ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Rule 1.4 and Data Breaches: Telling Clients What Happened

After a breach, a firm must decide what to tell clients and when. Review what Rule 1.4 and ABA Formal Opinion 483 say and how to prepare in advance.

3 min readBy Counsel Cyber Team

Few conversations are harder for a managing partner than calling a client to say that the firm's systems were compromised. Yet clients are entitled to expect candor, and the ethics rules speak to it. Understanding the framework before an incident, and drafting your communications in advance, makes a bad day more manageable.

This post summarizes what the ABA has said and offers a practical preparation approach. It is general information, not legal advice. Breach notification laws and bar rules differ by state, so involve counsel with experience in this area.

What Rule 1.4 says in general terms

Model Rule 1.4 covers communication. Among other things, it asks lawyers to keep clients reasonably informed about the status of their matters, to explain matters to the extent reasonably necessary to permit informed decisions and to consult about the means used to achieve objectives. A security incident affecting client information can fall within those principles.

What ABA Formal Opinion 483 adds

The ABA issued Formal Opinion 483 in 2018, on lawyers' obligations after an electronic data breach or cyberattack. In summary, it discusses that lawyers have a duty to monitor for breaches, to act reasonably to stop a breach and mitigate harm, to investigate what happened and to notify current clients when a breach involves material client confidential information. It also addresses former clients under certain circumstances, in light of other law. It stresses that state and federal law may impose additional notification duties.

The practical takeaways

  1. Monitoring is part of the expectation, so find out whether you would detect an intrusion.
  2. Respond quickly to stop and contain.
  3. Determine what was affected before deciding what to say.
  4. Tell affected current clients with enough information to make informed decisions.
  5. Check other legal obligations in parallel.

Prepare before an incident

Know your obligations map

Ask counsel to outline which state breach notification statutes might apply, where your clients reside, what your insurance policy requires in terms of notice and which client contracts include notice commitments. Many outside counsel guidelines specify short notification windows, so catalog them.

Create a communication template

Draft a client notification letter with placeholders and have counsel review it. A good notice generally includes:

  • What happened, in plain terms.
  • What information was involved, as far as is known.
  • What the firm has done to respond.
  • What the client can do to protect themselves.
  • Who to contact at the firm for questions.

Avoid speculation, blame and technical jargon. Update as facts develop, and do not overstate certainty early on.

Decide who speaks

Name a person responsible for client communications, usually a partner, with a backup. Instruct staff to refer questions to that person instead of improvising.

During an incident

  1. Preserve evidence and bring in forensic help, often arranged through your insurer.
  2. Contain the incident and secure accounts.
  3. Engage counsel early to guide privilege and notification analysis.
  4. Assess scope with your IT provider: which systems, which matters, which clients.
  5. Notify affected clients as directed by your analysis, and in line with deadlines found in laws and contracts.
  6. Document each decision and time.

Avoid common mistakes

  • Waiting for perfect information before telling anyone. Prompt, honest updates beat delayed certainty.
  • Telling clients something that later proves wrong. Qualify statements.
  • Forgetting to check cyber insurance notice requirements, which may affect coverage.
  • Letting staff discuss the incident on social media or with outsiders.
  • Failing to follow up with an explanation of what changed.

After the incident

Review what happened, strengthen controls and tell clients what you improved. Consider whether staff training or contract changes are needed. Keep records of the response, since they demonstrate reasonable efforts.

Link prevention to communication

Many client conversations become easier when the firm can say that data was encrypted, backups were intact and MFA limited access. Security controls determine what you will have to disclose.

Where Counsel Cyber fits

Counsel Cyber supports law firms before and during incidents, including log review, scoping and coordination with breach counsel. If you want help building an incident plan with a client notification template, we can walk through it with you.