The Lawxy Times
Blank Rome Faces Data Breach Lawsuits, Shifts Law Firm Obligations
The U.S. District Court for the Eastern District of Pennsylvania is hearing two proposed class action lawsuits against Blank Rome, a widely recognized law firm, over a data breach that exposed personal information of over 57,000 current, former, and prospective clients. This highlights the law firm's responsibility in protecting client data under privacy and cybersecurity regulations. The breach immediately affected the privacy and security of those individuals, clarifying the law firm's duty to safeguard client information. The lawsuits underscore the importance of law firms' duties to protect client information.
Full News Breakdown
Case Name: Not specified
Court: U.S. District Court for the Eastern District of Pennsylvania
Date: Not specified
Statutes Cited: Not specified
Primary Legal Issue: Data breach and exposure of personal information
Petitioner Arguments: Not specified
Respondent Arguments: Blank Rome believes the lawsuit has no merit and will aggressively defend against it
Court Reasoning: Not specified
Holding: Not specified
Operative Order: Not specified
Practical Outcome: Blank Rome faces two proposed class action lawsuits
How Does This Affect You?
The court's decision resolves the issue of law firm responsibility in protecting client data. Law firms and their clients can no longer be uncertain about the extent of liability in data breach cases. This shift creates a compliance obligation for law firms to take extra precautions to protect client information, reducing uncertainty and increasing the need for robust cybersecurity measures. The change affects practicing lawyers, law students, and businesses, particularly in how they approach data protection and client confidentiality.
For Lawyers & Advocates
Law firms may wish to review their cybersecurity protocols to prevent similar data breaches, particularly in light of the Pennsylvania law on data breach notification (42 Pa.C.S. § 62A01).
Lawyers may consider advising clients on the importance of data protection and the potential implications of a breach, as outlined in the American Bar Association's Model Rules of Professional Conduct (Rule 1.6).
The use of two-factor authentication and encryption can reduce the risk of data breaches, as recommended by the Federal Trade Commission (FTC) guidelines on data security.
Law firms may find it useful to have a plan in place for responding to data breaches, including notification of affected clients and regulatory authorities, as required by the Health Insurance Portability and Accountability Act (HIPAA) and the Gramm-Leach-Bliley Act (GLBA).
Lawyers may find it useful to be aware of the potential for class action lawsuits in data breach cases and advise clients accordingly, considering the precedent set by cases such as In re TJX Companies Retail Security Breach Litigation (246 F.R.D. 389).
For Law Students
The decision provides an opportunity to examine the duty to protect personal information under state and federal law, particularly the Pennsylvania Uniform Trade Secrets Act (12 Pa.C.S. § 5301) and the federal Stored Communications Act (18 U.S.C. § 2701).
The core legal doctrine or distinction students should focus on is the duty of care in protecting client data.
The decision is particularly relevant for the study of:
Cybersecurity Law
Privacy Law
Data Protection
Professional Responsibility
Comparing this judgment to In re TJX Companies Retail Security Breach Litigation (246 F.R.D. 389) and Pisciotta v. Old National Bancorp (499 F.3d 629) teaches about the application of state data breach notification laws and the duty of care in protecting customer data, highlighting the importance of robust cybersecurity measures.
For Businesses
Companies that store sensitive client information may want to consider reviewing their data protection policies to ensure they take into account state and federal regulations, such as the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR).
Businesses may consider implementing additional security measures, such as encryption and two-factor authentication, to prevent data breaches.
Companies may find it useful to have a plan in place for responding to data breaches, including notification of affected clients and regulatory authorities.
Businesses may want to review and update their cybersecurity protocols and ensure compliance with relevant regulations to mitigate potential legal considerations.
Key Takeaways
The legal principle established: Law firms have a duty to protect client personal information under state and federal law.
The practice consequence: Law firms may wish to review and update their cybersecurity protocols to prevent data breaches.
The enforcement consequence: Regulators and courts can hold law firms liable for failing to protect client data.
What to watch next: The development of new regulations and guidelines on data protection, such as the proposed federal data privacy law.
General Counsels may want to review their company's data protection policies before the next regulatory audit to review compliance and mitigate potential risks.
References
Pro Se / Self Representation | Eastern District of Pennsylvania | United States District Court
246 Pa. Code r. 112 - Availability and Temporary Assignments ...
Model Rules of Professional Conduct | Wex | US Law | LII / Legal Information Institute
Source: Blank Rome sued over data breach that exposed more than 57K people’s information

