compliance.
- Advising a global systemically important bank on privacy compliance and operations under the GLBA, the CCPA, HIPAA and international privacy laws.
- Advising a leading online reseller on privacy and cybersecurity, including counseling on securities disclosures and testing and maturing the organization’s incident response plan and processes.
- Advising an independent, multifacility health care system on maturing and enhancing its privacy and security program, including its HIPAA Privacy, Security, and Breach Notification Rule compliance.
- Counseling a vertically integrated technology and financial institution on developing its privacy program, including preparing and aligning its GLBA and CCPA privacy statements.
- Advising a global online gaming company on its privacy disclosures and compliance with app store privacy rules.
- Advising technology companies offering conversational AI-enabled solutions and AI infrastructure on contracting and proactive data and communication privacy considerations and disclosures.
Artificial intelligence Governance and Compliance
- Advising a CRN Tech Elite 250 security-first, IT solutions and services provider on a program overhaul to develop, mature, and enhance its artificial intelligence assessment and governance program.
- Counseling a global leader in compensation technology and data on developing terms of use for its customer-facing generative AI suite.
- Counseling a data-driven HR and talent optimization platform in creating guidelines for development and integration of AI solutions into its existing product portfolio.
- Advising an enterprise-grade AI safety and security services platform developer on legal issues around white-labeled product integration into agentic AI platforms.
- Counseling a leading research accelerator on best practices for data collection to use in training and tuning advanced AI systems.
Security Incidents and Cyber Risks
- Representing diverse companies in the financial services and health care sectors, including provider networks and multifacility healthcare systems in responding to security incidents involving potential unauthorized access to sensitive personal information.
- Representing a leading online reseller in responding to social engineering attacks against its employees.
- Representing a global systemically important bank in first-in-the-nation litigation at the intersection of the CCPA and GLBA, involving the alleged theft of financial information.
- Representing a Fortune 250 consumer goods company in investigating and responding to a ransomware attack at a vendor that impacts the development of a high-profile product.
- Representing a large, multi-office professional services firm in data handling and reporting obligations related to a security incident involving potential unauthorized access to sensitive client and firm files.
- Representing a leading health care data analytics organization in identifying potential security weaknesses and developing, enhancing and maturing its security program.
Commercial Litigation
- Representing a Fortune 100 financial institution in complex, consolidated breach of contract litigation and advising on data handling obligations of the outside counsel team.
- Representing a Fortune Global 500 financial institution in complex litigation over corporate governance and allegations of financial fraud.
- Representing a leading national specialty retailer and a S&P 600 technology company in separate wiretapping lawsuits at the intersection of communication technologies, SaaS solutions, artificial intelligence, and privacy.
- Representing a Fortune 100 pharmaceutical company in mass torts litigation in e-discovery and cross-border data flows, including advising the organization on the transfer of sensitive health care data across borders and across multiple regulatory regimes, including the GDPR, PIPEDA, the Australian Privacy Act, and Israeli law.
- Representing a leading sports league in handling and producing sensitive player data in class action and mass tort litigation.
- Representing a leading children’s hospital in complex class-action litigation pending in multiple forums arising out of a large, declared data breach.
M&A and General Corporate Compliance
- Counseling leading global investment and private equity firms on evaluating the privacy and security concerns for potential investments and acquisitions.
- Counseling an S&P 500 enterprise software company on strategic issues connected with an acquisition arising out of changes to privacy laws and privacy offerings in the marketplace, including around changes to the adtech and martech ecosystems.
- Counseling a Fortune 250 consumer goods company on corporate and management fiduciary duties related to the organization and the structure of its security response program and compliance with best practices in conformity with U.S. securities laws.
- Advising healthtech startups and investors on the application of novel anonymization techniques, including differential privacy, to permit deidentified data analytics of sensitive health care data to improve medical research.
- Representing an independent, multifacility health care system in the acquisition and integration of a major enterprise software solution.
- Representing a global nonprofit advocacy and research organization in the transition of its research data network to a new provider and new contractual structure.
- Representing a national health care company in the potential divestment of a retail subsidiary.
viewpoints
DOJ: ‘False Claims Act + Cybersecurity’ Is Here To Stay
April 3, 2025 | Blog | By Scott Lashway, Karen Lovitch , Matthew Stein
Amid ongoing policy shifts in Washington, the federal government’s interest in pursuing civil cyber-fraud cases appears to be here to stay.
Will New York Be Next to Regulate Specifically Personal Health Information to Further, and Possibly Re-Write, a New Paradigm of State-Level Health Data Regulation?
February 26, 2025 | Blog | By Scott Lashway, Matthew Stein, Cassandra Paolillo, Kayla LaRosa
The following is a summary comparison between the currently passed NY HIPA and WA MHMDA.
Health Care Enforcement Trends & 2025 Outlook
January 17, 2025 | Blog | By Karen Lovitch , Samantha Kingsbury, Keshav Ahuja, Eoin Beirne, Grady Campion, Daniel Cody, Tara E. Dwyer, Laurence Freedman, Hope Foster, Jane Haviland, Nicole Henry, Caitie Hill, Robert Kidwell, Nick A. LaPalme, Scott Lashway, Kevin McGinty, Payton Thornton, Matthew Stein, Rachel Yount
Our 2025 edition of EnforceMintz reflects on health care enforcement trends, predicts how health care enforcement may evolve, and offers practical guidance about what these trends and predictions mean for health care providers, payors, and other stakeholders.
EnforceMintz — Healing Healthcare? DOJ’s Cybersecurity Enforcement Trained Up for 2025
January 16, 2025 | Blog | By Laurence Freedman, Scott Lashway, Matthew Stein
In 2024, the Department of Justice ramped up cybersecurity enforcement under the Civil Cyber-Fraud Initiative (CCFI), targeting entities that failed to safeguard PHI and PII in federally funded contracts. Key cases highlight trends in False Claims Act litigation and underscore the importance of cybersecurity compliance heading into 2025.
String Of Numbers Or Identifier: The Ninth Circuit Weighs In On BIPA’s Application To Non-Users
October 17, 2024 | Blog | By Scott Lashway, Matthew Stein
In June, the U.S. Court of Appeals for the Ninth Circuit affirmed a social media company’s summary judgment win on BIPA claims, in a sophisticated ruling providing a plausible path forward for technology companies and others offering facial matching services.
News & Press
Pratt's Privacy and Cybersecurity Report published an article by Privacy & Cybersecurity Practice Co-chair Scott Lashway, Special Counsel Matthew MK Stein, Of Counsel Cassandra Paolillo, and Associate Kayla LaRosa examining the differences between the New York legislature's version of Washington's My Health Data Act and the Washington law. The New York Health Information Privacy Act currently awaits Kathy Hochul’s signature.
FCA Settlements Demonstrate Importance of Cybersecurity Controls Imposed by Contract
August 20, 2024
Members Scott Lashway, Laurence Freedman, and Special Counsel Matthew Stein published an article in Bloomberg Law about how recent False Claims Act (FCA) settlements show a focus on cybersecurity enforcement. In the article, they outline how organizations with government contracts can mitigate the risk of cybersecurity-related FCA investigations and litigation.
Publications
- Co-author, "FCA Settlements Demonstrate Importance of Cybersecurity Controls Imposed By Contract," Bloomberg Law (August 2024)
- Author, “Massachusetts’ march to comprehensive privacy legislation: an end-of-year update,” Massachusetts Lawyers Weekly (January 2024)
- Co-author, “How SEC And NY Cyber Reporting Rules Affect Key Industries,” Law360 (December 2023)
- Co-author, “Chapter 7: Telehealth and digital health privacy regulations,” Diabetes Digital Health and Telehealth (2022)
- Co-author, “Signs Inscribed on a Gate: The Impact of Van Buren v. United States on Civil Claims Under the Computer Fraud and Abuse Act,” Western New England Law Review (2022)
- Co-author, “Consumer Financial Services Answer Book (2022 Edition),” Practising Law Institute (November 2021)
- Co-author, “Cryptojacking: A Real, Economic Threat,” Legaltech News (June 2021)
- Co-author, “Considerations in Machine Learning–Led Programmatic Underwriting,” RAIL: The Journal of Robotics, Artificial Intelligence & Law (May 2021)
- Co-author, “Addressing The Security Risks Of University Foreign Funding,” Law360 (January 2021)
- Co-author, “An Intersection Between Ransomware and U.S. National Security: OFAC Speaks,” Corporate Compliance Insights (October 2020)
- Co-author, “Conducting Internal Investigations During the COVID-19 Pandemic,” Law Journal Newsletters’ Business Crimes Bulletin (March 2020)
- Co-author, “Figuring Out if You Are ‘Doing Business’ in California Under the CCPA,” Bloomberg Law (February 2020)
Matt advises organizations on privacy, cybersecurity, data governance, and artificial intelligence from development and data collection through deployment and data disclosure. His clients include some of the world's most sophisticated data users and data-first companies, spanning technology, financial services, health care, and adtech/martech.
Recognition & Awards
Greater Boston Chamber of Commerce’s Boston’s Future Leaders Program (2014)
Matt advises organizations on privacy, cybersecurity, data governance, and artificial intelligence from development and data collection through deployment and data disclosure. His clients include some of the world's most sophisticated data users and data-first companies, spanning technology, financial services, health care, and adtech/martech.
Involvement
- Book Publishing Board Member, Litigation Section, American Bar Association (2017-2019, 2023-Present)
- Newsletter editor, Class Actions & Derivative Suits Section, American Bar Association (2016-2018)

