ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

ABA Formal Opinion 483: What Law Firms Should Do After a Breach

A plain-English look at ABA Formal Opinion 483 on lawyers' duties after a data breach, with a practical response outline for firm administrators.

3 min readBy Counsel Cyber Team

ABA Formal Opinion 483, issued in 2018, addresses a question every firm eventually faces: what must a lawyer do when client data is exposed? The opinion walks through duties of competence, confidentiality, communication and supervision, and it concludes that lawyers have obligations before, during and after a breach.

This post summarizes the opinion in plain English and turns it into a practical outline. It is general information, not legal advice, and state law and your state bar's guidance may add requirements, so confirm with your ethics counsel.

The Opinion in Brief

As the ABA describes it, a lawyer's response to a data breach can be understood in three parts.

Before: monitor and prepare

The opinion discusses an obligation to make reasonable efforts to monitor for breaches of systems holding client information. It also encourages firms to have an incident response plan in place in advance. You cannot respond to something you never notice.

During: stop and restore

When a breach is detected, the opinion describes a duty to act reasonably and promptly to stop the breach and mitigate damage. It also discusses efforts to restore systems and to investigate what happened, such as which data was accessed and how.

After: notify

The opinion discusses when a lawyer must notify current clients under Rule 1.4 and Rule 1.1, when information relating to their representation was, or is reasonably believed to have been, compromised. Notice is meant to let clients make informed decisions. The opinion also notes that Rule 1.6 and various state and federal laws may affect what must be said and to whom. Duties to former clients are generally governed by other law.

Turning It Into a Plan

A workable plan does not need to be long. It does need names and phone numbers.

1. Detection

  • Centralized logging and alerting on email, endpoints and cloud accounts
  • Around-the-clock monitoring by a managed detection and response service, if the firm lacks internal staff
  • A clear way for staff to report suspicious activity without fear of blame

2. First hour

  1. Notify the incident lead, usually the managing partner or administrator, and your IT or security provider.
  2. Contain the incident: disconnect affected devices, disable compromised accounts, reset credentials.
  3. Do not wipe or reinstall systems before evidence is preserved.
  4. Call your cyber insurance carrier, because many policies require prompt notice and may provide approved breach counsel and forensic firms.

3. Investigation

  • Preserve logs, images and email evidence.
  • Identify which accounts, systems and matters were affected.
  • Determine whether client data was viewed, copied or only made unavailable.
  • Consider engaging outside breach counsel and forensic specialists.

4. Notification

  • Work with counsel to determine which clients, regulators or law enforcement agencies must be notified, including under state breach notification statutes.
  • Draft clear client communications that describe what happened, what information was involved, what the firm is doing, and what clients can do.
  • Keep a log of who was notified and when.

5. Recovery and review

  • Restore from clean backups.
  • Close the gap that allowed the incident.
  • Hold a post-incident review and update the plan.

Practical Preparation

  • Keep contact information offline. Print a one-page list with the insurer, IT provider, breach counsel and key partners.
  • Know where your data lives, so you can answer which clients are affected.
  • Practice. A tabletop exercise that walks partners through a hypothetical ransomware or email compromise exposes gaps cheaply.
  • Review insurance terms so you know what notice is required and what is covered.
  • Supervise vendors. Rules 5.1 and 5.3 address supervision, and a vendor breach can become your problem.

Common Mistakes

  • Waiting to be certain before calling anyone
  • Cleaning up systems in a way that destroys evidence
  • Delaying client communication while hoping the problem disappears
  • Having no written plan, leaving decisions to be invented under stress

Getting Ready

Counsel Cyber helps law firms write incident response plans, run tabletop exercises and monitor for threats. If your firm has not rehearsed a breach, we can facilitate a short session and leave you with a usable plan.