Scott T. Lashway
Member / Co-Chair, Privacy & Cybersecurity Practice
+1.617.348.1833
Scott is a globally recognized cybersecurity, privacy, and technology disputes attorney and business advisor. He co-chairs Mintz’s Privacy and Cybersecurity practice. With over 20 years of experience, he counsels clients through high-stakes incident response investigations, complex litigation, crisis management, national security matters, regulatory enforcement, board-level strategy, and emerging legal issues involving data, AI and evolving technologies.
His experience spans matters involving client’s digital ecosystems ranging from data and intellectual property theft and misappropriation, unauthorized access to systems and acquisition of protected data and IP, to ransomware, cyberextortion, and technology misuse, destruction, and disruptions. As a go-to business advisor, Scott provides strategic counsel on the rapid evolution of complex data privacy matters, data governance, data collection and scraping, cyber best practices, and technology innovation navigating complex and novel data and privacy issues in AI and related technology development. Scott dedicates a significant amount of his practice advising c-suites and boards of directors.
Scott is recognized for his depth of knowledge and client service by Chambers Global, Lawdragon, BTI Consulting Incident Response Forum’s leading global 40 cybersecurity attorneys:
“Scott Lashway is a standout in many ways. His client service skills are the best in the business. He’s always responsive and meets our timelines, even when we have last-minute requests and escalated deadlines. He is incredibly knowledgeable and is able to see the big-picture legal risks that might otherwise require multiple attorneys in a variety of disciplines.”
— Client, Legal 500 Cyber Law (including Data Privacy and Data Protection).
Scott represents companies across varied regulated sectors, including in critical infrastructure, health care, financial services, life sciences, media and AdTech, technology, AI and emerging technology, professional services. His regulatory experience includes representing clients before the SEC, DOJ, FINRA, state attorneys general, NYDFS, FDA, FTC, and European data regulators. He has advised on hundreds of privacy and security matters since 2001, with deep expertise in GDPR, CCPA, CPRA, HIPAA, BIPA, NYDFS cybersecurity regulations, the Shield Act, CFAA, and other federal and state laws. He also counsels on compliance with frameworks such as NIST, SOC 2, ISO, and HITRUST. Companies and their officers and directors turn to Scott to represent them in bet-the-company and investigations.
Earlier in Scott’s career, he worked as senior in-house counsel and head of investigations for a Fortune 100 global financial services company. He is a sought-after thought leader, regularly writing and speaking on emerging cybersecurity, privacy, and AI matters.
Scott is a globally recognized cybersecurity, privacy, and technology disputes attorney and business advisor. He co-chairs Mintz’s Privacy and Cybersecurity practice. With over 20 years of experience, he counsels clients through high-stakes incident response investigations, complex litigation, crisis management, national security matters, regulatory enforcement, board-level strategy, and emerging legal issues involving data, AI and evolving technologies.
Experience
Featured Experience:
- Led a team representing a global technology company responding to a sophisticated attack, including advising on complex investigation matters, crisis management and communications, interaction with various U.S. defense and intelligence agencies and the DOJ National Security Division.
- Led a team responding to and investigating a ransomware attack on a global life sciences company, including on multiple threat actor engagements, board matters, litigation mitigation, and crisis management.
- Led a team representing an academic medical center throughout its response to, and investigation of, a widely reported cybersecurity matter, including advising on and managing forensic investigation, crisis communications, litigation defense, regulatory interactions, law enforcement engagement, and all related matters.
- Served as lead counsel for a leading children's hospital, successfully defending allegations in a purported class action that alleged patient data was inappropriately accessed in violation of privacy and security disclosures. The case centered on a novel legal theory that a HIPAA Privacy Notice formed a contractual basis to bring actual and implied breaches of contract, a theory the court summarily rejected after significant oral argument.
- Lead counsel for a global adtech platform company defending claims related to use of its technology to collect and aggregate data, including wiretapping and related claims.
- Represented leading data intelligence company in the investigation of alleged data misappropriation, and then in the subsequent litigation pursuing claims related to theft of proprietary data and intellectual property allegedly used to build a competing AI technology. (West Publishing Corporation v. LegalEase Solutions, LLC (18-cv-01445; D. Minn.)
- Represented a global data and technology company throughout an investigation of, and its response to, simultaneous intrusions by multiple nation-state attackers and various financially motivated threat actors.
Cybersecurity, Data Privacy, Technology-Focused Matters, & Crisis Management
- Represented a health care analytics company and its business associate in its investigation of and response to a reported security compromise and reported breach by a vendor.
- Represented a global life sciences and biotech company in responding to multiple compromises and encryption events, including interaction with threat actors, crisis communications, and litigation mitigation.
- Counseled a health care claims and analytics company responding to and investigating a publicly reported cybersecurity matter from a key professional services vendor providing cybersecurity and privacy-related services, including advising on investigation and reporting obligations to hundreds of downstream vendors.
- Led a team representing a global biotechnology company in investigating and defending against a cyberattack by a sophisticated threat actor. This matter involved extensive interaction with various US agencies and law enforcement.
- Advised various clients on federal and state wiretapping statutes related to website pixels, cookies, tracking technologies, and chatbots. This work has included defending a healthtech provider in federal court litigation concerning alleged wiretapping violations through the deployment of social media pixels on its website, defending a national retailer in litigation regarding alleged wiretapping violations involving the deployment of a leading chatbot on its website, and advising health care companies on complying with recent US Department of Health and Human Services guidance as to the application of the Health Insurance Portability and Accountability Act's (HIPAA) Privacy Rule to website tracking technology.
- Represented a cloud e-commerce platform company in its response to multiple cybersecurity incidents involving alleged credit card data theft and misuse as well as in a privacy class action filed in Delaware.
- Advised a biotechnology and therapeutics company responding to reports of hacking of its patient technology, which entailed an investigation and reporting to the FDA.
- Advised a Big 4 accounting firm on numerous security and privacy matters.
- Represented a health information cloud provider throughout its investigation and remediation of a ransomware attack that encrypted thousands of patient records.
- Advised a global diagnostics and laboratory company on a material joint venture with a pharmaceutical company to develop a global privacy and security framework in compliance with laws from 50+ jurisdictions.
- Counseled a global financial services company on redesigning and rebuilding of its digital forensics and cybersecurity functions to increase the company's efficiency and efficacy in response to disputes, investigations, and compliance risks.
Privacy, Business, and Technology Litigation, Class Actions
- Obtained a defense verdict as first-chair trial counsel for a media company, prevailing on all counts after a multi-week federal court trial involving allegations of violations of intellectual property rights and a Massachusetts consumer protection statute.
- Represented West Publishing Group, a leading legal, business, and regulatory information company, as a plaintiff in federal court litigation alleging the unauthorized taking of protected data through an online portal using a bot, or "data scraper,” for use in developing AI and machine learning technology to compete unfairly.
- Defended Conduent (f/k/a Xerox Services, Inc.), a global data and technology company. in a Delaware Chancery Court action related to data quality and integrity that was brought by a competitor.
- Represented a multimedia company (Christopher Kimball’s Milk Street Kitchen) with an international audience against allegations involving data theft and raiding in a state court litigation, proactively advancing cyber espionage claims against former executives and employees.
- Represented individuals accused in a federal court action of violating the Computer Fraud and Abuse Act and the Stored Communications Act as part of an alleged scheme to clone a state-owned petrochemical company's electronic infrastructure.
- Secured dismissal of a purported class action for a surgical and medical facility in an issue of first impression in the US Court of Appeals for the Eleventh Circuit. The case concerned Article III standing requirements to plead harm in a case brought against a health care facility, which alleged that patient data had been accessed, stolen, and posted on the internet by a well-known threat actor.
- Obtained dismissal on matters of first impression for a global risk intelligence company in a purported class action alleging violation of state law concerning the alleged display of consumers' Social Security numbers. Also secured appellate victories upholding dismissal up to the state's highest court and established jurisdiction of a purported class action in the state's complex business session.
- Secured a complete defense verdict for a multichannel media company after a two-week federal court trial involving allegations of IP rights violations and Massachusetts consumer protection laws.
- Defended numerous clients in lawsuits brought by Atlas Data Privacy Corporation and others asserting violations of New Jersey's Daniel's Law, NJ Statutes section 56:8-166.1, which relates to the privacy of judicial officers and the online publication of data about law enforcement personnel.
- Represented a global pharmacy chain in litigation defending allegations related to alleged Telephone Consumer Protection Act violations.
Internal Investigations, Government Enforcement, and White Collar Defense
- Advising a global medical technology company in its response to multiple subpoenas stemming from a DOJ investigation of third parties' alleged Medicare fraud schemes relating to genetic testing.
- Resolved an SEC enforcement matter and other regulatory inquiries — stemming from allegations of a purported Dodd-Frank Act whistleblower — related to the disclosure of certain variable annuity features on behalf of a life insurance company.
viewpoints
DOJ: ‘False Claims Act + Cybersecurity’ Is Here To Stay
April 3, 2025 | Blog | By Scott Lashway, Karen Lovitch , Matthew Stein
Amid ongoing policy shifts in Washington, the federal government’s interest in pursuing civil cyber-fraud cases appears to be here to stay.
Will New York Be Next to Regulate Specifically Personal Health Information to Further, and Possibly Re-Write, a New Paradigm of State-Level Health Data Regulation?
February 26, 2025 | Blog | By Scott Lashway, Matthew Stein, Cassandra Paolillo, Kayla LaRosa
The following is a summary comparison between the currently passed NY HIPA and WA MHMDA.
US Copyright Office Publishes Second Part of Report on AI Copyrightability — AI: The Washington Report
February 7, 2025 | Article | By Bruce Sokler, Michael Renaud, Scott Lashway, Matthew Tikhonovsky
Read about the second part of the United States Copyright Office’s report on Copyright and Artificial Intelligence, which focuses on the question of how AI affects copyrightability.
Health Care Enforcement Trends & 2025 Outlook
January 17, 2025 | Blog | By Karen Lovitch , Samantha Kingsbury, Keshav Ahuja, Eoin Beirne, Grady Campion, Daniel Cody, Tara E. Dwyer, Laurence Freedman, Hope Foster, Jane Haviland, Nicole Henry, Caitie Hill, Robert Kidwell, Nick A. LaPalme, Scott Lashway, Kevin McGinty, Payton Thornton, Matthew Stein, Rachel Yount
Our 2025 edition of EnforceMintz reflects on health care enforcement trends, predicts how health care enforcement may evolve, and offers practical guidance about what these trends and predictions mean for health care providers, payors, and other stakeholders.
EnforceMintz — Healing Healthcare? DOJ’s Cybersecurity Enforcement Trained Up for 2025
January 16, 2025 | Blog | By Laurence Freedman, Scott Lashway, Matthew Stein
In 2024, the Department of Justice ramped up cybersecurity enforcement under the Civil Cyber-Fraud Initiative (CCFI), targeting entities that failed to safeguard PHI and PII in federally funded contracts. Key cases highlight trends in False Claims Act litigation and underscore the importance of cybersecurity compliance heading into 2025.
String Of Numbers Or Identifier: The Ninth Circuit Weighs In On BIPA’s Application To Non-Users
October 17, 2024 | Blog | By Scott Lashway, Matthew Stein
In June, the U.S. Court of Appeals for the Ninth Circuit affirmed a social media company’s summary judgment win on BIPA claims, in a sophisticated ruling providing a plausible path forward for technology companies and others offering facial matching services.
News & Press
Intellectual Property Ownership Conundrums in Business Transactions
October 24, 2025
Business Law Today highlighted comments from Privacy & Cybersecurity Practice Co-chair Scott Lashway, who spoke on a panel at the American Bar Association Business Law Fall Meeting in September. Discussing the role of intellectual property in business transactions, the panel addressed important considerations for the various types of IP, distinguishing the less concrete “lowercase ip” from the more formalized “uppercase IP.”
Mintz Advises Charlesbank Capital Partners on Acquisition of Q6 Cyber
September 15, 2025
Mintz advised Charlesbank Capital Partners, a middle-market private investment firm, on its acquisition of Q6 Cyber, an intelligence and fraud prevention services provider.
173 Mintz Attorneys Across 53 Practice Areas Recognized by The Best Lawyers in America 2026
August 28, 2025
173 Mintz attorneys across 53 practice areas have been recognized by Best Lawyers® in the 2026 edition of The Best Lawyers in America©. Five Mintz attorneys received 2026 “Lawyer of the Year” awards, and 61 firm attorneys were included in the 2026 edition of Best Lawyers: Ones to Watch.
Mintz has earned top rankings in the 2025 edition of Legal 500 United States and Canada guides. The firm is recognized in 20 practice categories, and 78 of its attorneys are individually ranked in the guide, with several receiving recognition in more than one category. Additionally, two attorneys are featured in the "Hall of Fame," seven attorneys are named "Leading Lawyers," and five attorneys are recognized as a "Next Generation Lawyers."
Chambers USA has recognized 43 of Mintz’s practices and 88 of its attorneys in its 2025 guide to the country’s leading law firms. Of those featured in the guide, 17 attorneys and seven practice areas were awarded Chambers’ highest ranking, Band 1. The firm expanded its rankings this year with three new practice area listings and 17 attorneys recognized for the first time or in additional categories.
Pratt's Privacy and Cybersecurity Report published an article by Privacy & Cybersecurity Practice Co-chair Scott Lashway, Special Counsel Matthew MK Stein, Of Counsel Cassandra Paolillo, and Associate Kayla LaRosa examining the differences between the New York legislature's version of Washington's My Health Data Act and the Washington law. The New York Health Information Privacy Act currently awaits Kathy Hochul’s signature.
Mintz Member Scott Lashway Recognized in Lawdragon’s 2025 List of 500 Top Global Cyber Lawyers
May 12, 2025
Lawdragon named Mintz Member and Privacy & Cybersecurity Co-chair Scott Lashway to its 2025 list of the “500 Leading Global Cyber Lawyers.” The list recognizes “world leaders in privacy, data, security, incident response, and the deals and lawsuits that revolve around all things Cyber.”
Mintz Member Scott Lashway Named to Cybersecurity Docket’s 2025 “Incident Response 50” List
May 08, 2025
Cybersecurity Docket has named Mintz Privacy & Cybersecurity Practice Co-chair, Scott Lashway to its “Incident Response 50” list for 2025. This list recognizes the global best cybersecurity and data breach response lawyers, considered the “first call” for companies that suddenly find themselves the victims of a data breach.
Mintz Increases Global Recognition with New Chambers 2025 Rankings
February 20, 2025
Mintz continues to earn high rankings by Chambers Global, a guide to the top law firms and attorneys worldwide. Four Mintz attorneys and four of the firm’s practices are ranked in the 2025 Chambers Global edition, including two new practice rankings for International Trade: Intellectual Property (Section 337) and Global Multi-Jurisdictional Life Sciences.
Legal Tech's Predictions for Data Privacy in 2025
January 8, 2025
Privacy & Cybersecurity Co-chair Scott Lashway recently provided insights for Legaltech News about his predictions for the data privacy landscape in 2025.
Mintz Announces New Members
December 20, 2024
Mintz announces the election of eight attorneys to Members, effective January 1, 2025. The newly promoted Members join the ranks of the firm’s growing membership, including six new lateral Members who joined the firm in 2024.
Thirteen Mintz attorneys named to Lawdragon’s 2025 “Leading Litigators in America” list
September 12, 2024
Thirteen Mintz attorneys have been named to Lawdragon’s 2025 “Leading Litigators in America.” The list honors the “best litigators the US has to offer – in antitrust, intellectual property, white collar and investigations, securities and corporate governance litigation, and a vast array of class actions, product liability and other complex civil litigation,” according to the publication.
FCA Settlements Demonstrate Importance of Cybersecurity Controls Imposed by Contract
August 20, 2024
Members Scott Lashway, Laurence Freedman, and Special Counsel Matthew Stein published an article in Bloomberg Law about how recent False Claims Act (FCA) settlements show a focus on cybersecurity enforcement. In the article, they outline how organizations with government contracts can mitigate the risk of cybersecurity-related FCA investigations and litigation.
The Best Lawyers in America 2025 Recognizes 184 Mintz Attorneys across 56 Practice Areas
August 15, 2024
187 Mintz attorneys have been recognized by Best Lawyers® in the 2025 edition of The Best Lawyers in America©. Notably, three Mintz attorneys received 2025 “Lawyer of the Year” awards, and 64 firm attorneys were included in the 2025 edition of Best Lawyers: Ones to Watch.
Mintz Privacy & Cybersecurity Chairs Named 2024 Go To Cybersecurity/Data Lawyers by Massachusetts Lawyers Weekly
June 24, 2024
Mintz is pleased to share that Privacy & Cybersecurity Practice Chairs Cynthia Larose and Co-chair Scott Lashway have been named 2024 Go To Cybersecurity/Data Lawyers by Massachusetts Lawyers Weekly. The award recognizes top cybersecurity/data lawyers across the Commonwealth who demonstrate significant leadership in the field with a record of success, and to whom other lawyers make referrals for their expertise and accomplishment.
Mintz announced today that 42 of its practices and 83 of its attorneys earned recognition in the 2024 edition of Chambers USA, a guide to the country’s leading law firms. Of those included in the guide, 18 attorneys and seven practice areas were awarded Chambers’ highest ranking, Band 1. The firm obtained new listings in three practice areas and 10 of its lawyers were recognized for the first time.
The Boston Business Journal covered the arrival of Members Scott Lashway and Chris Lisy to the firm’s Data & Privacy Litigation and Investigations Practice. Scott will serve as the Co-chair of the Privacy & Cybersecurity practice.
Mintz announces that two new Members, Scott Lashway and Chris Lisy, have joined the firm’s Boston office in its Data & Privacy Litigation and Investigations Practice.
The arrival of Members Scott Lashway and Chris Lisy to Mintz’s Data & Privacy Litigation and Investigations Practice was detailed in Law360.
The American Lawyer detailed the arrival of Privacy & Cybersecurity Co-chair Scott Lashway and Member Chris Lisy to Mintz’s Boston office.
Events & Speaking
Mintz's Annual Employment Law Summit 2025 - New York
Convene, 601 Lexington Ave, New York, NY 10022
Data Privacy Compliance: Pre-Attack Risk Mitigation and Post-Attack Best Practices
Incident Response Forum Masterclass 2025
Four Seasons Hotel, Washington, D.C.
Tales of Cloud Compromise: Lessons from Recent Mandiant Investigations
Google Cloud Next 2025
Mandalay Bay Convention Center, Las Vegas
Governance - Building Blocks for AI
Argyle AI Decision Makers Summit: Shaping the Future of Business
Understanding Business Email Compromise Fraud and Its Legal Fallout
Hosted by the Boston Bar Association
16 Beacon Street, Boston, MA 02108
Publications
- Author, "Massachusetts' march to comprehensive privacy legislation: an end-of-year update,” Massachusetts Lawyers Weekly (January 2024)
- Co-author, "How SEC And NY Cyber Reporting Rules Affect Key Industries," Law360 (December 2023)
- Co-author, "Navigating the HIPAA Risks of Website Trackers,” Privacy and Cybersecurity Law Report (June 2023)
- Co-author, "Chapter 7: Telehealth and digital health privacy regulations,” Diabetes Digital Health and Telehealth (2022)
- Co-author, "Signs Inscribed on a Gate: The Impact of Van Buren v. United States on Civil Claims Under the Computer Fraud and Abuse Act,” Western New England Law Review (2022)
- Co-author, "Data — and data protection — is key to digital strategies,” Sports Business Journal (November 2021)
- Co-author, "Considerations in Machine Learning-Led Programmatic Underwriting,” Rail: The Journal of Robotics, Artificial Intelligence & Law, Volume 4, No. 4 (May 2021)
- Co-author, "Addressing The Security Risks Of University Foreign Funding,” Law360 (January 2021)
- Co-author, "The California Privacy Rights Act Has Passed: What's In It?," Pratt's Privacy & Cybersecurity Law Report (November/December 2020)
- Co-author, "An Intersection Between Ransomware and U.S. National Security: OFAC Speaks,” Corporate Compliance Insights (October 2020)
- Co-author, "Conducting Internal Investigations During the COVID-19 Pandemic,” Law Journal Newsletters' Business Crimes Bulletin (March 2020)
- Co-author, " COVID-19: Evolving Cybersecurity Considerations for Business,” Corporate Compliance Insights (March 2020)
- Co-author, "6 Changes In California's New Draft Privacy Regulations,” Law360 (March 2020)
Scott is a globally recognized cybersecurity, privacy, and technology disputes attorney and business advisor. He co-chairs Mintz’s Privacy and Cybersecurity practice. With over 20 years of experience, he counsels clients through high-stakes incident response investigations, complex litigation, crisis management, national security matters, regulatory enforcement, board-level strategy, and emerging legal issues involving data, AI and evolving technologies.
Recognition & Awards
Chambers USA: Nationwide: Privacy & Data Security: Litigation (2025)
Chambers Global: Privacy & Data Security: Healthcare (2024-2025)
Chambers USA: Privacy & Data Security: Healthcare – National (2023-2025)
Cybersecurity Docket: Incident Response 40 (2022, 2023, 2024, 2025)
Lawdragon: “500 Leading Litigators in America” (2022 and 2024-2026)
Lawdragon: 500 Leading Global Cyber Lawyers (2025, inaugural list)
BTI Consulting: Client Service Super All-Star (2022)
Massachusetts Lawyers Weekly: Go-To Lawyers: Cybersecurity and Data Privacy (2022, 2024)
Best Lawyers in America: Privacy and Data Security Law (2021– 2026)
Best Lawyers in America: Commercial Litigation (2023 – 2024)
Massachusetts Supreme Judicial Court – Pro Bono Honor Roll (2020)
Scott is a globally recognized cybersecurity, privacy, and technology disputes attorney and business advisor. He co-chairs Mintz’s Privacy and Cybersecurity practice. With over 20 years of experience, he counsels clients through high-stakes incident response investigations, complex litigation, crisis management, national security matters, regulatory enforcement, board-level strategy, and emerging legal issues involving data, AI and evolving technologies.
Involvement
- Advisory Council, Woods College of Advancing Studies, Cybersecurity and Governance Master’s Program, Boston College (2017 – present)
- Advisory Council, New England Legal Foundation (2016 – present)
- Board Member, New England Legal Foundation (2015 – 2016)
- Member, Cybersecurity & Privacy Editorial Advisory Board, Law360
- Member, Board of Advisors, Boston Symphony Orchestra

