• Patricia M. Carreiro
  • 305.539.7314
  • Share Share this page
Patricia M. Carreiro

Patricia M. Carreiro



Trish Carreiro is an experienced cybersecurity and privacy litigator who advises clients on privacy compliance and data breach response. She is a certified information privacy professional (CIPP/US) and certified information privacy manager (CIPM), accredited by the International Association of Privacy Professionals, and experienced in high-stakes cybersecurity litigation. She has particular depth of experience in highly regulated industries, such as insurance, health care, financial services, and telecommunications. She is a privacy and cybersecurity thought leader who uses her litigation perspective to guide clients to both avoid, and effectively handle, privacy and cybersecurity litigation. 

She is a frequent speaker and author on cybersecurity, privacy, and insurance issues. Her insights have been featured in publications including Bloomberg Health Law & Business, Law360Law.comCorporate CounselToday’s General CounselInsideCounselThe Cybersecurity Law ReportData Breach TodayHealth IT SecurityHealthcare IT News, Healthcare Infosecurity, Fierce Healthcare, Daily Business Review, Miami Herald, Dark Reading, and STAT.

Her prior experience includes time with the U.S. Department of Justice Criminal Division’s Fraud Section, the U.S. Securities and Exchange Commission Division of Enforcement, the New York State Attorney General’s Medicaid Fraud Unit, and the Connecticut Commission on Human Rights and Opportunities. She is proficient in Spanish and Portuguese.


Cybersecurity Class Action Litigation

  • Advised one of the nation’s largest banks on possible causes of action, defenses, class action strategy, and litigation options following nationwide data breach.
  • Advised large, publicly traded financial institution regarding multiple data breach class actions.
  • Represented health care provider in class action breach litigation. 

Privacy Compliance

Financial Institutions

  • Advised large financial institution and affiliated producer regarding privacy compliance throughout development of fully electronic automated underwriting application, including negotiating contractual agreements with third-party service providers, developing procedures for operationalizing and demonstrating privacy compliance, and drafting privacy policies, procedures, notices, and authorizations.
  • Counseled various financial institutions, including insurers, producers, and mortgage servicers, regarding compliance with privacy laws such as the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act (CCPA), the Telephone Consumer Protection Act of 1991 (TCPA), the CAN-SPAM Act of 2003, the Telemarketing Sales Rule, the Fair Credit Reporting Act, the Health Insurance Portability and Accountability Act (HIPAA), and National Association of Insurance Commissioners (NAIC) model laws, as applicable.
  • Counseled financial institutions regarding intersection of the GLBA and the CCPA.
  • Advised large insurer regarding contractual privacy provisions, privacy compliance, and cybersecurity insurance coverage.
  • Drafted privacy policies, associated notices, and privacy request processing procedures for organizations across industries, from financial institutions to nonprofits to retailers, including drafting sample communications and scripts.


  • Advised large telecommunications carrier on legal compliance and risk-reducing steps for numerous proposed uses and sharing of customer proprietary network information (CPNI).

Health Care

  • Drafted comprehensive HIPAA compliance program for HIPAA-covered entity, including drafting associated policies and procedures.
  • Advised business associate regarding compliance with the  CCPA, including drafting necessary privacy notices and establishing procedures for processing associated privacy requests.

Data Breach Response

  • Executed data breach response for companies of all sizes, including a large telecommunications carrier and numerous health care providers.
  • Represented health care providers throughout post-breach Office for Civil Rights and attorneys general investigations.

All Insights

Professional & Community Involvement

  • Connecticut Bar Association
    • House of Delegates District 12 (Hartford) Representative (2018–2019)
    • Executive Committee, Women in the Law Section (2016–2019)
  •  FAIR Institute
    • Cyber Insurance Workgroup (2018)
  • International Association of Privacy Professionals
    • Women Leading Privacy
    • Chair, South Florida KnowledgeNet Chapter
  • United Way Women United

Speaking Engagements

  • “Data Breach Litigation,” Global Aesthetics Conference (November 2021)
  • “HIPAA Breaches,” Miami Cosmetic Surgery & Aesthetic Dermatology Symposium (August 2021)
  • "Decision-Making with FAIR - Quantification and the Rise of Class Action Lawsuits," 2020 FAIR Conference (October 2020)
  • "Privacy Leaders Circle: Miami," Truyo (July 9, 2020)
  • "Privacy Policy and Terms of Use Basics for Start Ups," Nova Southeastern University Shepard Broad College of Law (March 2020)
  • "Evaluating Cyber Insurance Using the FAIR Doctrine," Legal Services Information Sharing and Analysis Organization (LS-ISAO) (May 2019)
  • "Using FAIR to Optimize Your Cyber Insurance Coverage," 2018 FAIR Conference on Information Risk Management (October 2018)
  • "Data Breach Litigation: Recent Trends and Developments," The Knowledge Group (June 2018)
  • "Cyber & Law: It’s Really About the Money," Evolver (January 2018)
  • "Which Insurance Would Cover a Breach-Related Injury?," Healthcare Info Security (October 2017)
  • "Cyber Risk and Liability Insurance: What Is It and Why You Need It," The Knowledge Group (October 2017)
  • "She Leads: Women in the Law," Quinnipiac University School of Law (November 2016)
  • "Cybersecurity Litigation and the Role of Cyber Insurance," Connecticut Law Tribune (September 2015)


  • New York University School of Law (J.D., 2013)
  • Duke University (B.A., 2008)
Bar Admissions
  • Florida
  • Connecticut
Industry Specialization Certifications
  • CIPM
  • Spanish
  • Portuguese
Court Admissions
  • U.S. District Court, Middle District of Florida
  • U.S. District Court, Southern District of Florida


  • Litigation Associate, Axinn, Veltrop & Harkrider LLP, Hartford, CT (2015–2019)
  • Litigation Associate, Wofsey Rosen Kweskin & Kuriansky LLP, Stamford, CT (2013–2015)


The information on this website is presented as a service for our clients and Internet users and is not intended to be legal advice, nor should you consider it as such. Although we welcome your inquiries, please keep in mind that merely contacting us will not establish an attorney-client relationship between us. Consequently, you should not convey any confidential information to us until a formal attorney-client relationship has been established. Please remember that electronic correspondence on the internet is not secure and that you should not include sensitive or confidential information in messages. With that in mind, we look forward to hearing from you.