Sarah Cronan Spurlock

Sarah Cronan Spurlock is a member of the firm’s Health Care Service Group and is Co-Chair of the firm’s Privacy & Data Security Group. Sarah regularly advises clients on a wide range of health care and privacy matters, including fraud and abuse laws, physician and hospital contracting, information privacy and security laws, and data breach prevention and response. Her practice includes regulatory and transactional matters and health care litigation. Sarah is a Certified Information Privacy Professional (CIPP/US) and serves as the firm’s Chief Privacy Officer.

Recent News, Articles & Speaking Engagements

Under Attack: Ransomware Threats, Prevention Tips, and Response Strategy for Health Care Providers

Revenue Cycle and Compliance Summit, First Healthcare Compliance, June 23, 2022

Help! They've Hijacked Our Network and They Want Money - Now What? Strategies for Managing the Cyber-Attack

Moderator, IADC 2021 Annual Meeting, August 15-19, 2021

Data Privacy Day: Scanning Data Privacy Issues for 2021

Liberating Patient Data – Is Your Hospital Ready for the Information Blocking Rule?

Webinar, Kentucky Hospital Association, January 26, 2021

Not Your Grandma’s Quilt: Exploring the Current ‘Patchwork’ and Recent Trends in U.S. Data Privacy and Security Laws

Kentucky Bar Association Corporate House Counsel Webinar, November 18, 2020

Medical Liability Considerations for Physicians

Kentucky Medical Association Virtual Town Hall, September 24, 2020

Eliminating Kickbacks in Recovery Act

Kentucky Health Law Institute, UK CLE, September 2, 2020

The Future of Medicine for the Emerging Physician post COVID-19

Kentucky Medical Association Virtual Annual Meeting, August 22, 2020

Is Telehealth Here to Stay?

Medical News, June 30, 2020

OSHA Revises COVID-19 Guidance

Privacy 2020 – California’s Seismic Shift

Discussion of the California Consumer Privacy Act (CCPA), Southern Law Network, April 16, 2020

Information You Need on the COVID-19 Coronavirus

Shifting Sands of U.S. Privacy Laws

International Association of Defense Counsel Webinar, December 11, 2019

No-fault insurance in Kentucky

Cybersecurity and Data Breach Response for Lawyers: Threats, Prevention Tips, and Mitigation Strategies for Lessening the Risks of a Cyberattack

Kentucky Bar Association Annual Convention, June 12, 2019

The Race to Privacy

Stites & Harbsion Thirsty Thursday Speaker Series, April 25, 2019

Cyber Security for Rural and Critical Access Hospitals: Tips for Improving Data Security and Mitigating the Impact of a Cyber Attack

Alliant Management Services Management Meeting, April 10, 2019

Introduction to Health Law

Panel member, Health Enterprise Network Healthcare Fellows, University of Louisville Louis D. Brandies School of Law, March 19, 2019

Taking Stock of Your 2019 Cybersecurity Resolutions

Pings That Go Bump in the Night: A Discussion of Health Care, Cybersecurity Threats, Prevention Tips and Mitigation Tactics

Moderator and Panelist, 2018 Kentucky Health Law Institute, Lexington, KY, September 14, 2018

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-17, 2018

Employment Contracting Seminar

Kentucky Medical Association, Louisville, Ky., January 27, 2018

Leadership in Action: Take the Lead in Solving the Opioid Epidemic

2017 Kentucky Medical Association Annual Meeting, Louisville, KY, August 25, 2017

Cyber Threats & Ransomware

Kentucky Academy of Hospital Attorneys, Kentucky Hospital Association Annual Convention, May 29, 2017

Digital Fortress

Modern Steel Construction, May 2017

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-16, 2017

Cybersecurity for business: Improving data security and mitigating the impact of a cyber-attack

Kentucky Society of CPAs Spring Business Conference, Louisville, KY, April 20, 2017

Be Cyberwise: Protect & Position Your Business for Growth

Ohio River Valley Women's Business Council, 2017 Catch the Wave Conference, April 18, 2017

The Interplay Between Social Media and Healthcare Privacy

American Bar Association Regional CLE, Brave New World: Emerging Cyber and Electronic Issues in Health Care Litigation, March 31, 2017

Improving Data Security and Mitigating the Impact of a Cyber-Attack

Kentucky Medical Group Management Association Spring Conference, March 16, 2017

Under Attack: Cyber Threats Against the Health Care Industry

presentation, Kentucky Health Law Institute, September 15, 2016

Passwords, Revisited

The Goods, Kentucky Association of Manufacturers, September 2016

Build a Better Machine

Residents in Business

faculty panel, University of Louisville School of Medicine and Greater Louisville Medical Society, May 24-26, 2016

Stop. Think. Connect.

presentation, Stites & Harbison Summer Associate Program, May 16, 2016

Law Firm Data Security: It's the End of the World As We Know It (And I Don't Feel Fine)

presentation, Southern Law Network, Louisville, Kentucky, May 13, 2016

Don't Bet on Longshots - Practical Advice on Data Security for Financial Institutions

Stites & Harbison Creditors' Rights & Bankruptcy Service Group Day at the Races, Keeneland, April 14, 2016

Identifying and Protecting Your Core Data

The Goods (p.36), Kentucky Association of Manufacturers, March 2016

Data Breaching Now Its Own Industry

by Robert Hadley, The Lane Report, December 8, 2015

Data Breaches: Is Your Attitude about Data Security Putting You and Your Company at Risk?

The Goods (p. 16), Kentucky Association of Manufacturers, November 2015

Employee Attitudes Fuel Your Data Security Plan

Legaltech News, October 29, 2015

Are you ready for a HIPAA Audit?

Kentucky Association of Health Care Facilities Webinar, October 21, 2015

Technology Highlights for the Restructuring Professional: Privacy, Data Security & Electronic Discovery

co-presenter, International Women's Insolvency & Restructuring Confederation (IWIRC) Day at Keeneland, October 9, 2015

Prevention and Response: Is Your Business Prepared for a Data Security Breach?

Stites & Harbison, PLLC Thirsty Thursday networking event, May 21, 2015

Is your attitude about data security putting you and your company at risk?

Professional Insight, Business First of Louisville, March 27, 2015

Hot Topics in the Area of Health Law Privacy

Kentucky Health Law Institute, Novemer 7, 2013

HIPAA Wants You

Final Rule Amending HIPAA Regulations

Physician Employment Contracting Symposium

co-presenter, Kentucky Medical Association, November 3, 2012

Turning up the heat on HIPAA compliance: What to expect from increase enforcement and Office for Civil Rights audits

co-author, Louisville Bar Association's Bar Briefs, November 2012

HIPAA Update for Physician Office Managers

Kentucky Pediatric Office Managers Association, October 11, 2012

Stolen laptop leads to $1.5 million HIPAA settlement

HIPAA and HITECH's Impact on Certified Public Accountants

Kentucky Society of CPAs Healthcare Conference, May 16, 2012

Keeping up with technology demands: Delayed deadlines for Meaningful Use and ICD-10 reflect overburdened healthcare providers

Medical News, April 2012

HIPAA Audits and Investigations - What to expect when the Office for Civil Rights comes knocking

Louisville Bar Association, Health Law Section, April 11, 2012

Make Way for Medicaid Managed Care: What to expect as Kentucky departs from traditional fee-for-service reimbursement in favor of managed care for Medicaid recipients across the Commonwealth

Louisville Bar Association's Bar Briefs, November 2011

HITECH Challenges for Physicians: Keeping Up with Changes to Health Information Privacy and Security Rules in an Expanding Electronic Environment

Kentucky Medical Association, August 23, 2011

HIPAA and Social Media Issues for Employers, Hot Topics and Critical Issues Pertinent to Employers and Health Care Providers

Health Law and Labor & Employment Sections, Louisville Bar Association, June 2, 2011

HITECH's Amendments to HIPAA: Recent Changes to Health Information Privacy and Security Rules and their Impact on State Regulatory Investigations

National Board for Certification in Occupational Therapy, Annual Conference on Occupational Therapy State Regulation, October 23, 2010

HIPAA Update for Employers

Society of Human Resources Management Mid-West Kentucky Chapter, Madisonville, Ky., April 2010

How will the HITECH Act affect your law firm?

Louisville Bar Association, Health Law Section, April 28, 2010


The Regional Medical Center of Hopkins County, Madisonville, Ky., March 2010

Current Trend: Employment of Physicians by Hospitals

2010 Health Law and Compliance Update 1-2 (John Steiner ed., 2010)

Grounding Cyberspeech: Public Schools' Authority to Discipline Students for Internet Activity

97 Kentucky Law Journal 149 (2008)
Recent Assignments
Bar Admissions
Firm Leadership

Chief Privacy Officer

Privacy & Data Security Practice Group, Co-Chair

Office of General Counsel, as Chief Privacy Officer

American Bar Association, Health Law Section
Kentucky Bar Association
Louisville Bar Association, Health Law Section, Chair (2011)
American Health Lawyers Association
International Association of Privacy Professionals
International Association of Defense Counsel, Cyber Security, Data Privacy and Technology Committee, Chair
Community Involvement

Yew Dell Botanical Gardens, Board of Directors (2018-present)

Louisville Legal Aid Society, Volunteer (2009-16)

Sisters of Charity of Nazareth, Inc., Board of Directors (2011-16)

Focus Louisville, February 2016 Class

More Than Stites & Harbison

Sarah joined Stites & Harbison in September of 2009 after participating in the firm's summer associate program in 2008. In the summer of 2007, she worked in the legal department at Brown-Forman Corporation in Louisville. Before law school, Sarah lived in New York City where she worked at Friedman, Wang & Bleiberg, P.C. as a paralegal, and Lehman Brothers, Inc. in human resources supporting the information technology division.

Sarah is an accomplished equestrian and enjoys riding American Saddlebred horses in her free time.


Best Lawyers in America®, Health Care Law (2019-22)

Business First of Louisville, 20 People to Know in Law (2018)

Business First of Louisville, Partners in Health Care People to Watch (2014)

Spurlock Best Lawyers 2022
Cipp Seal Hires Small
Iadc Member Logo Color Sm
See more related to Sarah Cronan Spurlock

Revenue Cycle and Compliance Summit

Date: 6/23/22
Time: 12:00 p.m. - 4:30 p.m.

Online Event

The Revenue Cycle and Compliance Summit is an online half-day workshop to provide convenient education with CEUs and CLE for professionals. Stites attorneys Sarah Spurlock and Michael Denbow will be presenters at this Summit on June. 23, 2022.

Michael Denbow and Sarah Cronan Spurlock May 13, 2022

U.S. Privacy And Data Security Developments - Where Do We Go From Here?

Sara Spurlock and Mari-Elise Paul discuss U.S. Privacy Laws, FTC Enforcement and The COVID effect in this Mondaq Webinar.

by Mari-Elise Paul and Sarah Cronan Spurlock January 07, 2022
Press Releases

Stites & Harbison, PLLC Lawyers Named to 2022 Best Lawyers® Publications

LOUISVILLE, Ky.—Stites & Harbison, PLLC is pleased to announce that 93 lawyers are included in the 2022 Edition of The Best Lawyers in America©. Since it was first published in 1983, Best Lawyers® has become universally regarded as the definitive guide to legal excellence. Additionally, 11 attorneys are named as “Lawyer of the Year” and 14 attorneys are recognized in “Best Lawyers: Ones to Watch,” which recognizes attorneys early in their careers for outstanding professional excellence in private practice in the United States.

by Stites & Harbison, PLLC September 01, 2021

IADC 2021 Annual Meeting

Date: 8/15/21 - 8/19/21

Fairmont Chicago, Chicago, Illinois

Please join the IADC in Chicago for it's first in-person meeting in 18 months! Louisville office Sarah Spurlock with be a speaker at the event on August 15, 2021.

Sarah Cronan Spurlock July 30, 2021
Client Alerts

“No Company is Safe” — White House Urges Private Sector to Act Now in Hardening Defenses Against Growing Ransomware Threats

Following the most recent slew of high-profile ransomware attacks, the White House deputy national security adviser for cyber and emerging technology, Anne Neuberger, issued an open letter to the private sector urging action to increase cyber defenses to match the nation’s increasing ransomware threat.

by Sarah Cronan Spurlock June 10, 2021

U.S. Privacy and Data Security Developments - Where Do We Go From Here?

Stites & Harbison attorneys Sarah Cronan Spurlock and Mari-Elise Paul discuss U.S. Privacy Laws, FTC Enforcement and The Covid Effect in this Webinar presented by Mondaq.

by Sarah Cronan Spurlock and Mari-Elise Paul June 08, 2021

U.S. Privacy and Data Security Developments - Where Do We Go From Here?

Date: 6/3/21
Time: 10:00 a.m. - 11:00 a.m.


On June 3, 2021 at 10:00 EST, Mondaq will be hosting a webinar featuring Stites & Harbison attorneys, Sarah Cronan Spurlock and Mari-Elise Paul discussing U.S. privacy and data security developments.

Sarah Cronan Spurlock and Mari-Elise Paul May 14, 2021
Client Alerts

Data Privacy Day: Scanning Data Privacy Issues for 2021

Every January 28, the United States, Canada, and 27 countries of the European Union celebrate Data Privacy Day, which is an international effort to create awareness about the importance of safeguarding data and respecting privacy.

by Mari-Elise Paul, Sarah Cronan Spurlock, and Alexandra MacKay January 29, 2021