Gicel Tomimbang is an associate in the Data Privacy, Cybersecurity & Digital Assets Practice. A former deputy attorney general and Office of Civil Rights investigator, she advises domestic and international companies on data privacy and protection, advertising technology, digital health, cybersecurity readiness and incident response, and consumer protection law.
Gicel served as a deputy attorney general for the California Department of Justice – Office of the Attorney General, where she specialized in conducting health data privacy and cybersecurity-focused government investigations and enforcement pursuant to health privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA); state medical information laws, including the California Confidentiality of Medical Information Act; and state consumer protection laws prohibiting unfair and deceptive acts and practices, including the California Unfair Competition Law and False Advertising Law. She also provided legislative advice and drafted legal filings submitted on behalf of the attorney general.
Gicel also served as an investigator for the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR), where she investigated domestic and international companies’ compliance with the HIPAA Privacy, Security, and Breach Notification rules. She provided technical assistance to help covered entities and business associates identify and address deficiencies in their HIPAA compliance programs and operationalize HIPAA requirements.
Gicel leverages her public sector experience to counsel traditional healthcare providers, digital health companies and clients across all other industries on a broad range of data privacy and cybersecurity compliance and regulatory issues. Clients frequently turn to her for advice and counsel on complex issues arising out of state and federal requirements for consumer data, healthcare data, and business planning and operational matters.
Gicel prepares clients in the public and private sectors to respond to future cybersecurity incidents by assisting them with development and implementation of proactive cybersecurity measures. She also works with IT forensic firms to help clients respond to and remediate cybersecurity incidents, including executing incident response strategy, incident response notification and reporting. She interfaces with law enforcement and regulatory authorities in the US and coordinates global incident response activities across jurisdictions.
Gicel is a Certified Information Privacy Professional (CIPP/US and CIPP/E), a Certified Information Privacy Manager (CIPM) and an IAPP Fellow of Information Privacy (FIP). She invests in her community through her active leadership in and contributions to the Los Angeles County Bar Association, the International Association of Privacy Professionals and various mentorship programs.