Skip to content

Home / Resources / Blog Articles / Protecting Your Business series, Episode 2

Protecting Your Business series, Episode 2

About the Protecting Your Business Series

Protecting Your Business is a video series from LegitScript and our Compliance Collective partners, built for healthcare, telehealth, and addiction treatment providers navigating what comes after certification. Each episode tackles a real operational risk — from accessibility and privacy to advertising rules that keep shifting — and breaks down what it actually takes to manage it.

Blog-protecting-business-Ep2-image

September 18, 2026 | by LegitScript Folks

Episode 2: The Privacy Patchwork

LegitScript's Naomi Moono and Clym's Michael Williams dig into why HIPAA is only one piece of a much larger privacy puzzle. They break down how the shift from one state privacy law in 2020 to twenty-three today has created a compliance patchwork that follows businesses across state lines, why "moment in time" compliance efforts fail the moment the law changes, and what's uniquely at stake when handling substance use disorder and behavioral health records — where 42 CFR Part 2 adds another layer of protection, and where a patient's trust in privacy can be the deciding factor in whether they seek care at all.

 

Transcript

David (LegitScript):  Welcome everyone to our protecting your business series, which features experts from LegitScript and our Compliance Collective partners to help healthcare, telehealth, and addiction treatment providers navigate what comes after certification — from accessibility and privacy to advertising rules that keep shifting. Each episode tackles a real operational risk and shows what it takes to manage it. Today, we're talking about the complexities of privacy and what it actually takes to manage it operationally. I'm David Khalaf, and for this episode, we're happy to welcome Michael Williams, who is a licensed attorney in California and Washington DC, and is cofounder and CFO at Clym, a compliance platform that helps businesses better manage data privacy, web accessibility, and transparency requirements across more than a hundred and ninety global regulations all from one dashboard.

And also Naomi Moono, an MBA graduate who is director of strategy for LegitScript Certification, which gives businesses in highly regulated industries a way to prove legitimacy to major online platforms and payment processors, opening doors to advertising and payment access so that they can grow their business.

So privacy is complex. It's got a lot of layers to it. Michael, let's start with you. When folks think about privacy in regard to health care and really anything involving patients, the first thing that comes to mind is HIPAA, of course, but that's really just one small piece of a patchwork of privacy considerations.

Help us understand what are some of the major laws that listeners should be aware of when it comes to privacy.

Michael (Clym):  I think the word you just used is aware. Right? So I think that a lot of this is an awareness issue where most companies are unaware that they have other consumer data privacy obligations, and that's partially because this is a relatively new field. Right?

So some listeners might be familiar with GDPR, which is a European law that was implemented in two thousand eighteen. It's kind of the first modern consumer data privacy law that existed. And, basically, what that law said is that if you collected, stored, or processed information from consumers in Europe, you were subject to the GDPR. So that was two thousand eighteen.

In 2020, California implemented a law called CCPA, which said the same thing about California consumers. So whereas in the US in twenty twenty, there was one state with a law. Now there's twenty three states in the US that have some sort of consumer data privacy law in existence. They're all a little bit different.

None of them are exactly the same, and it's a patchwork of laws that could affect you regardless of where your business actually is located. So I started my career as a tax attorney, specifically a state and local income and sales tax attorney. So I think about this like tax. You could be a Texas based business selling to California consumers.

And if you do that, you may have an obligation to collect and remit sales tax to California. Same thing here. If you're an operator in Texas, but you have California customers or you have people from California visiting your website, you could be obligated to comply with this California law. Right?

That becomes very complex because you may not know where you are. It's unlikely you're gonna know where everyone is gonna be accessing your website from.

And that's why you need to have a really comprehensive and dynamic approach to consumer data privacy laws because you oftentimes cannot control kind of where the consumers are coming from. That's why you have to have a, again, a more comprehensive approach to those laws. And, again, there's an expansion of those laws across the US. So, again, six years ago, there was one. Now there's twenty three. We expect more to come on board over the next few years as well.

David (LegitScript):  Yeah. It feels really overwhelming for a business thinking that they might have to adhere to potentially dozens of privacy laws, not knowing, you know, what jurisdiction a user might be accessing their site from.

But, of course, knowing the laws around privacy is just the first step. Actually, implementing an effective system to comply with them, is, you know, something very different.

What does it actually take to operationalize things like consent management and data subject requests at scale?

Michael (Clym):  Yeah. I'll tell you a quick story, about one of the reasons that Climb was founded actually because it addresses this exact issue. So in two thousand eighteen, I was a CFO of a global travel management company based in Los Angeles, and we had a GIGAM plan. Even though we're based in Los Angeles, we collected and processed data from European consumers, so we had to get compliant with GDPR.

We hired a consulting firm. We paid them a hundred thousand dollars to get compliant. And the day after that consulting engagement ended, we found ourselves out of compliance because we were not provided with an ongoing software solution with which to comply. So that's a light bulb moment for Clym.
We said there's gotta be a better way. So we wanted to build a scalable, flexible, dynamic, and cost effective platform for companies to comply with these various laws. And that's really important because it's compliance is what that consulting engagement did for us in twenty eighteen for that company was a moment in time approach to compliance. It was not an ongoing approach.

Some of these laws change. Right? California, as I mentioned, implemented a law in 2020. They changed it in twenty twenty three.

Right? So even if you're compliant right now, it's possible that on an ongoing basis, you may not be. So that's why it's really important to work with software and service providers that implement solutions that are dynamic, that can be changed, that along with the laws and also with the needs of your business. You could operate today in a particular jurisdiction where you're not subject to a law.

And just because of changes in your business, you may become subject to that law, either in that jurisdiction or another one. So solutions that you're implementing need to be automated. They need to be flexible. They need to be dynamic to the changing regulatory landscape as well as the changing realities of your business.

David (LegitScript):  You know, one thing that we've talked about in our episode around accessibility was how trends, are being driven by both private litigation and public regulatory enforcement. You have touched upon a little bit of the regulatory environment and all the various jurisdictions with their own laws. And, also, then what about private litigation? How is that playing out with privacy?

Michael (Clym):  Sure. No. It's an expanding area of the law. So just one more touch point on the state piece.

States are increasing their enforcement of privacy violations because it almost functions as a silent tax. Right? So California, in particular, has levied a number of multimillion dollar fines in the last year against companies for privacy violations because it's again, it's a revenue generator for them.

So there's that one piece. We are seeing a significant uptick in private litigation as well, particularly in California, New York, and Florida where but other states as well where private litigants are enforcing these laws, these privacy laws against companies, again, for violations that they may not know exist.

But there's just a number there's a few what we call prolific litigants as well where they're just doing this. They're actually using technology to sue companies at scale. Right? So think about the technology that exists there today to obtain information off of someone's public facing website.

You can obtain a lot of information, and you can just kind of, in a boilerplate way, send out demand letters or file litigation against these companies in a way that you could not do even a few years ago. So an individual we've seen a few individuals in particular file hundreds of these cases on a daily basis. So it's a growing problem, and some of those private litigants are winning a substantial number of their cases. And that creates a number of headaches for businesses.

But that again, that's why input the the ounce of prevention that you can take to resolve some of those or or remediate some of those issues in the front end we'll say was it's much better than the pound of cure that it will take to respond to those demand letters, to to respond to the litigation, to involve your own attorneys to resolve or remediate those issues. You're much better off doing some advanced work by implementing a software and service solution first before those bad things happen.

David (LegitScript):  Yeah. Thanks, Michael. Let's bring Naomi into the conversation. Naomi, LegitScript has a dedicated privacy standard for its certification programs. Why is that important for certification, and what are the things that you're looking for?

Naomi (LegitScript):  Yeah. Great question and great call out, David. I would say privacy is incredibly important to certification because those health care and health care related businesses routinely handle some of the most personal information somebody can share, things from contact and payment information to medical conditions, prescriptions, treatment history. That's really private sensitive information. And our privacy standard is really about making sure that a business is doing more than simply just saying, we take your privacy seriously.

We wanna see that it can actually demonstrate compliance with the privacy laws that apply to its operations and the sensitive data that sensitive data is being handled securely and sensitively. And that includes confirming that the business has the appropriate privacy policy in place where required by law and that the organization is meeting those applicable requirements like Michael mentioned, such as HIPAA. And then for me, I think this also comes back to transparency and trust. Patients should really be able to understand what information that they're providing and why it's being collected, how it's being used and shared.

A privacy policy, I don't think it should just exist as a document that's buried at the bottom of a website that takes ages to find. It should accurately, clearly reflect what the business is actually doing. And, ultimately, certification is really designed to, in a lot of ways, help patients as well identify health care providers that operate legitimately and responsibly. And I think protecting patient information is a major part of that responsibility. Patients should not have to sacrifice their privacy in order to access care.

David (LegitScript):  Yeah. Let's talk a little bit more about that because, you know, obviously, privacy is important for every sector, but especially for, say, you know, addiction treatment and behavioral health providers. Talk a little bit more about that.

Naomi (LegitScript):  Yeah. Completely agree. Privacy absolutely matters across all of health care, all sectors. But I also agree that I do think the stakes can be a little bit higher in the behavioral health and substance use disorder treatment space because, again, those records contain deeply sensitive information about a person's diagnosis and treatment and recovery history. And, also, I think it's important to note that many substance use disorder treatment programs, those records at times can be protected by forty two CFR part two, which is a federal confidentiality framework that's specifically designed to protect substance use disorder treatment records. So while some of those requirements have been closely aligned with HIPAA recently, it still includes some really important additional protections.

So mishandling information in this space, it can really have consequences that go far beyond just receiving an unwanted email, as an example. The improper disclosure of someone's sensitive information like their treatment history could also expose them to stigma, you know, affect sensitive areas of their life, including things like their employment or their custody and family matters, legal proceedings. It's really important to take that into consideration when you're thinking about how critical privacy is, especially in this context and in this space. And then I also think that there's that direct connection between privacy and then, of course, access to care.

Someone may feel afraid. They might feel uncertain about seeking behavioral health or substance use disorder treatment. And if they don't trust that the information that they provide is going to remain private, that fear will prevent them from reaching out. So because of that, I don't think privacy is just an administrative requirement or a policy on a website.

It truly helps create that mutual trust that people need, especially when they're seeking treatment.

David (LegitScript):  Exactly. Really great insight. Thank you both, Naomi and Michael, for your expertise. That'll do it for this episode on privacy. And, everyone, please stay tuned for our next episode. Thanks.

Related Blog Articles