Overview

Kathie McDonald‑McClure is a trusted advisor in data privacy, cybersecurity, and health care regulatory compliance, bringing decades of experience at the intersection of law, technology, and risk management. She works closely with organizations and business leaders to navigate evolving data privacy and security obligations, with particular depth in health care and other highly regulated industries.

Kathie regularly advises clients on compliance with HIPAA, FERPA, GLBA, GDPR, and state data privacy and breach notification laws, and assists organizations in preparing for and responding to data security incidents. As data privacy has become increasingly intertwined with cyber technology, she has become a go‑to resource for health technology agreements and data privacy and security representations and warranties. She also collaborates with clients and their IT teams to develop, assess, and update data security policies and procedures that meet today’s expectations from legal and regulatory, contractual, cyber‑insurance, consumer, and third‑party perspectives.

In 2009, Kathie founded a legal blog, originally launched under the name HITECH Law, and focused on developments arising from the HITECH Act and its impact on HIPAA privacy and security requirements. As federal incentives for electronic health record adoption concluded, the blog evolved to address significant legal developments in data privacy and cybersecurity affecting organizations across all industries.

Kathie’s career in health care (both in‑house and in private practice) has shaped a broad regulatory practice centered on compliance and risk management. She advises clients on state and federal health care program matters, including Medicare and Medicaid enrollment and revalidation, board of pharmacy licensing, and regulatory due diligence for transactions, including changes of ownership (CHOWs). She regularly counsels clients on Anti‑Kickback Statute (AKS) safe harbors, with a particular niche in discount and rebate rules, and has developed compliant contract templates for client sales teams designed to align with AKS requirements. In addition, she advises health care organizations on compliance with the 21st Century Cures Act, including requirements related to electronic health information, information blocking, interoperability, and patient access.

Kathie also has extensive experience advising on human research and clinical trials, including clinical trial agreements, research policy development, FDA and OHRP compliance, informed consent requirements, HIPAA research authorizations, insurance and indemnification for adverse outcomes, Medicare Secondary Payor recovery issues, Medicare billing compliance, and data de‑identification. She has drafted U.S. contracting and informed consent templates for a global medical device company and assisted in training company personnel on compliance considerations affecting research contracts.

Her health care clients include hospitals, long‑term care providers, physicians, chiropractors, pharmacies, durable medical equipment suppliers, behavioral health providers, clinical laboratories, home health agencies, therapy providers, and medical device companies. Her non‑health care clients include manufacturers, community support agencies, public school districts, and colleges and universities. Kathie is an active member of several health care and data privacy professional associations and has continuously maintained her Certification in Healthcare Compliance (CHC) through the Compliance Certification Board (CCB)® since 2007.

Industries & Practices

Education

J.D., University of Louisville, Louis D. Brandeis School of Law

  • Executive Editor of the Journal of Family Law (Law Review)

B.S.B.A. with highest honors, University of Louisville

Distinctions

  • Martindale-Hubbell AV Preeminent® Peer Review Rated™ Highest Professional Rating
  • CITY Lawyer of the Year, The Best Lawyers in America® – Health Care Law (2018)
  • Listed, The Best Lawyers in America® – Health Care Law (2009–present)
  • Selected, “Partner in Healthcare” – Business First (2008–2016)

Professional Activities

  • Member, Kentucky Bar Association
  • Chair, Kentucky Bar Association – Health Law Section (July 2025–present)
  • Member, Health Care Compliance Association (HCCA)
  • Certificate in Healthcare Compliance (CHC) by the SCCE and HCCA Compliance Certification Board (CCB)® (2009–present)
  • Member, International Association of Privacy Professionals (IAPP)
  • Member, American Bar Association (ABA)
  • Member, ABA’s Health Care Law Section and Litigation, Tort & Insurance Section
  • Member, American Health Law Association (AHLA) (all AHLA practice groups)
  • Member, American Society for Pharmacy Law (ASPL)
  • Member, Healthcare Financial Management Association (HFMA)
  • Member, Kentucky Societies of Healthcare Risk Management (KSHRM)
  • Member, American Societies of Healthcare Risk Management (ASHRM)
  • Member, Louisville Bar Association; Chair of Health Law Section (2005); Chair, Litigation Section Mock Trial Seminar (1991); Past Member, Board of Directors; Past Member, Publications Committee
  • Participant, LTC Legal Risk Forum (2017–2019)
  • Member, Association for Conflict Resolution (ACR) (2003–2016)
  • Board of Directors, Network for Hope (formerly Kentucky Organ Donors Affiliates) (2023 to present)
  • Member, Venture Connectors of Louisville
  • Member, Zonta Club of Louisville and Zonta International (2023–present)
  • Graduate, Leadership Kentucky (Class of 2017)
  • Governing Board for the Greater Louisville (GLI) Health Enterprises Network (HEN) (January 2007–April 2022); Executive Committee (2008–2021); Vice Chair, HEN Nominating Committee (2016–2021); Policy Forum (2010–2014)
  • Fellow, Health Enterprises Network Fellows Class (2006)
  • Executive Leadership Team Member, American Heart Association 25th Anniversary Heart Ball fundraiser (2017)
  • Elder Serve Champion, Aging Awards Luncheon (fundraiser) (2012); Honorary Chair
  • Co-Chair, US Figure Skating’s Regional Championships in Louisville, KY – Local Organizing Committee (2006–2007)
  • Board of Directors, Louisville Skating Academy (2007–2008)
  • Board of Directors, Court Appointed Special Advocates (CASA) (1994–1995)

Experience

  • Served for 12 years in-house with a national long-term care organization, ultimately as Vice President and Counsel of Liability Claims, where she built and managed an internal claims department of 13–15 professionals, oversaw liability claims for more than 300 skilled nursing facilities and 35 long-term acute care hospitals, managed multimillion-dollar insurance reserves for the company's captive insurer, negotiated and administered commercial liability and professional liability insurance programs with leading reinsurers, and collaborated with clinical, technology, and operational teams to strengthen enterprise-wide risk management practices.
  • State and federal data privacy laws, including HIPAA, HITECH, FERPA, FTC, GDPR, comprehensive state privacy laws (including CCPA/CPRA), Part 2 (Substance Use Disorder Confidentiality), GLBA, FTC Red Flags Rule
  • Data security incident response (SIR), including forensics, breach notification, government agency investigations, and the development of SIR policy and procedure
  • Electronic Health Information (EHI) Interoperability (formerly Meaningful Use) and the 21st Century Cures Act Information Blocking Rule applicable to ensuring patient and provider access to EHI
  • Software technology agreements (both healthcare and non-healthcare related) that implicate compliance with data privacy and/or information security laws and industry standards
  • Identity Theft advice and assistance
  • Website and mobile app privacy notice drafting, updating, and advice for compliance with applicable privacy laws
  • Human research and clinical trials agreements with a focus on compliance with the Federal Policy for the Protection of Human Subjects (Common Rule), HIPAA, FDA, False Claims Act, Anti-Kickback Statute, Stark Law, and more
  • Anti-Kickback Statute, Stark Law, Civil Monetary Penalties Law compliance advice relevant to healthcare transactions
  • Healthcare mergers and acquisitions due diligence, including Change of Ownership (CHOW) filings with Medicare, Medicaid, and applicable state licensing agencies and boards of pharmacy.
  • Enrollment, revalidation, and change of information in Medicare and state Medicaid programs, including disclosure of ownership and control and adverse actions (hospitals, nursing homes, DME suppliers, pharmacies)
  • Pharmacy matters, including pharmacy services agreements, state pharmacy board licensure review, and investigations
  • Clinical integration arrangements involving behavioral health, primary care, and/or acute/post-acute care and population health
  • Nursing home arrangements advice for medical directors, PT/OT, and other ancillary services, and I-SNPs
  • Vendor discounts and rebates advice, including employee training, on healthcare product sales and services arrangements relevant to compliance with the Anti-Kickback Statute
  • Employer wellness programs and on-site clinics as related to compliance with HIPAA and healthcare provider-related licensing rules and regulations
  • Physicians Payments Sunshine Act compliance guidance for both product manufacturers and teaching hospitals
  • Durable medical equipment (DME) compliance with Medicare DME standards, billing, and competitive bidding program rules
  • Long-term care pharmacy contracting and compliance matters
  • Medicare Secondary Payer (MSP) recovery issues related to liability claim settlements involving Medicare beneficiaries
  • Concierge medicine practice advice, including patient consent forms, space sharing arrangements, HIPAA, and Medicare billing compliance
  • Group purchasing organization (GPO) arrangements
  • Compliance audits for hospitals, skilled nursing homes, and DME suppliers, including employee training and education
  • Government surveys, citations, subpoenas, warrants, and civil investigative demands
  • DOJ and OIG exclusionary issues
  • Fraud, Waste, and Abuse (FWA) multi-state policy development for compliance with the Deficit Reduction Act of 2005 (DRA)
  • Liability insurance coverage questions, including cyber liability insurance policies

Insights

Blog Posts

Presentations & Publications

  • “Navigating the Digital Quilt: The 2026 State of U.S. Data Privacy,” BGW Memphis Corporate Counsel Seminar (April 2026)
  • “Introduction to Laws Related to Fraud, Waste & Abuse,” University of Louisville School of Public Health Class (March 2026)
  • “Cybersecurity Panel,” Greater Louisville, Inc. (GLI) (Louisville Chamber)
  • “HIPAA in the Workplace,” National Business Institute, Kentucky HR Bootcamp (June 2025)
  • “Let’s Explore the AI Cybersecurity Collaboration,” Technology Association of Louisville, Kentucky (TALK) (June 2025)
  • “Legal Update on HIPAA and Cybersecurity for Employer-Sponsored Health and Welfare Plans,” Kentucky Chamber HR Conference (April 2025)
  • “Introduction to Laws Related to Fraud, Waste & Abuse,” University of Louisville School of Public Health Class (March 2025)
  • “Don’t Let a Curve Ball Strike You Out: Stay Safe on the Field of Cyber Threats,” 17th Annual In-House Counsel Seminar (June 2024)
  • “HIPAA Rules and Updates 2024,” National Business Institute (May 2024)
  • “Data Privacy & Security: State and Federal Laws & Regulations,” Transformations Annual Printers Conference (August 2023)
  • “HIPAA Rules and Updates 2023,” National Business Institute (March 2023)
  • “Cybersecurity Best Practices for EHRs/EMRs and Law Firms,” Kentucky Hospital Association Annual Conference (May 2023)
  • “HIPAA Update Fall 2022: New Rules and Recent Changes,” National Business Institute (November 2022)
  • “Social Engineering Fraud Awareness,” Client In-Person Training (August 2022)
  • “Data Security & Social Engineering Fraud,” Community Action Kentucky Annual Conference (June 2022)
  • “HIPAA Update 2022-2023: New Rules & Recent Changes,” National Business Institute (March 2023)
  • “Cybersecurity Considerations for Lawyers and Clients,” Inn of the Court Luncheon (March 2023)
  • “Cyber Risk Rising in Email: From Smishing to Pretexting to BEC,” Technology Association of Louisville, Kentucky (TALK) (June 2022)
  • “HIPAA in the Workplace,” National Business Institute, Idaho HR Bootcamp (May 2022)
  • “HIPAA Update 2022: New Rules and Recent Changes,” National Business Institute (March 2022)
  • “The Information Blocking Rule,” Louisville Bar Association Health – Law Section (October 2021)
  • Co-Author with Mary Fullington, Overview & Guidance Note for Kentucky data privacy law for DataGuidance by OneTrust, a global privacy intelligence platform (September 2019, updated 2020)
  • Co-Author with Margaret Young Levi, “Data Security in the ‘New Normal’ of Teleworking,” Lorman Education Services (September 2020)
  • Co-Author with Margaret Young Levi, “Audio-Video Conferencing Risks and Tips for Healthcare Providers” (September 2020)
  • Co-Author with Margaret Young Levi, “CISA/NCSC Joint Alert Warns of APT Groups Targeting Healthcare and Essential Services,” Lorman Education Services (August 2020)
  • “Risk Management in Long Term Care Institutions and Services,” Risk Management in Health Care Institutions: Limiting Liability and Enhancing Care, Chapter 16 (2014, 3rd)
  • "OCR Steps Up HIPAA Audits," Valeo Communications (July 2011)
  • “Medicare’s New Mandatory Reporting Requirements for Liability Insurers, Including Self-Insured Entities,” HCCA Compliance Today (July 2009)
  • “Mandatory Reporting of Liability Settlements: Law to Shine Spotlight on Attorneys and Their Clients’ Pocketbooks,” LBA Bar Briefs (June 2009)
  • Co-Author with R. Benvenuti, Ill, “Enforcement Activities By Investigating Authorities and Responding to Investigations,” Chapter 5, Kentucky Health Law (2009 5th)
  • “Outpatient Therapy Clinics and Their Referring Physicians: Fraud and Abuse Risks,” HCCA Compliance Today (April 2008)
  • “Deficit Reduction Act Update,” HFMA Kentucky Chapter Financial Scene (January 2007)
  • ”The DRA’s New False Claims Requirements,” HFMA Kentucky Chapter Financial Scene (June-July, 2006)
  • “US Supreme Court Limits Medicaid Recoveries in Personal Injuries Settlements,” HFMA Kentucky Chapter Financial Scene (June-July 2006)
  • “Compliance 101, Clinical Trials Primer,” HCCA Compliance Today (June 2006)
Kathie McDonald-McClure, Bricker Graydon Wyatt LLP Photo

Kathie McDonald-McClure

Partner
  • 400 West Market Street
    Suite 2000
    Louisville, KY 40202

Admissions

  • Kentucky (1985)
Jump to Page

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.