Skip to Main Content
Practices

Data Incident Response

Print Version

When incidents arise, Baker Donelson's credentialed data incident response team provides real-time legal and highly technical advice 24/7/365.

Featured Videos


Ransomware Attacks in 2021: How to Navigate the Evolving Threat Landscape July 21, 2021
Additional Incident Response Considerations – Protecting the Attorney-Client Privilege and Involving Your Board of Directors May 19, 2021
Incident Response: What You Need to Know April 30, 2021
How To Prepare for a Cybersecurity Incident February 17, 2021
Cybersecurity for Financial Institutions: Essential Information on Cyber Incidents and Regulatory Issues November 18, 2020
COVID-19: Cybersecurity and Data Privacy Considerations for Financial Institutions April 7, 2020

Practice Overview


When incidents arise, Baker Donelson's credentialed data incident response team provides real-time legal and highly technical advice 24/7/365. We assist clients through all phases of a data incident. Our established relationships with forensic investigators, consumer notification mail houses, call centers and public relations firms provide clients the ability to staff even the largest breach matters from the first call.

More than one-third of our Data Incident Response Team includes members who are certified by the International Association of Privacy Professionals (IAPP) as Certified Information Privacy Professionals (CIPP/US, CIPP/E and/or CIPP/C) and two attorneys who are Certified Information Privacy Managers (CIPM). In addition, we have a team member certified in the Law of Data Security and Investigations (GLEG) and another who is certified as a Payment Card Industry Professional (PCIP). We have attorneys who specialize in handling incident responses in highly regulated industries, such as education, financial institutions and health care. Our team also includes the former general counsel of the Department of Homeland Security.

We assist clients through all phases of a data incident including:

  • Working with industry experts to assist with detection, containment and recovery;
  • Collaborating with expert third-party ransomware responders to advise clients on ransomware negotiations;
  • Coordinating e-Discovery efforts when intrusions are identified;
  • Communicating on behalf of our clients with state and federal law enforcement agencies with whom we have established relationships;
  • Assisting with assessment and drafting of any state and federal notification obligations;
  • Managing communications with vendors, employees, customers and other stakeholders;
  • Responding to any state and federal government investigations that result from an incident;.
  • Providing analysis to assist in developing post-incident remediation; and
  • Representing clients in ensuing litigation, including class action cases, involving data incident issues.
  • Led incident response team for a medical information technology company following a ransomware incident. Oversaw HIPAA issues, regulator issues and breach notification in multiple states, and managed law enforcement interaction, overseeing crisis communications and litigation arising from the data breach.

  • Managed ransomware incident for a national transportation and logistics company. Led the incident response team managing breach notification in multiple states, law enforcement interaction, overseeing crisis communications and compliance with relevant breach notification laws across 30 states.

  • Represented U.S. distribution company for international lubricants company in managing phishing incident that led to significant wire fraud. Managed the response dealing with U.S. privacy laws, GDPR, law enforcement interaction and breach notification in more than 14 states.

  • Represented a national bank whose vendor experienced a data incident that impacted hundreds of the bank’s corporate customers and more than 250,000 individuals.

  • Successfully negotiated a ransomware incident on behalf of a school board in a ransomware attack that resulted in network interruptions to schools providing education to more than 5,000 children.

  • Advised a leading e-commerce company that was severely impacted by a phishing attack on multiple employee e-mail accounts that required assessment of regulatory issues under the Payment Card Industry Data Security Standards (PCI-DSS) and responding to regulatory investigations by state attorneys general.

  • Successfully represented a large hospital system that experienced a data breach in the subsequent investigation by the Office for Civil Rights.

  • Advised a national brokerage firm with respect to potential individual and regulatory notification obligations arising from employee theft of electronic information.

  • Represented a bank in a wire fraud incident which resulted in a return of a portion of the stolen funds.

  • Assisted a mental health facility in responding to an incident involving a former employee's theft and misappropriation of patient mental health records.

  • Advised a network of automotive dealerships on breach notification obligations and remediation of a data incident related to theft of employee information.

  • Successfully resolved class action litigation against a national company resulting from data incident relating to a phishing attack on a company employee.
  • Assisted a national mortgage company with notification to individuals as well as state and federal regulators in response to an inadvertent email incident.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept