1. S.B. 26-189, Concerning the Use of Automated Decision-Making Technology in Consequential Decisions, and, in Connection Therewith, Making an Appropriation (Colo. 2026) (to be codified at Colo. Rev. Stat. §§ 6-1-1701 to 1709) (effective Jan. 1, 2027), https://leg.colorado.gov/bill_files/116489/download ↩︎
  2. S.B. 24-205, Consumer Protections for Artificial Intelligence, 74th Gen. Assemb., Reg. Sess. (Colo. 2024), https://leg.colorado.gov/bill_files/47770/download. ↩︎
  3. President Trump’s December 2025 Executive Order criticized state AI laws as a “patchwork of 50 different regulatory regimes” and cited Colorado’s algorithmic-discrimination law as an example. Exec. Order No. 14,365, Ensuring a National Policy Framework for Artificial Intelligence, 90 Fed. Reg. 58,499 (Dec. 16, 2025), https://www.federalregister.gov/documents/2025/12/16/2025-23092/ensuring-a-national-policy-framework-for-artificial-intelligence; Fact Sheet: President Donald J. Trump Ensures a National Policy Framework for Artificial Intelligence, White House (Dec. 11, 2025), https://www.whitehouse.gov/fact-sheets/2025/12/fact-sheet-president-donald-j-trump-ensures-a-national-policy-framework-for-artificial-intelligence/. ↩︎
  4. In the signing statement for the 2024 AI Act, Governor Polis expressed that he signed SB 24-205 “with reservations,” warning that it imposed a complex compliance regime, risked a state law patchwork that could hamper innovation and competition, and needed refinement before taking effect. Letter from Jared S. Polis, Governor of Colo., to Members of the Colo. Gen. Assemb. (May 17, 2024). https://drive.google.com/file/d/1i2cA3IG93VViNbzXu9LPgbTrZGqhyRgM/view.  Governor Polis convened a Colorado AI Policy Work Group to develop a revised policy framework, producing the 2026 Act.  See Press Release, Office of Governor Jared Polis, Colorado Artificial Intelligence Policy Workgroup Delivers Unanimous Support for Revised Policy Framework (Mar. 17, 2026), http://governorsoffice.colorado.gov/governor/news/colorado-artificial-intelligence-policy-workgroup-delivers-unanimous-support-revised-policy; see also S.B. 26-189, 75th Gen. Assemb., Reg. Sess. (Colo. 2026), https://leg.colorado.gov/bills/sb26-189. ↩︎


Continue Reading Colorado Scales Back AI Law, with Targeted Implications for Health Care

In an International Association of Privacy Professionals (IAPP) article, health care partner David Peloquin and data, privacy and cybersecurity associate Jake Barr along with Legend Biotech Chief Privacy Officer and Assistant General Counsel Corey Dennis discuss the landmark rule limiting sensitive data transfers to “countries of concern.” The article reviews key aspects for health care

In December 2024, the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology (“ASTP/ONC”) within the U.S. Department of Health and Human Services (“HHS”) published two final rules that establish health data interoperability and information blocking regulations (the “New HTI Final Rules”).

The New HTI Final Rules will affect Trusted Exchange

In a Bloomberg Law article, attorneys examined Washington State’s comprehensive new privacy law, the My Health My Data Act, the first state law that specifically safeguards consumer health data.

The article discusses the new law’s scope, applicability, and ensuing company obligations. The Act will apply to many life sciences companies, pharmaceutical and device

On December 20, 2023, the National Institute of Standards and Technology (“NIST”) National Cybersecurity Center of Excellence (“NCCoE”) published its Cybersecurity of Genomic Data report (the “Report”).  The Report aims to assist organizations in protecting against misuse of genomic data and enabling secure collaborative innovations.  Note, however, that the Report is not authoritative with respect to its assessment of the treatment of genomic data under the current U.S. regulatory framework, including with respect to the identifiability of such information.

Continue Reading NIST Cybersecurity Center of Excellence – Cybersecurity of Genomic Data Report 

The past year has seen unprecedented growth and development of artificial intelligence (“AI”) tools, which have been significantly propelled by the rapid deployment of generative AI (“GenAI”) tools.  The health care and life sciences industries have increasingly sought the use of AI and GenAI tools to promote innovation, efficiency and precision in the delivery of treatment and care, as well as in the production of biologics and medical devices.  For example, AI tools may more accurately predict and analyze diagnostic test results and develop personalized treatments than traditional tools; may improve clinical trial design, eligibility screening and data analysis; may be used as a diagnostic tool in a clinical trial designed to assess the safety or efficacy of a medical device; and may be used to accelerate the drug development timeline.  While such uses raise inherent concerns regarding, among other things, the improper use and/or disclosure of personal information, the introduction and/or perpetuation of bias and discrimination, as well as data security, reliability, transparency and accuracy, there is currently no developed federal or cohesive state regulatory framework designed to minimize such risks.  

Continue Reading The 2023 AI Boom Calls for Further Regulation of the Use of AI Tools in the Health Care and Life Sciences Industries

On July 20, 2023, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) and the Federal Trade Commission (“FTC”) sent warning letters to approximately 130 hospital systems and telehealth providers. The letters were intended to warn those entities of the privacy and security risks of online tracking technologies integrated into their websites and mobile applications. The agencies noted that the entities may be impermissibly disclosing consumers’ sensitive personal health information to third parties such as Meta/Facebook pixel and Google Analytics through the use of such online tracking technologies in potential violation of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended (collectively, “HIPAA”), the FTC Act, and/or the FTC Health Breach Notification Rule (“HBNR”).

Continue Reading HHS and FTC Warning Letters Highlight Continued Scrutiny of Use of Online Tracking Technologies in Healthcare

The Ropes & Gray Decoding Digital Health podcast series discusses the digital health industry and related legal, business and regulatory issues. In this episode, Digital Health Initiative co-lead and health care partner, Christine Moundas, interviews health care partner and member of the digital health group, David Peloquin. They discuss the legal challenges and potential solutions