Skip to Main Content

Data Incident Response

Print Version

When incidents arise, Baker Donelson's credentialed data incident response team provides real-time legal and highly technical advice 24/7/365.

Featured Videos

How To Prepare for a Cybersecurity Incident February 17, 2021
Cybersecurity for Financial Institutions: Essential Information on Cyber Incidents and Regulatory Issues November 18, 2020
COVID-19: Cybersecurity and Data Privacy Considerations for Financial Institutions April 7, 2020
Coronavirus: Privacy, Security and Telehealth for Long Term Care Providers March 31, 2020
Coronavirus (COVID-19): What Your Business Should Do Right Now March 11, 2020
M&A and Cyber Risk: The Intersection Between Growth and Risk May 21, 2019

Practice Overview

When incidents arise, Baker Donelson's credentialed data incident response team provides real-time legal and highly technical advice 24/7/365. We assist clients through all phases of a data incident. Our established relationships with forensic investigators, consumer notification mail houses, call centers and public relations firms provide clients the ability to staff even the largest breach matters from the first call.

More than one-third of our Data Incident Response Team includes members who are certified by the International Association of Privacy Professionals (IAPP) as Certified Information Privacy Professionals (CIPP/US, CIPP/E and/or CIPP/C) and two attorneys who are Certified Information Privacy Managers (CIPM). In addition, we have a team member certified in the Law of Data Security and Investigations (GLEG) and another who is certified as a Payment Card Industry Professional (PCIP). We have attorneys who specialize in handling incident responses in highly regulated industries, such as education, financial institutions and health care. Our team also includes the former general counsel of the Department of Homeland Security.

We assist clients through all phases of a data incident including:

  • Working with industry experts to assist with detection, containment and recovery;
  • Collaborating with expert third-party ransomware responders to advise clients on ransomware negotiations;
  • Coordinating e-Discovery efforts when intrusions are identified;
  • Communicating on behalf of our clients with state and federal law enforcement agencies with whom we have established relationships;
  • Assisting with assessment and drafting of any state and federal notification obligations;
  • Managing communications with vendors, employees, customers and other stakeholders;
  • Responding to any state and federal government investigations that result from an incident;.
  • Providing analysis to assist in developing post-incident remediation; and
  • Representing clients in ensuing litigation, including class action cases, involving data incident issues.
  • Represented health care technology company managing ransomware incident which included leading the incident response team of cyber experts, advising on ransomware negotiation, reviewing client contracts, conducting HIPAA and multi-state breach notification analysis and overseeing crisis communications with employees and clients.

  • Assisted a national transportation and logistics company managing ransomware incident including ransomware negotiation, law enforcement interaction, breach notification assessment and developing communications playbook.

  • Advised U.S. distributor for international company in managing phishing incident that led to significant wire fraud, including providing advice on compliance with GDPR and state and federal privacy and breach notification laws.

  • Represented a national bank whose vendor experienced a data incident that impacted hundreds of the bank’s corporate customers and more than 250,000 individuals.

  • Successfully negotiated a ransomware incident on behalf of a school board in a ransomware attack that resulted in network interruptions to schools providing education to more than 5,000 children.

  • Advised a leading e-commerce company that was severely impacted by a phishing attack on multiple employee e-mail accounts that required assessment of regulatory issues under the Payment Card Industry Data Security Standards (PCI-DSS) and responding to regulatory investigations by state attorneys general.

  • Successfully represented a large hospital system that experienced a data breach in the subsequent investigation by the Office for Civil Rights.

  • Advised a national brokerage firm with respect to potential individual and regulatory notification obligations arising from employee theft of electronic information.

  • Represented a bank in a wire fraud incident which resulted in a return of a portion of the stolen funds.

  • Assisted a mental health facility in responding to an incident involving a former employee's theft and misappropriation of patient mental health records.

  • Advised a network of automotive dealerships on breach notification obligations and remediation of a data incident related to theft of employee information.

  • Successfully resolved class action litigation against a national company resulting from data incident relating to a phishing attack on a company employee.
  • Assisted a national mortgage company with notification to individuals as well as state and federal regulators in response to an inadvertent email incident.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept