Few conversations are harder for a law firm than telling a client that their confidential information may have been exposed. Firms that have never rehearsed it tend to improvise under pressure, and improvised breach communications often create new problems.
The ABA addressed lawyers' obligations after a breach in Formal Opinion 483, issued in 2018. This post summarizes its themes in general terms and suggests how to prepare. It is not legal advice. State rules and bar opinions differ, and breach notification statutes may impose separate duties, so involve ethics counsel early.
What the ABA has said
Opinion 483 discusses obligations arising under several Model Rules:
- Rule 1.1 (competence): Lawyers should understand technology risks and be able to respond to incidents.
- Rule 1.4 (communication): Lawyers must keep clients reasonably informed. The opinion concludes that when a breach involves material client confidential information, the lawyer must notify current clients, subject to its analysis.
- Rule 1.6 (confidentiality): Lawyers must make reasonable efforts to prevent unauthorized access and, once an incident occurs, take reasonable steps to stop it and mitigate harm.
- Rules 5.1 and 5.3: Supervisory duties extend to ensuring that the firm has measures to respond to incidents.
The opinion also describes an expectation that lawyers monitor for breaches, which suggests that detection matters as much as prevention. Check how your state bar has addressed these points.
Separate legal duties may also apply
Beyond ethics rules, state data breach notification laws, contractual obligations to clients, and obligations to insurers may require notice within particular timeframes. Outside counsel guidelines sometimes require notice within a specified number of hours. Your plan should identify these sources before an incident.
Build a client notification workflow now
1. Decide who decides
Name the people who determine whether notification is required: typically the managing partner, firm general counsel or ethics counsel, and the incident response lead. Include a backup for each.
2. Define how you determine scope
You can only notify the right clients if you know whose data was involved. Prepare to answer:
- Which systems were affected?
- Which matters and clients' files lived in those systems?
- Was data accessed, copied or only encrypted?
- What kinds of information were involved?
Document management and practice-management systems with good audit logs make this far easier. Poor logging can leave a firm unable to rule clients out, which may push toward notifying everyone.
3. Prepare templates
Draft a notification letter and a short call script in advance, with blanks for specifics. Include:
- What happened, in plain language
- What information was involved
- What the firm is doing about it
- What the client can do to protect themselves
- A direct contact person and phone number
Avoid speculation, jargon and defensiveness. Have counsel review the templates ahead of time.
4. Choose the channel carefully
If email is compromised, do not use it to send breach notices. Have a way to reach clients by phone or a separate system.
5. Coordinate with the insurer and response team
Many cyber policies require consent before you incur certain expenses or make statements. Know the policy's notice requirements and who to call.
6. Keep a record
Maintain a timeline of discovery, decisions and communications. Notes made at the time carry more weight than reconstructions later.
Common mistakes
- Waiting for perfect information before telling anyone
- Notifying clients through a channel the attacker can read
- Letting different partners give clients inconsistent accounts
- Forgetting former clients, who may be covered by other duties, and discussing them with counsel
- Having no list of clients tied to specific systems
Exercise it
A tabletop exercise that includes drafting a notification and making the first three client calls reveals gaps quickly. Do it once a year.
How Counsel Cyber supports preparation
We help firms build incident response plans that include client communication steps, system logging that supports scoping, and tabletop exercises. If your plan lacks a notification workflow, we can help you draft one with your counsel.