WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Pro Bono
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
HHS Announces New Director of Office for Civil Rights: What to Watch from the New Health Privacy Leader
Alerts
June 11, 2025

On June 4, 2025, the U.S. Department of Health and Human Services (HHS) announced the appointment of Paula M. Stannard as the Director of the Office for Civil Rights (OCR). As Director, Stannard will lead the enforcement of the Privacy, Security, and Breach Notification Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as federal civil rights laws.

Director Stannard has an extensive background in healthcare regulation and public service at the state and federal levels. She served in HHS as Senior Counselor and Advisor to former HHS Secretaries Tom Price and Alex Azar during the Trump Administration, and as the Department’s Acting General Counsel and Deputy General Counsel during the Bush Administration. Notably, during the Bush Administration, Director Stannard played a key role in revising the original HIPAA Privacy Rule.

Given Director Stannard’s background in HHS policy, she is likely to support enforcing HHS policies that she helped bring to life. As Director Stannard begins her new role, she will likely address four key issues: i) the future of the proposed HIPAA Security Rule, ii) the use of artificial intelligence (AI) by HIPAA-covered entities and business associates, iii) the use of patient care decision support tools, and iv) the use of advertising technologies by digital health companies.

Proposed HIPAA Security Rule Modifications

The agency is considering significant proposed modifications to the HIPAA Security Rule, which were released under the Biden Administration. As discussed in a prior Wilson Sonsini alert, OCR published a proposed rule in January 2025 that would strengthen the security of electronic protected health information (ePHI) in response to emerging threats and technologies. Public comments to the proposed rule closed in March 2025. Eight industry associations co-signed a letter to President Trump calling for the proposed update to be rescinded. Representatives of the Administration have noted that HHS is reviewing comments carefully and will consider next steps. Director Stannard is likely to play a key role in this process.

Artificial Intelligence

With respect to the use of AI, OCR indicated in its proposed amendments to the HIPAA Security Rule that ePHI in AI training data, prediction models, and algorithm data that is maintained by a regulated entity for covered functions is protected by the HIPAA rules; and advised regulated entities to incorporate the use of AI tools in its risk analyses.

Patient Care Decision Support Tools

In May 2025, OCR published a final rule to implement Section 1557 of the Affordable Care Act, which, among other things, prohibits discrimination in the use of automated or non-automated patient care decision support tools. OCR indicated in the final rule that these tools include AI used to support clinical decision-making. Under the final rule, covered entities must make reasonable efforts to identify uses of patient care decision support tools that consider race, color, national origin, sex, age, or disability; and mitigate the risk of discrimination resulting from the tools’ use of such information.

Advertising Technologies

Finally, companies should watch for whether OCR, under Director Stannard, will take a position on the use of third-party online tracking technologies by HIPAA-covered entities on unauthenticated websites. As analyzed in a prior Wilson Sonsini alert, in December 2022, OCR issued guidance that would have restricted HIPAA-covered entities’ and business associates’ use of online tracking technologies not only on authenticated websites like patient portals, but also on unauthenticated websites (e.g., consumer facing websites). However, the U.S. District Court for the Northern District of Texas partially vacated the guidance in June 2024, reasoning that the agency overreached its authority by redefining the definition of “protected health information” under HIPAA. The guidance document indicates that HHS is evaluating its next steps in light of the district court’s order.

Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex privacy and data security issues. If you have any questions or need assistance with HIPAA compliance, please do not hesitate to contact Maneesha Mithal, Jodi Daniel, Tracy Shapiro, Haley Bavasi, Hale Melnick, or any other member of our Data, Privacy, and Cybersecurity practice.

Taylor Stenberg Erb contributed to the preparation of this alert.

Contributors

  • Jodi Daniel
  • Maneesha Mithal
  • Tracy Shapiro
  • Hale Melnick
  • Taylor Stenberg Erb
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.