---
title: "Law Firm Data Breach Decisions That Preserve Client Trust"
url: "https://lawyermagazine.co/qa/law-firm-data-breach-decisions-that-preserve-client-trust/"
author: "Lawyer Magazine"
published: "2026-10-06"
updated: "2026-10-06"
---

# Law Firm Data Breach Decisions That Preserve Client Trust

## Law Firm Data Breach Decisions That Preserve Client Trust

When a law firm faces a data breach, every message can affect client trust. Experts in the field share practical guidance on when to disclose, whom to contact, and what to say. These steps help firms provide clear facts and prompt protective action.

### Use Two-Stage Disclosure

A suspected data breach at a law firm is uniquely terrifying because attorneys handle some of the most sensitive information imaginable—Social Security numbers, financial records, bankruptcy filings, litigation strategy. When that trust is potentially compromised, the stakes go beyond reputation; they touch directly on ethical duties under Rules of Professional Conduct governing confidentiality, plus breach notification laws that vary significantly by state.

My decision framework starts with an immediate, contained investigation before any external communication—not to delay disclosure, but to ensure what we tell clients is accurate rather than speculative. Premature, incorrect statements damage credibility worse than delayed but precise ones. I involve forensic IT specialists and outside counsel specializing in data privacy immediately, because determining scope, cause, and whether actual client data was compromised (versus mere unauthorized access attempts) shapes both legal notification obligations and the content of client communication.

Once we have reliable facts, I follow a rule that has served me well: disclose what's confirmed, acknowledge what's still under investigation, and always pair bad news with protective action already underway. Clients don't need speculation; they need honesty about what's known and reassurance that concrete steps are happening in real-time.

One specific decision that reduced legal risk while preserving trust involved a suspected phishing attempt against our email system years ago. Rather than issuing a vague, anxiety-inducing notice or waiting until we had absolutely every detail, we sent an initial communication within 48 hours stating clearly: unauthorized access was detected, here's exactly what data was potentially exposed, here's what wasn't, and here's the specific monitoring and protective measures already implemented, including credit monitoring services offered proactively for affected clients.

That two-stage communication—prompt initial transparency followed by comprehensive final disclosure—satisfied state notification timing requirements, demonstrated good faith diligence rather than concealment, and critically, gave clients actionable information immediately instead of leaving them anxiously waiting weeks for answers. Not a single client left the practice over that incident, and several specifically praised the communication approach afterward.

*— [Loretta Kilday](https://www.linkedin.com/in/lorettakilday/), DebtCC Spokesperson, Debt Consolidation Care*

---

### Prioritize Direct Conversations

I would not treat every client as though the potential exposure carried the same consequences. A family law firm can hold highly sensitive financial records, medical information, communications, and documents involving children. If an investigation showed that a particular client's information might have been exposed, I would prioritize a direct conversation with that client rather than relying solely on a general notice. 

I would also avoid reassuring language that goes beyond the evidence. Something as simple as, "We have contained the issue, but our investigation is still determining what information, if any, was accessed," gives the client useful information without pretending we know more than we do. In my view, that balance protects credibility because the client can see both the seriousness of the response and the limits of what we currently know.

*— [Joy Owenby](https://www.linkedin.com/in/joyowenby/), Founder and Family Law Attorney, Owenby Law, P.A.*

---

### Deliver Actionable Facts Promptly

In a suspected law-firm data breach, client communication should be driven by the sensitivity of the information, the credibility of the suspected compromise, applicable notification duties, and what clients need to do to protect themselves, rather than waiting for every forensic detail to be resolved. ABA Formal Opinion 483 says that when material client information has been accessed, disclosed, or is reasonably suspected of being compromised, affected clients should receive enough information to make informed decisions, with continuing updates as material facts develop. A message that can reduce both legal and reputational risk is a simple, factual one: "A security incident has been identified, the investigation is ongoing, these categories of information may be affected, immediate protective measures have been taken, and further confirmed information will be communicated as it becomes available." That approach avoids speculation while preventing silence from becoming the story. The FTC similarly advises organizations to communicate clearly, avoid misleading statements, explain what is known, describe remediation steps, and provide practical guidance to affected individuals. The broader leadership lesson is that breach communication should be treated as an ongoing process rather than a single announcement: disclose material facts promptly when required, distinguish confirmed findings from preliminary indicators, preserve investigative integrity, and keep affected clients reasonably informed as the picture becomes clearer.

*— [Arvind Rongala](https://www.linkedin.com/in/arvindrongala/), CEO, Edstellar*

---

### Verify Exposure Before Targeted Outreach

If I suspected a breach, I would resist the temptation to send a firmwide message to clients before we knew what happened. My first concern would be preserving evidence, involving the appropriate technology and legal professionals, and determining whether client information actually became accessible. At the same time, I would identify which clients might face a particular risk so we could communicate with them directly rather than send everyone the same vague warning. 

The message I would use would be straightforward: we identified a potential security issue, we are investigating it, and we will provide another update when we have verified information that affects the client. That approach avoids making unsupported statements while showing the client that we took the concern seriously. I would rather give a client a careful answer a little later than speculate and have to correct it.

*— [Gerard Virga](https://www.linkedin.com/in/gerard-virga-006a9263/), Founding Attorney, The Virga Law Firm, P.A.*

---

### Appoint One Communications Lead

My first concern would be making sure the response itself does not create another problem. I would limit the initial information to what we could confirm, involve the appropriate privacy and security professionals, and determine which clients actually faced a meaningful risk. I would rather give a client a short, accurate update than send a lengthy notice filled with technical details that might later prove wrong. 

One step I would take is to designate a single person to coordinate client communications throughout the investigation. That prevents different members of the firm from giving clients inconsistent answers as new information comes in. I would also tell affected clients when they could expect the next update, even if we had nothing new to report. Keeping that promise goes a long way toward maintaining trust when the facts are still developing.

*— [Loren Schwartz](https://www.linkedin.com/in/loren-schwartz-5a649640/), Attorney, Rouda Feder Tietjen & McGuinn*

---

### Call Highest-Risk Individuals First

If I were dealing with a suspected breach at my firm, my first concern would be the clients whose private family and financial information might be involved. I would not want a client learning about a potential exposure from a generic firmwide email before I had taken the time to understand what happened. I would work with our technology and privacy professionals to establish the facts, identify which clients might be affected, and determine what we needed to tell them. I would also be careful not to promise certainty while the investigation remained ongoing. 

One thing I would do personally is call the clients facing the greatest potential exposure before sending a formal notice. I would tell them what we knew, what we were still investigating, and what steps we had taken to protect their information. I think that human conversation matters, particularly in family law, where clients often give their lawyer information they would never want outside the office. Even when I could not immediately answer every question, being willing to have that conversation would help maintain the trust we had built.

*— [Judith Sadler](https://www.linkedin.com/in/judithsadler), Managing Shareholder, Diggs & Sadler*

---

### Make Notices Drive Protective Action

Treat a breach notice as a decision document, not a PR statement. The test is simple: after reading it, can the client make a better choice? If not, the message is either too vague or too early. For a tax practice, the risks go beyond identity theft. Exposed data can lead to fraudulent returns, fake payment instructions, or leaks that weaken a client's position with a tax agency.

I'd notify affected clients once the firm knows what type of data was involved and what safeguards are in place. A strong first notice says an investigation is underway, says whether any misuse has been confirmed, and gives one clear action. For example, tell clients to confirm any request to change payment details by calling a number they already know. Specific steps like that ease panic and reduce fraud risk.

*— [Jonathan Sooriash](https://www.linkedin.com/in/jonathan-sooriash-esq-ll-m-10a91a14), Founder & CEO, J. David Tax law*

---

### State Unknowns With Candor

I would be very careful about giving a client either too little information or information that has not been verified. In a suspected breach, I would first determine what happened, what information may have been exposed, and whether the incident affects the client's representation. At the same time, I would not wait for every forensic question to be answered before communicating when the circumstances create a duty to notify. As licensed attorneys, we have a duty-bound obligation to notify our clients when a breach involves, or is substantially likely to involve, material confidential client information. 

If this were to occur, we are likely to tell the client what we know, what we do not know yet, and what we are doing about it. I would avoid reassuring them that "everything is fine" simply because the investigation is incomplete. A short, factual update that acknowledges the uncertainty and explains the protective steps being taken gives the client useful information without speculating. I think that distinction matters because trust is much easier to preserve when a client sees that you are being candid about an uncomfortable situation rather than trying to manage their reaction to it.

*— [John A. Fallk](https://www.linkedin.com/in/johnafalk), Managing Partner, Faraci Lange, LLP*

---

### Report Confirmed Access Without Delay

When dealing with a suspected breach, disclosure should happen the moment unauthorized access to sensitive information is confirmed, rather than waiting weeks for full forensic finality. The key decision that preserves trust while mitigating legal risk is communicating clearly about what is verified, what remains uncertain, and what concrete steps are being taken to secure client files.

As an attorney at Simmons & Fletcher in Houston, I believe handling these situations comes down to basic professional ethics and duty of care. Our clients entrust us with deeply private medical and personal records. Waiting too long to speak or hiding behind vague language only multiplies legal exposure once facts emerge. Direct, early communication protects both the firm's standing and the client's interests.

*— [Paul Cannon](https://www.linkedin.com/in/paul-h-cannon/), Attorney, Simmons & Fletcher*

---

### Related Articles

- [Your Law Firm’s First Steps After a Cyber Scare](https://lawyermagazine.co/qa/your-law-firms-first-steps-after-a-cyber-scare)
- [Law Firm Data Breach Readiness That Actually Works](https://lawyermagazine.co/qa/law-firm-data-breach-readiness-that-actually-works)
- [Deliver Bad News in Legal Matters Without Losing the Client](https://lawyermagazine.co/qa/deliver-bad-news-in-legal-matters-without-losing-the-client)
