PRACTICE AREA
Most companies do not call cyber counsel because everything is going well. They call when they discover a potential breach, receive a report of suspicious activity, learn that customer information may have been exposed, or find themselves trying to determine what happened and what they are legally required to do next.
In those moments, uncertainty is often the greatest challenge.
Dorwart helps companies navigate cybersecurity incidents, data breaches, privacy obligations, and regulatory notification requirements. We advise businesses, financial institutions, healthcare organizations, and other companies facing cybersecurity events ranging from inadvertent disclosures to sophisticated cyberattacks.
Dorwart helps clients answer those questions and move forward with confidence.
Cybersecurity incidents rarely happen at convenient times. Clients need counsel who can respond quickly, understand the regulatory landscape, coordinate with technical professionals, and provide practical guidance under pressure.
Dorwart helps organizations manage cybersecurity events, satisfy regulatory obligations, and protect their businesses when the stakes are highest.
Dorwart represented a company responding to a cybersecurity incident involving a third-party vendor. The incident resulted in the unauthorized acquisition of consumer information that was subsequently posted on the dark web.
The matter involved individuals located across all 50 states and several foreign countries, creating significant regulatory complexity.
Dorwart worked with the client to establish the protections of attorney-client privilege, analyze affected data, identify impacted individuals, evaluate notification obligations, and coordinate regulatory reporting. The team focused on rapidly assessing complex facts while ensuring compliance with dozens of overlapping state notification requirements.
The company successfully completed a nationwide notification effort involving more than 50,000 consumer notices using numerous versions of notice letters because of the complex nature of the facts. Dorwart also managed multiple regulatory notifications including to multiple state attorneys general and one relevant federal regulator. The response was completed within applicable legal deadlines.
The client was able to satisfy its legal obligations, manage a significant cybersecurity event, and move forward without follow-on litigation.
Represented a company that experienced a data security incident caused by software-related issues rather than malicious activity.
After evaluating the nature of the exposed information and the affected individuals, Dorwart advised that notification obligations were not triggered. The client avoided unnecessary notification costs and disruption while remaining compliant with applicable legal requirements.
Advised clients regarding healthcare-related cybersecurity incidents and HIPAA breach notification obligations. Guided clients through investigation, risk assessment, notification analysis, and regulatory compliance decisions.
Advised financial institutions regarding cybersecurity incidents and notification obligations under various regulatory frameworks, including GLBA and industry-specific requirements.
Experience and Insight for your most complex legal matters
Meet the Lawyers Who Practice in This Area