Sara guides organizations through their data privacy and security incident response obligations under U.S. state and federal law, regulatory requirements, and contractual commitments with third parties. She collaborates closely with key vendors in the incident response industry to determine the scope and scale of an incident, verify containment, and support the organization in mitigating its operational, financial, and reputational risks.
Sara’s experience covers the spectrum of data incidents, from system-wide network intrusions and ransomware attacks to cyber extortion, fraudulent wire transfers, e-mail account compromises, stolen computers, and employee misconduct. Sara serves a broad range of private- and public-sector clients in multiple industry verticals, including banking and financial services, health care, not-for-profit and for-profit education, e-commerce, technology, retail, manufacturing, state and local government, accounting, legal, and other professional services.
Sara is highly knowledgeable of and counsels clients on compliance with the wide range of U.S. data privacy and information security laws, including the Health Insurance Portability and Accountability Act (HIPAA), the Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act), the Children’s Online Privacy Protection Rule (COPPA), the Biometric Information Privacy Act (BIPA), and comprehensive state privacy laws such as the California Consumer Privacy Act (CCPA). She also advises clients on international data protection requirements, particularly the EU’s General Data Protection Regulation (GDPR).