ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Breach Notification Planning: Lessons From ABA Opinion 483

ABA Formal Opinion 483 discusses lawyers' duties to monitor for, stop and disclose breaches. Here is a plain-English summary and what it means for planning.

3 min readBy Counsel Cyber Team

Most firms prepare for the possibility of a breach by buying software. Fewer prepare for the questions that follow: who must be told, when and what do we say? ABA Formal Opinion 483, issued in 2018 and titled "Lawyers' Obligations After an Electronic Data Breach or Cyberattack," addresses those questions from an ethics perspective.

This post summarizes the opinion's themes in plain English. It is not legal advice. The ABA's opinions are persuasive guidance, not binding law in your state, and breach notification statutes and contractual duties may impose separate requirements. Confirm with your state bar and counsel.

The big picture

Opinion 483 ties together several Model Rules. In broad terms, it discusses:

  • Competence (Rule 1.1): including keeping abreast of technology and, as the opinion describes, having a plan in place to detect and respond to incidents.
  • Communication (Rule 1.4): the duty to keep clients reasonably informed and, in some circumstances, to tell current clients about a breach involving their information.
  • Confidentiality (Rule 1.6): the duty to make reasonable efforts to prevent unauthorized access, and to act to stop and remediate a breach.
  • Supervision (Rules 5.1 and 5.3): responsibility to oversee lawyers, staff and vendors.

Duty to monitor

The opinion discusses the idea that lawyers should make reasonable efforts to monitor for breaches of systems holding client information. You cannot respond to an intrusion you never notice. For a small firm, that can mean tools and services that watch for suspicious activity rather than relying on someone to spot trouble.

Duty to stop and restore

When a breach is discovered, the opinion describes a need to act reasonably and promptly to stop it and mitigate damage. It also recommends having an incident response plan, ideally one that is developed and rehearsed before an incident, with defined roles, contacts and steps for investigation and restoration.

Duty to determine what happened

The opinion discusses making a reasonable effort to assess what occurred: what information was affected, which clients were involved and how. This is where logs matter. If logging was never enabled, the firm may be unable to rule out access, which complicates notification decisions. Many firms bring in a forensic specialist, often through the cyber insurance carrier.

Duty to notify current clients

The opinion describes an obligation, under Rule 1.4, to notify current clients when a breach involves, or substantially likely involves, material client confidential information. It explains that notice should be sufficient to let clients make informed decisions, and that the lawyer should provide enough information about what happened, what was affected and what is being done.

It treats former clients differently, noting that the Model Rules do not generally require this same notification, although other law may. Do not assume that stops your analysis, since state statutes and agreements may reach former clients.

Other sources of notification duties

Even if you satisfy the ethics rules, other requirements may apply.

  • State data breach notification laws.
  • Contract terms with clients, especially in outside counsel guidelines.
  • Obligations under regulations if you handle specialized data, such as health information.
  • Insurance policy notice requirements, which often require prompt reporting.

Planning before an incident

  1. Write an incident response plan. Name an incident lead, a backup and decision makers. Include phone numbers that do not depend on email.
  2. Know your insurer's requirements. Keep the policy and the claims hotline accessible offline.
  3. Retain contacts. Identify outside counsel, a forensic firm and a communications resource ahead of time.
  4. Turn on logging and keep it long enough to be useful.
  5. Draft notification templates with placeholders for facts, so you are not writing from scratch under pressure.
  6. Prepare a client contact list that can be accessed even if systems are down.
  7. Rehearse. A tabletop exercise reveals gaps before they matter.

Communicating with clients

If notification is needed, plain language helps: what happened, what information may be involved, what you are doing, what clients can do and who to contact. Avoid speculation. Have a partner call key clients personally and follow with written notice.

A note on privilege and documentation

Investigations may raise questions about privilege over incident reports. Counsel can advise on structuring the engagement, and that is a good reason to involve them early.

Next step

Counsel Cyber builds incident response plans for law firms and supports firms through incidents, including coordination with insurers and forensic partners. If your plan has not been reviewed in the past year, we can help you update it and run a tabletop exercise.