Skip to main content

Kathryn May on broadening her digital health policy perspective through privacy law

September 23, 2026

Isidora Ateljevic

4 Min Read

Share With Your Network

Privacy had long been an area of law that Kathryn May wanted to explore in greater depth. A lawyer working in digital health strategy and policy with the Ontario government, she had completed the Certified Information Privacy Professional (Canada) certification in 2020 and occasionally encountered questions involving Ontario’s health privacy legislation, but she wanted an opportunity to study privacy law formally.

As her work increasingly brought her into contact with privacy and cybersecurity issues, she wanted a stronger foundation in both areas. Osgoode’s Professional LLM in Privacy and Cybersecurity Law offered a way to develop that expertise while continuing her work in digital health.

Privacy and Data Security from a Legal, Business and Technological Perspective gave Kathryn a foundation in key privacy and cybersecurity issues, while Privacy Law in Canada took her into legislation including the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal Privacy Act and Ontario’s Personal Health Information Protection Act (PHIPA). Learning alongside classmates working in IT was particularly useful for Kathryn, who did not have a technical background.

“The lawyers learned things from the people working in IT, who were able to explain things to us in language you can understand and vice versa,” she says.

Kathryn was also one of only a few people working in health in a cohort that included professionals from banking, law enforcement, the military and other sectors. Classmates were based across Canada and brought experience from different provincial and federal contexts, giving her opportunities to learn how privacy and cybersecurity issues were approached in other sectors and jurisdictions. The connections sometimes proved directly useful: when a colleague needed information about another province’s approach to digital health, Kathryn remembered a classmate working for the agency responsible for digital health in Newfoundland and Labrador and reached out for a contact.

International Privacy Law became one of her favourite courses. Studying how other jurisdictions address privacy and cybersecurity gave her a chance to consider approaches Canada might learn from, a particularly useful exercise for someone working in public policy.

“You’re always trying to figure out new ways of doing things, better ways of doing things,” she says.

The LLM also pushed Kathryn to think more broadly about how governments regulate. Courses examined different approaches to regulation, including when legislation may be appropriate, when non-binding standards can play a role and when an issue may instead develop through the courts. Instructors with experience at privacy commissioners’ offices also discussed how regulators apply and enforce privacy law in practice. For example, Kathryn learned more about the factors regulators consider when determining penalties for non-compliance, which provided valuable context on how privacy legislation is interpreted and applied in real-world settings.

“You get a better sense of how things work in practice,” she says.

Research papers gave her another opportunity to connect the coursework with digital health. Assignments often required students to develop recommendations for regulatory reform in response to current privacy and cybersecurity issues. Kathryn wrote both about subjects outside her usual work, including government use of artificial intelligence, as well as digital health topics that had been on her radar but that she had never had the opportunity to investigate in depth, such as privacy and cybersecurity considerations in virtual healthcare.

By the end of the LLM, Kathryn felt more confident pursuing work specifically focused on privacy and cybersecurity. She has since moved into the Ontario Ministry of Health’s Information Management Strategy and Policy Branch, where she is helping to advance modernization of Ontario’s health privacy legislation, PHIPA.

Enacted more than two decades ago, PHIPA was written when health-care delivery was far more paper-based and today’s digital environment was not yet contemplated. Kathryn’s work now involves questions about how the legislation applies to specific digital health initiatives and how it may need to evolve as health care becomes increasingly digital.

“I’m able to leverage the background I got from working in digital health strategy and policy, along with the grounding I got from the LLM in privacy and cybersecurity, and bring all those things together to help contribute to modernization of the legislation.”

Wondering if the Professional LLM is right for you? Get information on course requirements, application dates, tuition and more!


Kathryn May, alumna of the part-time Professional LLM in Privacy and Cybersecurity Law.

Kathryn May – Senior Information Management Policy Advisor, Ontario Ministry of Health

Graduate of the LLM in Privacy and Cybersecurity Law (2024)