Photo of Joseph J. Lazzarotti

Joe has had the honor of being a part of the AmLaw 100, nationwide law firm, Jackson Lewis, which has 60+ offices around the country, for nearly 25 years. After practicing in the northeast for most of his career, Joe is resident in the firm's growing Tampa office.

In 2005, as an associate, Joe founded and currently co-leads the firm’s national privacy, cybersecurity, and AI practice groups, which touts 25+ attorneys navigating complex and emerging challenges, particularly around the collection, use, disclosure, and retention of personal information, the deployment of artificial intelligence, and overall governance, risk and compliance in these areas, including FTCA, HIPAA, NIST, CCPA, CPRA, BIPA, GIPA, NY SHIELD, CIPA, etc. Joe has handled hundreds of data breaches, stood up cybersecurity compliance programs, and established AI governance programs.

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced a HIPAA enforcement action against an employer-sponsored group health plan. The action resulted in a payment to HHS of $245,000 and a two-year corrective action plan. While HIPAA enforcement is common in the healthcare sector, actions directly against employer-sponsored…

HIPAA compliance requirements continue to evolve, and recent court decisions have understandably drawn significant attention.

Last summer, we examined these developments in our Workplace Privacy Report article, analyzing how a Texas federal district court decision affected the HIPAA Reproductive Health Privacy Rule and why a subsequent Supreme Court decision may change that outcome.  The…

It is increasingly evident that artificial intelligence (AI) is reshaping all facets of business, and its impact on employee benefit plans is no exception. From automating plan administration to personalizing participant communications, AI introduces both new opportunities and new responsibilities for those overseeing Employee Retirement Income Security Act of 1974 (ERISA)-covered retirement and health plans…

A Texas federal court just shook the foundation of HIPAA’s reproductive health privacy protections — but the Supreme Court may have the final word. In a sweeping decision, Judge Matthew Kacsmaryk vacated key provisions of the 2024 Reproductive Health Rule, stripping away national safeguards on disclosing reproductive health information. Yet, a recent SCOTUS ruling in …

On June 2, 2025, the U.S. Department of Labor (DOL) announced a significant expansion of its compliance assistance tools by launching an Opinion Letter Program across five key enforcement agencies, including the Employee Benefits Security Administration (EBSA). This initiative aims to provide employers, plan sponsors, and other stakeholders with clear, tailored guidance on complex issues…

A little more than three years ago, the U.S. Department of Labor (DOL) posted cybersecurity guidance on its website for ERISA plan fiduciaries. That guidance extended only to ERISA-covered retirement plans, despite health and welfare plans facing similar risks to participant data.

Last Friday, the DOL’s Employee Benefits Security Administration (EBSA) issued Compliance Assistance Release…

In 2021, the Department of Labor (DOL) issued cybersecurity guidance for ERISA-covered retirement plans. The guidance expands the duties retirement plan fiduciaries have when selecting service providers. Specifically, the DOL makes clear that when selecting retirement plan service providers, plan fiduciaries must prudently assess the cybersecurity of those providers.  

On May 15, 2024, the…

On April 22, 2024, the federal Department of Health and Human Services’ Office for Civil Rights (OCR) announced a final rule enhancing privacy protections relating to reproductive health care. Specifically, the final rule amends the Privacy Rule under the Health Insurance Portability and Accountability Act (HIPAA) to, among other things, establish new limits on the…

It started sometime last year and, in hindsight, was inevitable.  Clients with 401(k) plans and a crypto-savvy employee population began asking whether they could offer cryptocurrency as a plan investment option.  In the 401(k) world, where even a self-directed brokerage window with built-in investment limitations can be too risky, the answer seemed obvious – watch…