Sarah Cronan Spurlock

Sarah Cronan Spurlock is a member of the firm’s Health Care Service Group and is Co-Chair of the firm’s Privacy & Data Security Group. Sarah regularly advises clients on a wide range of health care and privacy matters, including fraud and abuse laws, physician and hospital contracting, information privacy and security laws, and data breach prevention and response. Her practice includes regulatory and transactional matters and health care litigation. Sarah is a Certified Information Privacy Professional (CIPP/US) and serves as the firm’s Chief Privacy Officer.

Recent News, Articles & Speaking Engagements

Help! They've Hijacked Our Network and They Want Money - Now What? Strategies for Managing the Cyber-Attack

Moderator, IADC 2021 Annual Meeting, August 15-19, 2021

Data Privacy Day: Scanning Data Privacy Issues for 2021

Liberating Patient Data – Is Your Hospital Ready for the Information Blocking Rule?

Webinar, Kentucky Hospital Association, January 26, 2021

Not Your Grandma’s Quilt: Exploring the Current ‘Patchwork’ and Recent Trends in U.S. Data Privacy and Security Laws

Kentucky Bar Association Corporate House Counsel Webinar, November 18, 2020

Medical Liability Considerations for Physicians

Kentucky Medical Association Virtual Town Hall, September 24, 2020

Eliminating Kickbacks in Recovery Act

Kentucky Health Law Institute, UK CLE, September 2, 2020

The Future of Medicine for the Emerging Physician post COVID-19

Kentucky Medical Association Virtual Annual Meeting, August 22, 2020

Is Telehealth Here to Stay?

Medical News, June 30, 2020

OSHA Revises COVID-19 Guidance

Privacy 2020 – California’s Seismic Shift

Discussion of the California Consumer Privacy Act (CCPA), Southern Law Network, April 16, 2020

Information You Need on the COVID-19 Coronavirus

Shifting Sands of U.S. Privacy Laws

International Association of Defense Counsel Webinar, December 11, 2019

No-fault insurance in Kentucky

Cybersecurity and Data Breach Response for Lawyers: Threats, Prevention Tips, and Mitigation Strategies for Lessening the Risks of a Cyberattack

Kentucky Bar Association Annual Convention, June 12, 2019

The Race to Privacy

Stites & Harbsion Thirsty Thursday Speaker Series, April 25, 2019

Cyber Security for Rural and Critical Access Hospitals: Tips for Improving Data Security and Mitigating the Impact of a Cyber Attack

Alliant Management Services Management Meeting, April 10, 2019

Introduction to Health Law

Panel member, Health Enterprise Network Healthcare Fellows, University of Louisville Louis D. Brandies School of Law, March 19, 2019

Taking Stock of Your 2019 Cybersecurity Resolutions

Pings That Go Bump in the Night: A Discussion of Health Care, Cybersecurity Threats, Prevention Tips and Mitigation Tactics

Moderator and Panelist, 2018 Kentucky Health Law Institute, Lexington, KY, September 14, 2018

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-17, 2018

Employment Contracting Seminar

Kentucky Medical Association, Louisville, Ky., January 27, 2018

Leadership in Action: Take the Lead in Solving the Opioid Epidemic

2017 Kentucky Medical Association Annual Meeting, Louisville, KY, August 25, 2017

Cyber Threats & Ransomware

Kentucky Academy of Hospital Attorneys, Kentucky Hospital Association Annual Convention, May 29, 2017

Digital Fortress

Modern Steel Construction, May 2017

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-16, 2017

Cybersecurity for business: Improving data security and mitigating the impact of a cyber-attack

Kentucky Society of CPAs Spring Business Conference, Louisville, KY, April 20, 2017

Be Cyberwise: Protect & Position Your Business for Growth

Ohio River Valley Women's Business Council, 2017 Catch the Wave Conference, April 18, 2017

The Interplay Between Social Media and Healthcare Privacy

American Bar Association Regional CLE, Brave New World: Emerging Cyber and Electronic Issues in Health Care Litigation, March 31, 2017

Improving Data Security and Mitigating the Impact of a Cyber-Attack

Kentucky Medical Group Management Association Spring Conference, March 16, 2017

Under Attack: Cyber Threats Against the Health Care Industry

presentation, Kentucky Health Law Institute, September 15, 2016

Passwords, Revisited

The Goods, Kentucky Association of Manufacturers, September 2016

Build a Better Machine

Residents in Business

faculty panel, University of Louisville School of Medicine and Greater Louisville Medical Society, May 24-26, 2016

Stop. Think. Connect.

presentation, Stites & Harbison Summer Associate Program, May 16, 2016

Law Firm Data Security: It's the End of the World As We Know It (And I Don't Feel Fine)

presentation, Southern Law Network, Louisville, Kentucky, May 13, 2016

Don't Bet on Longshots - Practical Advice on Data Security for Financial Institutions

Stites & Harbison Creditors' Rights & Bankruptcy Service Group Day at the Races, Keeneland, April 14, 2016

Identifying and Protecting Your Core Data

The Goods (p.36), Kentucky Association of Manufacturers, March 2016

Data Breaching Now Its Own Industry

by Robert Hadley, The Lane Report, December 8, 2015

Data Breaches: Is Your Attitude about Data Security Putting You and Your Company at Risk?

The Goods (p. 16), Kentucky Association of Manufacturers, November 2015

Employee Attitudes Fuel Your Data Security Plan

Legaltech News, October 29, 2015

Are you ready for a HIPAA Audit?

Kentucky Association of Health Care Facilities Webinar, October 21, 2015

Technology Highlights for the Restructuring Professional: Privacy, Data Security & Electronic Discovery

co-presenter, International Women's Insolvency & Restructuring Confederation (IWIRC) Day at Keeneland, October 9, 2015

Prevention and Response: Is Your Business Prepared for a Data Security Breach?

Stites & Harbison, PLLC Thirsty Thursday networking event, May 21, 2015

Is your attitude about data security putting you and your company at risk?

Professional Insight, Business First of Louisville, March 27, 2015

Hot Topics in the Area of Health Law Privacy

Kentucky Health Law Institute, Novemer 7, 2013

HIPAA Wants You

Final Rule Amending HIPAA Regulations

Physician Employment Contracting Symposium

co-presenter, Kentucky Medical Association, November 3, 2012

Turning up the heat on HIPAA compliance: What to expect from increase enforcement and Office for Civil Rights audits

co-author, Louisville Bar Association's Bar Briefs, November 2012

HIPAA Update for Physician Office Managers

Kentucky Pediatric Office Managers Association, October 11, 2012

Stolen laptop leads to $1.5 million HIPAA settlement

HIPAA and HITECH's Impact on Certified Public Accountants

Kentucky Society of CPAs Healthcare Conference, May 16, 2012

Keeping up with technology demands: Delayed deadlines for Meaningful Use and ICD-10 reflect overburdened healthcare providers

Medical News, April 2012

HIPAA Audits and Investigations - What to expect when the Office for Civil Rights comes knocking

Louisville Bar Association, Health Law Section, April 11, 2012

Make Way for Medicaid Managed Care: What to expect as Kentucky departs from traditional fee-for-service reimbursement in favor of managed care for Medicaid recipients across the Commonwealth

Louisville Bar Association's Bar Briefs, November 2011

HITECH Challenges for Physicians: Keeping Up with Changes to Health Information Privacy and Security Rules in an Expanding Electronic Environment

Kentucky Medical Association, August 23, 2011

HIPAA and Social Media Issues for Employers, Hot Topics and Critical Issues Pertinent to Employers and Health Care Providers

Health Law and Labor & Employment Sections, Louisville Bar Association, June 2, 2011

HITECH's Amendments to HIPAA: Recent Changes to Health Information Privacy and Security Rules and their Impact on State Regulatory Investigations

National Board for Certification in Occupational Therapy, Annual Conference on Occupational Therapy State Regulation, October 23, 2010

HIPAA Update for Employers

Society of Human Resources Management Mid-West Kentucky Chapter, Madisonville, Ky., April 2010

How will the HITECH Act affect your law firm?

Louisville Bar Association, Health Law Section, April 28, 2010


The Regional Medical Center of Hopkins County, Madisonville, Ky., March 2010

Current Trend: Employment of Physicians by Hospitals

2010 Health Law and Compliance Update 1-2 (John Steiner ed., 2010)

Grounding Cyberspeech: Public Schools' Authority to Discipline Students for Internet Activity

97 Kentucky Law Journal 149 (2008)
Recent Assignments
Bar Admissions
Firm Leadership

Chief Privacy Officer

Privacy & Data Security Practice Group, Co-Chair

American Bar Association, Health Law Section
Kentucky Bar Association
Louisville Bar Association, Health Law Section, Chair (2011)
American Health Lawyers Association
International Association of Privacy Professionals
International Association of Defense Counsel, Cyber Security, Data Privacy and Technology Committee, Chair
Community Involvement

Yew Dell Botanical Gardens, Board of Directors (2018-present)

Louisville Legal Aid Society, Volunteer (2009-16)

Sisters of Charity of Nazareth, Inc., Board of Directors (2011-16)

Focus Louisville, February 2016 Class

More Than Stites & Harbison

Sarah joined Stites & Harbison in September of 2009 after participating in the firm's summer associate program in 2008. In the summer of 2007, she worked in the legal department at Brown-Forman Corporation in Louisville. Before law school, Sarah lived in New York City where she worked at Friedman, Wang & Bleiberg, P.C. as a paralegal, and Lehman Brothers, Inc. in human resources supporting the information technology division.

Sarah is an accomplished equestrian and enjoys riding American Saddlebred horses in her free time.


Best Lawyers in America®, Health Care Law (2019-22)

Business First of Louisville, 20 People to Know in Law (2018)

Business First of Louisville, Partners in Health Care People to Watch (2014)

Spurlock Best Lawyers 2022
Cipp Seal Hires Small
Iadc Member Logo Color Sm
See more related to Sarah Cronan Spurlock