ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

ABA Formal Opinion 483 and Your Firm's Breach Response Plan

What ABA Formal Opinion 483 says about lawyers' duties after a data breach, and how to turn it into a practical incident response and client notice plan.

3 min readBy Counsel Cyber Team

Most firms treat a breach as an IT problem. The ABA treats it as a lawyer's problem too. In Formal Opinion 483, issued in 2018, the ABA Standing Committee on Ethics and Professional Responsibility addressed what lawyers must do when a data breach or cyberattack affects client information.

This article summarizes the opinion in plain English and shows how to build its themes into a plan. It is general information, not legal advice. Check your state's rules and ethics opinions, which may differ.

What the Opinion Addresses

In summary, the opinion discusses duties arising under the Model Rules, including competence, confidentiality, communication and supervision, in the context of a breach. Its main points can be framed in three groups.

Before a breach: take reasonable precautions

The opinion ties into earlier guidance, including Formal Opinion 477R on securing communications. Lawyers are expected to make reasonable efforts to prevent breaches, which includes understanding the technology they use and having a plan. The opinion discusses the idea of an incident response plan as a prudent step.

Detection: monitor for breaches

The opinion indicates that lawyers should make reasonable efforts to monitor for breaches of client data. That means a firm cannot ignore the possibility until someone tells it that something went wrong. Monitoring can include security tools, alerts on suspicious sign-ins and review of logs, scaled to the size and risk of the firm.

After a breach: stop, restore, assess and notify

The opinion discusses acting promptly to stop the breach and mitigate harm, and making reasonable efforts to restore systems. It also explains that when a breach involves material client confidential information, lawyers have a duty to notify current clients, tied to Model Rule 1.4 on communication. The opinion discusses what the notice should convey, including what happened and what information was involved, so clients can make informed decisions.

It also addresses former clients differently, generally leaving notice questions to other law, so confirm with counsel which duties apply in your jurisdiction. State breach-notification statutes, federal rules in some sectors and client contracts can add their own requirements and deadlines.

Turning It Into a Plan

1. Write an incident response plan

Even two pages help. Include:

  • How to recognize and report a possible incident
  • Who leads the response and who can make decisions
  • Who to call: IT provider, insurer, outside counsel
  • How to preserve evidence
  • A communication plan for clients, staff and others

2. Set up detection

Ask your IT provider what is monitored. Examples include alerts for impossible-travel logins, suspicious mailbox rules, mass file changes and malware detections. Confirm who reviews them and how quickly.

3. Define "material" in advance

Decide, with counsel, how the firm will evaluate whether client information was involved and how severe the exposure is. Having criteria makes decisions faster and more consistent under pressure.

4. Prepare notice templates

Draft a basic client notice with placeholders. Cover what happened, what information was involved, what the firm is doing and what the client can do. Have counsel review it in advance.

5. Know your timelines

Document the notification windows in state law, client contracts and your insurance policy. Insurers often require prompt notice, and some contracts promise very short windows.

6. Train and rehearse

Walk the partners through a scenario once a year. Most gaps show up within the first twenty minutes.

Supervision Matters

Model Rules 5.1 and 5.3 address supervisory duties over lawyers and nonlawyers, including vendors. Make sure vendors with access to client data are contractually required to notify you promptly of incidents.

Document Your Reasoning

If a breach occurs, a record of the steps taken and the reasoning behind decisions is valuable. Keep notes with timestamps from the start.

Do Not Wait for an Incident

The best time to learn who calls whom is before the phone rings. A plan that exists on paper and has been read once is better than a plan improvised at midnight.

Counsel Cyber helps law firms draft incident response plans, set up monitoring and run rehearsals. If you would like to align your firm's plan with the themes in Opinion 483, we can help you build it.