Skip to Main Content
Professional Photo
Professionals

Alexandra P. Moylan, CIPP/US, AIGP

Shareholder

Alexandra P. Moylan is a shareholder in Baker Donelson's Baltimore office and a member of the Health Law Group and the Data Protection, Privacy and Cybersecurity Team.

Overview


Alexandra Moylan advises health systems, academic medical centers, and life sciences organizations on privacy compliance, AI governance, clinical research regulation, and enterprise data operations. As both a Certified Information Privacy Professional (CIPP/US) and Certified AI Governance Professional (AIGP), Alex helps clients design and implement legally compliant data governance frameworks that align with HIPAA, FDA requirements, and global privacy standards, enabling the responsible use of health data and artificial intelligence in research and clinical care.

Alex works extensively with health systems and academic research institutions to ensure compliance across Institutional Review Board (IRB) operations, data use and sharing, and human subjects research oversight. She assists with the development and review of IRB policies, data sharing agreements, informed consent templates, and data access workflows that support compliant secondary research, multisite studies, and enterprise data warehouse initiatives. Her counsel integrates HIPAA Privacy and Security Rule requirements with emerging AI and predictive analytics applications, helping organizations leverage data while maintaining regulatory fidelity.

In the AI and data governance space, Alex advises on the ethical and regulatory dimensions of algorithmic development, validation, and deployment in health care environments. She counsels clients on compliance with state, federal, and international privacy laws, including HIPAA, the California Privacy Rights Act (CPRA), the General Data Protection Regulation (GDPR), and the EU Artificial Intelligence Act. She has led the design of AI governance frameworks addressing transparency, bias mitigation, and model accountability within enterprise health systems.

Her practice also encompasses complex data transactions, including drafting and negotiating data use, licensing, and de-identification agreements for hospitals, research consortia, and technology vendors. She routinely collaborates with general counsel, chief privacy officers, research compliance teams, and IT and information security leadership to operationalize data governance policies and privacy compliance strategies.

Clients value Alex's ability to bridge clinical, technical, and legal considerations when advising on digital transformation, data warehousing, and AI implementation. Her counsel provides practical strategies that advance innovation while satisfying regulatory, ethical, and institutional review expectations.

A frequent writer and speaker, Alex contributes thought leadership on health care AI regulation, HIPAA modernization, and research privacy to publications including Bloomberg Law and Corporate Compliance Insights. She serves on the Maryland State Bar

  • Drafted template agreements and terms of use for clients developing AI software for use by life science and health care organizations and advised on regulatory compliance and data privacy issues.

  • Provided strategic counsel on AI ethics, governance, and risk management to health care, technology, and life science organizations, helping them navigate the complex and evolving landscape of AI regulation.

  • Assisted with the development of internal documents related to AI procurement, vendor management, and data use.

  • Provided privacy advice and counsel to clients on collecting, processing, and using personal data to comply with GDPR and US federal and state privacy laws, including drafting informed consent and authorization templates and notices of privacy practices.

  • Developed master clinical trial agreement templates and negotiated numerous clinical site agreements, investigator-initiated trial agreements, letters of indemnification, NDAs, informed consent forms, and other documents involved in all phases of clinical research and product development for U.S. and international clinical trials (EU, APAC, and Latin America).

  • Negotiated complex data licensing and data sharing agreements.

  • Conducted compliance reviews and drafted agreements for CROs and SMOs, including reviewing standard operating procedures.

  • Listed in The Best Lawyers in America® for Medical Malpractice Law - Defendants (2021 – 2026); Product Liability Litigation - Defendants (2024 – 2026); Commercial Litigation (2025, 2026); Mass Tort Litigation/Class Actions - Defendants (2026) 
  • The Maryland Daily Record's Business Law Power List (2025)
  • Baltimore Business Journal's 40 Under 40 (2022)
  • The Maryland Daily Record's Personal Injury & Medical Malpractice Power List (2022)
  • Listed in Chambers USA as a leading Litigation: Medical Malpractice attorney in Maryland (2021 – 2025)
  • Member – Baltimore City Bar Association
  • Member – Baltimore County Bar Association
  • Member – Hispanic National Bar Association
  • Member – Maryland Defense Counsel
  • Member – Maryland State Bar Association
  • Member – Maryland State Bar Association Artificial Intelligence Task Force (2024 – 2026)
  • Board Member – Baltimore Medical Systems
  • "GS3 Emerging Technologies Risk and Compliance: Cybersecurity, Privacy, and TCPA," HCCA Healthcare Enforcement Compliance Conference (October 2025)
  • "AI Implementation in Clinical Research: Risks, Benefits and Compliance Considerations," Maryland Tech Council Bio Innovation Conference (September 2025)
  • "Legal Innovation Forum AI Workshop" (August 2025)
  • Panelist – "Futuristic Law: Artificial Intelligence Innovations in Legal Practice," Maryland State Bar Association's Young Lawyers' Section and Baltimore City Bar Associations' Young Lawyers' Division (February 2025)
  • Host/Panelist – "Data Governance: Building a Framework for the Future of Emerging Technology," Roundtable, Sixth Annual Maryland Tech Council Technology Transformation Conference (February 2025)
  • "Artificial Intelligence: A Brave New World," Mid Atlantic Society of Healthcare Risk Management AI Seminar (December 2024)
  • "Section 1557 of the ACA: Impact and Implementation Deadlines," Medical Society of New Jersey Lecture Series (June 2024)
  • "One Boring Day: AI Governance and Security," Mind Over Machines (May 2024)
  • "AI Governance and Risk Management: Legal Considerations in the Development and Deployment of Generative AI," Perrin Conferences (April 2024)
  • "Federal US Privacy Bill on the Horizon? Exploring the Draft APRA & New State Privacy Legislation," OneTrust DataGuidance (April 2024)
  • Panelist – "Breaking the Double Bind," World Trade Center Institute's 2023 Women Spanning the Globe Conference (May 2023)

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept