Sarah Cronan Spurlock

Sarah Cronan Spurlock is a member of the firm’s Health Care Service Group and is Co-Chair of the firm’s Privacy & Data Security Group. Sarah regularly advises clients on a wide range of health care issues, including fraud and abuse laws, compliance guidance, physician self-referral, physician employment agreements, physician and hospital contracting, technology and general contracting, HIPAA privacy and security, and data breach prevention and response. Her practice includes regulatory and transactional matters and health care litigation. Sarah is a Certified Information Privacy Professional (CIPP/US) and serves as the firm’s Chief Privacy Officer.

Recent News, Articles & Speaking Engagements

Tips for Defending Against Data Breach Litigation in the US and Abroad

co-speaker, International Association of Defense Counsel (IADC) 2024 Annual Meeting, July 6-11, 2024

The Cost of Third-Party Data Breaches: How to Avoid a Financial Disaster

co-speaker, The Knowledge Group Webinar, June 14, 2024

AI in Health Care: Navigating Growth, Risks and Implementation

Kentucky Hospital Association Annual Convention, May 20-22, 2024

Framework debate shows as Kentucky nears comprehensive privacy law

by Joseph Duball, International Association of Privacy Professionals (IAPP), The Privacy Advisor, March 12, 2024

Mitigating Hospital Cyber Risks - Ransomware’s Impact on Operations and Outcomes

Cybersecurity Crisis Management: Strategies for Health Care Professionals, Kentucky Hospital Association, January 23, 2024

Artificial Intelligence in Healthcare

Stites & Harbison Client Event, November 2, 2023

Cybersecurity: The Rising Cost of Cyber Threats

by Shannon Clinton, The Lane Report, September 25, 2023

Cybersecurity: The Rising Cost of Cyber Threats

by Shannon Clinton,, September 2023

Mitigating Hospital Cyber Risks - Ransomware’s Impact on Operations and Outcomes

Kentucky Hospital Association 94th Annual Convention, Lexington, KY, May 15-17, 2023

Kentucky Lawmakers Considering Comprehensive Data Privacy Legislation

Ransomware Threats: Prevention Tips and Response Strategies

panelist, American Bar Association, Infrastructure and Regulated Industries Section Webinar, February 28, 2023

Incident Preparedness: Developing a Program to Respond to Security Incidents

Speaker, Data Security and Privacy Symposium, Atlanta, February 8, 2023

Patient Inducement Prohibitions: Anti-Kickback and Civil Monetary Penalty Considerations

Kentucky Primary Care Association Annual Conference, October 11, 2022

Under Attack: Ransomware Threats, Prevention Tips, and Response Strategy for Health Care Providers

Revenue Cycle and Compliance Summit, First Healthcare Compliance, June 23, 2022

Help! They've Hijacked Our Network and They Want Money - Now What? Strategies for Managing the Cyber-Attack

Moderator, IADC 2021 Annual Meeting, August 15-19, 2021

Data Privacy Day: Scanning Data Privacy Issues for 2021

Liberating Patient Data – Is Your Hospital Ready for the Information Blocking Rule?

Webinar, Kentucky Hospital Association, January 26, 2021

Not Your Grandma’s Quilt: Exploring the Current ‘Patchwork’ and Recent Trends in U.S. Data Privacy and Security Laws

Kentucky Bar Association Corporate House Counsel Webinar, November 18, 2020

Medical Liability Considerations for Physicians

Kentucky Medical Association Virtual Town Hall, September 24, 2020

Eliminating Kickbacks in Recovery Act

Kentucky Health Law Institute, UK CLE, September 2, 2020

The Future of Medicine for the Emerging Physician post COVID-19

Kentucky Medical Association Virtual Annual Meeting, August 22, 2020

Is Telehealth Here to Stay?

Medical News, June 30, 2020

OSHA Revises COVID-19 Guidance

Privacy 2020 – California’s Seismic Shift

Discussion of the California Consumer Privacy Act (CCPA), Southern Law Network, April 16, 2020

Information You Need on the COVID-19 Coronavirus

Shifting Sands of U.S. Privacy Laws

International Association of Defense Counsel Webinar, December 11, 2019

No-fault insurance in Kentucky

Cybersecurity and Data Breach Response for Lawyers: Threats, Prevention Tips, and Mitigation Strategies for Lessening the Risks of a Cyberattack

Kentucky Bar Association Annual Convention, June 12, 2019

The Race to Privacy

Stites & Harbsion Thirsty Thursday Speaker Series, April 25, 2019

Cyber Security for Rural and Critical Access Hospitals: Tips for Improving Data Security and Mitigating the Impact of a Cyber Attack

Alliant Management Services Management Meeting, April 10, 2019

Introduction to Health Law

Panel member, Health Enterprise Network Healthcare Fellows, University of Louisville Louis D. Brandies School of Law, March 19, 2019

Taking Stock of Your 2019 Cybersecurity Resolutions

Pings That Go Bump in the Night: A Discussion of Health Care, Cybersecurity Threats, Prevention Tips and Mitigation Tactics

Moderator and Panelist, 2018 Kentucky Health Law Institute, Lexington, KY, September 14, 2018

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-17, 2018

Employment Contracting Seminar

Kentucky Medical Association, Louisville, Ky., January 27, 2018

Leadership in Action: Take the Lead in Solving the Opioid Epidemic

2017 Kentucky Medical Association Annual Meeting, Louisville, KY, August 25, 2017

Cyber Threats & Ransomware

Kentucky Academy of Hospital Attorneys, Kentucky Hospital Association Annual Convention, May 29, 2017

Digital Fortress

Modern Steel Construction, May 2017

Residents in Business

faculty panel, University of Louisville School of Medicine, May 15-16, 2017

Cybersecurity for business: Improving data security and mitigating the impact of a cyber-attack

Kentucky Society of CPAs Spring Business Conference, Louisville, KY, April 20, 2017

Be Cyberwise: Protect & Position Your Business for Growth

Ohio River Valley Women's Business Council, 2017 Catch the Wave Conference, April 18, 2017

The Interplay Between Social Media and Healthcare Privacy

American Bar Association Regional CLE, Brave New World: Emerging Cyber and Electronic Issues in Health Care Litigation, March 31, 2017

Kentucky Health: Shadowing a Primary Care Physician

Kentucky Health,, March 26, 2017

Improving Data Security and Mitigating the Impact of a Cyber-Attack

Kentucky Medical Group Management Association Spring Conference, March 16, 2017

Under Attack: Cyber Threats Against the Health Care Industry

presentation, Kentucky Health Law Institute, September 15, 2016

Passwords, Revisited

The Goods, Kentucky Association of Manufacturers, September 2016

Build a Better Machine

Residents in Business

faculty panel, University of Louisville School of Medicine and Greater Louisville Medical Society, May 24-26, 2016

Stop. Think. Connect.

presentation, Stites & Harbison Summer Associate Program, May 16, 2016

Law Firm Data Security: It's the End of the World As We Know It (And I Don't Feel Fine)

presentation, Southern Law Network, Louisville, Kentucky, May 13, 2016

Don't Bet on Longshots - Practical Advice on Data Security for Financial Institutions

Stites & Harbison Creditors' Rights & Bankruptcy Service Group Day at the Races, Keeneland, April 14, 2016

Identifying and Protecting Your Core Data

The Goods (p.36), Kentucky Association of Manufacturers, March 2016

Data Breaching Now Its Own Industry

by Robert Hadley, The Lane Report, December 8, 2015

Data Breaches: Is Your Attitude about Data Security Putting You and Your Company at Risk?

The Goods (p. 16), Kentucky Association of Manufacturers, November 2015

Employee Attitudes Fuel Your Data Security Plan

Legaltech News, October 29, 2015

Are you ready for a HIPAA Audit?

Kentucky Association of Health Care Facilities Webinar, October 21, 2015

Technology Highlights for the Restructuring Professional: Privacy, Data Security & Electronic Discovery

co-presenter, International Women's Insolvency & Restructuring Confederation (IWIRC) Day at Keeneland, October 9, 2015

Prevention and Response: Is Your Business Prepared for a Data Security Breach?

Stites & Harbison, PLLC Thirsty Thursday networking event, May 21, 2015

Is your attitude about data security putting you and your company at risk?

Professional Insight, Business First of Louisville, March 27, 2015

Hot Topics in the Area of Health Law Privacy

Kentucky Health Law Institute, Novemer 7, 2013

HIPAA Wants You

Final Rule Amending HIPAA Regulations

Physician Employment Contracting Symposium

co-presenter, Kentucky Medical Association, November 3, 2012

Turning up the heat on HIPAA compliance: What to expect from increase enforcement and Office for Civil Rights audits

co-author, Louisville Bar Association's Bar Briefs, November 2012

HIPAA Update for Physician Office Managers

Kentucky Pediatric Office Managers Association, October 11, 2012

Stolen laptop leads to $1.5 million HIPAA settlement

HIPAA and HITECH's Impact on Certified Public Accountants

Kentucky Society of CPAs Healthcare Conference, May 16, 2012

Keeping up with technology demands: Delayed deadlines for Meaningful Use and ICD-10 reflect overburdened healthcare providers

Medical News, April 2012

HIPAA Audits and Investigations - What to expect when the Office for Civil Rights comes knocking

Louisville Bar Association, Health Law Section, April 11, 2012

Make Way for Medicaid Managed Care: What to expect as Kentucky departs from traditional fee-for-service reimbursement in favor of managed care for Medicaid recipients across the Commonwealth

Louisville Bar Association's Bar Briefs, November 2011

HITECH Challenges for Physicians: Keeping Up with Changes to Health Information Privacy and Security Rules in an Expanding Electronic Environment

Kentucky Medical Association, August 23, 2011

HIPAA and Social Media Issues for Employers, Hot Topics and Critical Issues Pertinent to Employers and Health Care Providers

Health Law and Labor & Employment Sections, Louisville Bar Association, June 2, 2011

HITECH's Amendments to HIPAA: Recent Changes to Health Information Privacy and Security Rules and their Impact on State Regulatory Investigations

National Board for Certification in Occupational Therapy, Annual Conference on Occupational Therapy State Regulation, October 23, 2010

HIPAA Update for Employers

Society of Human Resources Management Mid-West Kentucky Chapter, Madisonville, Ky., April 2010

How will the HITECH Act affect your law firm?

Louisville Bar Association, Health Law Section, April 28, 2010


The Regional Medical Center of Hopkins County, Madisonville, Ky., March 2010

Current Trend: Employment of Physicians by Hospitals

2010 Health Law and Compliance Update 1-2 (John Steiner ed., 2010)

Grounding Cyberspeech: Public Schools' Authority to Discipline Students for Internet Activity

97 Kentucky Law Journal 149 (2008)
Recent Assignments
Bar Admissions
Firm Leadership

Chief Privacy Officer

Privacy & Data Security Practice Group, Co-Chair

Office of General Counsel, as Chief Privacy Officer

American Bar Association, Health Law Section
Kentucky Bar Association
Louisville Bar Association, Health Law Section, Chair (2011)
American Health Lawyers Association
International Association of Privacy Professionals
International Association of Defense Counsel, Cyber Security, Data Privacy and Technology Committee, Chair
Community Involvement

Yew Dell Botanical Gardens, Board of Directors (2018-present)

Louisville Legal Aid Society, Volunteer (2009-16)

Sisters of Charity of Nazareth, Inc., Board of Directors (2011-16)

Focus Louisville, February 2016 Class

More Than Stites & Harbison

Sarah joined Stites & Harbison in September of 2009 after participating in the firm's summer associate program in 2008. In the summer of 2007, she worked in the legal department at Brown-Forman Corporation in Louisville. Before law school, Sarah lived in New York City where she worked at Friedman, Wang & Bleiberg, P.C. as a paralegal, and Lehman Brothers, Inc. in human resources supporting the information technology division.

Sarah is an accomplished equestrian and enjoys riding American Saddlebred horses in her free time.


Best Lawyers in America®, Health Care Law (2019-24)

Business First of Louisville, 20 People to Know in Law (2018)

Business First of Louisville, Partners in Health Care People to Watch (2014)

Spurlock Best Lawyers2024
Cipp Seal Hires Small
Iadc Member Logo Color Sm
See more related to Sarah Cronan Spurlock

International Association of Defense Counsel (IADC) 2024 Annual Meeting

Date: 7/6/24 - 7/11/24

Fairmont Hotel Vancouver, 900 West Georgia Street, Vancouver, Canada

Privacy and Data Security attorney Sarah Cronan Spurlock will be a speaker at the 2024 Annual Meeting of the IADC July 6-11.

Sarah Cronan Spurlock May 29, 2024

The Cost of Third- Party Data Breaches: How to Avoid a Financial Disaster

Date: 6/14/24
Time: 12:00 p.m. - 1:30 p.m.


Chad McTighe and Sarah Spurlock will be the speakers for The Knowledge Group's Webinar on June 14, 2024 discussing the costs associated with unforeseen security risks.

Chadwick A. McTighe and Sarah Cronan Spurlock May 28, 2024

Kentucky Hospital Association Annual Convention

Date: 5/20/24 - 5/22/24

Central Bank Center, 430 West Vine Street, Lexington, Kentucky 40507

Health care attorneys Shea Luna and Sarah Spurlock will be presenters at the Kentucky Hospital Association's Annual Convention in Lexington, KY being held May 20-22, 2024.

Stacy Shea Luna (Shea) and Sarah Cronan Spurlock April 22, 2024
Press Releases

Stites & Harbison, PLLC Lawyers Named to 2024 Best Lawyers® Publications

LOUISVILLE, Ky.—Stites & Harbison, PLLC is pleased to announce that 101 of its lawyers are included in the 2024 edition of The Best Lawyers in America®.

by Stites & Harbison, PLLC August 24, 2023
Client Alerts

Health Care Providers and Business Associates Beware: Use of Online Tracking Technology May Violate HIPAA

Entities regulated by the Health Insurance Portability and Accountability Act (HIPAA) may be surprised to learn that use of certain online tracking technology may result in inadvertently sharing information protected under HIPAA with unauthorized third parties. On December 1, 2022, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services issued guidance with far-reaching implications for HIPAA regulated entities highlighting their HIPAA compliance obligations when using third-party online tracking technologies designed to collect and analyze information pertaining to a user’s interaction with the regulated entity’s webpages and mobile apps.

by Stacy Shea Luna (Shea) and Sarah Cronan Spurlock April 28, 2023

Kentucky Hospital Association 94th Annual Convention

Date: 5/15/23 - 5/17/23

Central Bank Center, 430 W Vine Street, Lexington, Kentucky 40507

Stites & Harbison attorneys Sarah Spurlock, Ameena Khan and Shea Luna will be speakers at this year's Kentucky Hospital Association Convention in Lexington, Ky.

Sarah Cronan Spurlock and Stacy Shea Luna (Shea) April 05, 2023
Client Alerts

Kentucky Lawmakers Considering Comprehensive Data Privacy Legislation

Kentucky may soon join the growing number of states that have enacted data privacy legislation. On January 3, 2023, Senator Whitney Westerfield and Senator John Schickel introduced Senate Bill 15, which, if passed, will create new sections of KRS Chapter 367 to establish consumer protection rights for Kentucky residents relating to personal data.

by Sarah Cronan Spurlock March 07, 2023

Ransomware Threats: Prevention Tips and Response Strategies

Date: 2/28/23
Time: 1:00 p.m. - 2:30 p.m.


Stites & Harbison attorneys, Mari-Elise Paul and Sarah Cronan Spurlock, will participate in this upcoming ABA program focused on cybersecurity law and cyber incident response preparedness.

Sarah Cronan Spurlock February 08, 2023