With Halloween the highlight of October, it is fitting that October is also Cybersecurity Awareness Month. While children are fascinated by tales of ghosts and goblins, for lawyers, the real horror story is a data breach. A stolen laptop, a convincing phishing email, or even forgetting to turn on your VPN while checking email at a coffee shop can expose confidential client information. Our ethical obligations require reasonable efforts to protect client data, but the fact is, you can do everything right and still have something go horribly wrong.
This month, Greenspoon Marder LLP’s Technology, Privacy & Data Security team will highlight cybersecurity issues important to both practitioners and their clients. It is only fitting, therefore, to start with what happens when something does go wrong.
Nearly ten years ago, the ABA issued Formal Opn. No. 18-483, highlighting a series of competence-based duties that are triggered in the event of a data breach. This includes conducting a reasonable inquiry into what happened and which clients are affected, and notifying any client whose interests are reasonably likely to be negatively impacted as soon as reasonably possible. See also, Rule 1.4(a)(3); Bus. & Prof. Code, § 6068(m). While the California State Bar suggests that Rule 5.1 may require a formal data breach response plan (see Formal Opinion No. 2020-203), failing to have a plan in place invites disaster.
Cybersecurity Awareness Month should be the time that you create or update your data breach plan, since the unfortunate reality is that it is likely a question of when, not if, you will need to implement it. A sound plan should include:
- Procedures to implement immediate containment, including the ability to locate, lock, and wipe lost devices.
- A process to investigate the breach, including identifying outside security experts that can assist, to identify affected clients and the sensitivity of the information.
- Client notification, including who communicates, when, and what is said.
- Legal notice analysis under Civil Code section 1798.82 and any federal or international laws, such as HIPAA or the GDPR.
- Insurance notice, both cyber and malpractice.
- Training and post-incident review, so policies evolve with new threats.
Stay tuned throughout Cybersecurity Awareness Month as our team explores the evolving threat landscape and shares practical guidance to help organizations prevent, prepare for, and respond to cybersecurity incidents with confidence.
This publication is provided by Greenspoon Marder LLP is issued for informational purposes only and is not intended to be construed or used as general legal advice nor a solicitation of any type. Please contact the author(s) or your Greenspoon Marder LLP contact if you have any questions regarding the currency of this information. The hiring of a lawyer is an important decision. Before you decide, ask for written information about the lawyer’s legal qualifications and experience.