Cybersecurity Risk and Liability: Hot Button Issues for Lawyers

ALM Law.com
Share this page:

A discussion of cybersecurity issues for attorneys in light of New York State’s recently introduced CLE requirement in Cybersecurity, Privacy and Data Protection. The article touches on ethics requirements in that regard and discusses several relevant attorney malpractice cases.

In March 2023, the New York State Attorney General fined a law firm for its poor data security measures that led to a data breach which compromised the personal information of approximately 114,000 patient records of the firm’s clients.

In March 2023, a law firm in New York issued a notice to its affected clients that an unauthorized third-party gained remote access to the firm’s systems at the end of 2022. Over 93,000 individuals’ personal information, such as names and Social Security numbers, was compromised by the data breach.

Another law firm experienced a data breach in 2021 that exposed confidential information of more than 78,000 people, resulting in two separate class actions, one of which was filed in March 2023.

It is becoming increasingly common for law firms to fall prey to data breaches and ransomware attacks. Without attention to cybersecurity threats, lawyers and law firms are at serious risk of liability for malpractice, breach of contract and breach of fiduciary duty, and could even face class action suits, as well as professional discipline.

Client Disclosures

It is worth noting at the outset that cybersecurity risk should be discussed with the client and disclosed in the engagement letter with the client. For example, the letter should explain in some degree the risks associated with cybersecurity in respect of the client’s confidential information, especially where highly sensitive client data is involved.

Lawyers have a duty of communication under Rule 1.4(a)(2) of the New York Rules of Professional Conduct (the “Rules”) to reasonably consult with the client about the means by which the client’s objectives are to be accomplished.

One objective is that lawyer-client communications will be maintained in confidence, including when e-mail, the Internet and computer technologies are used. Comment [17] to Rule 1.6 provides that when transmitting a communication that includes information relating to the representation of a client, a lawyer must take reasonable precautions to prevent the information from coming into the hands of unintended recipients.

In Guo Wengui v. Clark Hill, PLC, 440 F. Supp. 3d 30 (D.D.C. 2020), the court found that the plaintiff, who was the client of the defendant law firm and a political dissident in his native country, had cautioned before engaging the firm that it should “expect to be subjected to sophisticated cyber attacks” and to “take special precautions to prevent improper disclosure of plaintiff’s sensitive confidential information” by, for example, “not placing any of plaintiff’s information on the firm’s computer server,” as doing so would make the information more vulnerable to hackings. Id. at 36.

The parties proceeded to enter into an engagement letter; however, despite the client’s clear warnings about hacking, the client’s confidential information was, nonetheless, compromised after the firm stored the information on its server, which was hacked.

In denying the firm’s motion to dismiss, the court concluded that the client properly pled claims that the firm (i) breached its fiduciary duties of loyalty and good faith by misrepresenting the manner in which the firm would protect his confidential records, (ii) committed legal malpractice by failing to maintain “reasonable security measures to secure their computer system from unauthorized access, as required and promised to plaintiff,” and (iii) breached its contractual obligation to provide “competent representation” in undertaking a matter beyond its “professional or technical competence” and in “neglecting to undertake reasonable security measures.” Id. at 37-39.

The court also determined that the client may have other viable claims, including violation of a general obligation of attorneys to provide competent representation to the extent that the firm provided insufficient protection to client materials.

Security Vulnerabilities

Even absent an actual data breach, law firms have been sued for alleged weaknesses in their information security systems. To illustrate, in Shore v. Johnson & Bell,No. 16-CV-4363, 2017 WL 714123, (N.D. Ill. 2017), an action seeking class arbitration was filed in 2016 against a Chicago-based law firm alleging that it put at risk the confidential information of its clients by using a computer time entry system recognized as particularly vulnerable to hacking, causing such information to be “unsecured and unprotected,” despite there being no actual allegation of a security breach having occurred.

Although the court’s decision addressed the plaintiffs’ request for class arbitration, which the court denied, and did not resolve their claim that the security vulnerability left them under “a heightened risk of … injuries,” the lawsuit was litigated for almost a year in court, undoubtedly resulting in cost, effort and potential reputational harm to the firm.

This case serves as a reminder that lawyers are obligated under Comment [8] to Rule 1.1 to keep abreast of the benefits and risks associated with technology lawyers use to provide services to clients or to store or transmit confidential information, and under Rule 1.6(c), to make reasonable efforts to prevent inadvertent or unauthorized disclosure or use of, or access to, such information.

Data Breaches

When a data breach does occur, what duties do lawyers and law firms have? Comment [17] to Rule 1.6 provides that in certain situations, a lawyer may be required to take specific steps to safeguard a client’s information in order to comply with laws, such as state and federal laws, or with court rules, that govern data privacy or that impose notification requirements upon the loss of, or unauthorized access to, client confidential electronic information.

To that end, it is important to bear in mind that each of the fifty U.S. states has a data security breach notification law that requires the notification of affected individuals and, in certain instances state Attorneys General or agencies, of the unauthorized access to or use of certain types of personal information.

There are also notification requirements under the Health Insurance Portability and Accountability Act (HIPAA), which could apply to a law firm representing a client that is a HIPAA-covered entity, and other rules, such as the Federal Trade Commission’s Breach Notification Rule, which applies to health data not governed by HIPAA.

The EU General Data Protection Regulation (GDPR) and the UK’s version of that law since Brexit, which apply to the personal data of individuals in the EU and in the UK, respectively, require notification within seventy-two (72) hours of a personal data breach.

Under Rule 1.4, lawyers are required to promptly inform a client of any information required by a court rule or other law to be communicated to a client, and of material developments in a matter; to keep the client reasonably informed about the status of the matter; to promptly comply with a client’s reasonable requests for information; and to explain the matter to the extent reasonably necessary to permit the client to make informed decisions regarding the firm’s representation of the client.

In Hiscox Insurance Co. v. Warden Grier, LLP, 474 F. Supp. 3d 1004 (W.D. Missouri 2020), where client confidential information was compromised, the law firm did not promptly notify its client, an insurance company, and the client learned two years after the firm sustained a security breach that the client’s insureds’ personal information had been leaked to the dark web.

Having undertaken its own investigation of the matter, the insurer decided to notify its insureds of the breach and commenced a lawsuit against the firm, alleging breach of contract, breach of implied contract, breach of fiduciary duty and negligence. The court denied the firm’s motion to dismiss the first three counts, holding that the plaintiff had properly pled facts to support each of the separate claims alleged.

Phishing

Stolen data and ransomware attacks, which encrypt data so it can no longer be accessed (unless a ransom is paid for the encryption key), are often perpetrated by phishing schemes against law firms. For example, in Otto v. Catrow Law PLLC, 243 W. Va. 709, 850 S.E.2d 708 (S. Ct. App. 2020), a case involving a residential real estate transaction, a real estate agent’s unencrypted e-mail was intercepted by scammers who succeeded in convincing the buyers to wire funds to the scammers’ account, instead of the law firm’s account.

In their legal malpractice action against the firm, the buyers “alleged that bulletins sent to [the firm] as an agent/attorney for [the title company] warning of phishing scams gave rise to a duty for [the firm] to warn [the buyers] against someone substituting fake wiring instructions into the transaction.” Id. at 713.

The buyers alleged that the firm breached this duty by failing to alert the parties to the real estate transaction, including the buyers, of such risk. Acknowledging that a lawyer has a duty “to disclose anything known to him which might affect his client’s decision whether or how to act,” the court ruled in favor of the firm, holding that the buyers had failed to demonstrate that the firm actually knew of the phishing scams. Id. at 716.

Conclusion

With rapidly evolving technology and sweeping developments in data security and in privacy laws and regulations, lawyers and law firms need to be acutely aware of the risks associated with cybersecurity. Alongside those concerns, attorneys must observe their ethical duties under the Rules, as well as their legal obligations under data protection laws and applicable regulatory regimes.


Reprinted with permission from the July 05, 2023 issue of the New York Law Journal, © 2023 ALM Media Properties, LLC. Further duplication without permission is prohibited.  All rights reserved. Further duplication without permission is prohibited, contact 877-256-2472 or asset-and-logo-licensing@alm.com.

Resources