Custom IT Solutions for All Types of Industries

Data Collaboration Services empowers industry-specific transformation through secure, scalable, and intelligent data solutions.

Cloud Solutions

Finance

Financial institutions in New York are not only bound by national regulations like PCI-DSS, SOX, and GDPR, but also face local regulatory demands, such as those set by the NYDFS.
Data Backup & Recovery

Healthcare

Healthcare providers today face the dual challenge of improving patient care while navigating complex technological and regulatory requirements.

The Breach Wasn’t at the Hospital. It Was at the Law Firm.

A Thompson Coburn data breach exposed Social Security numbers and medical records of 305,088 Presbyterian Healthcare patients.

Published

What Happened

A client trusted the firm with its data. The firm got breached.

On May 29, 2024, the national law firm Thompson Coburn LLP detected unauthorized activity on its network. The intrusion was brief investigators later pinned the access window to roughly May 28–29 but the damage was not. The files the attacker viewed or took didn’t belong to the firm. They belonged to the firm’s client, Presbyterian Healthcare Services, a New Mexico nonprofit health system whose health plan serves more than 580,000 members.

Thompson Coburn was holding protected health information on Presbyterian’s patients in connection with its legal work. When the firm’s network was compromised, that PHI was compromised too. The law firm ultimately reported to the U.S. Department of Health and Human Services that 305,088 individuals were affected.

No known ransomware group ever claimed the attack, and the firm said it found no evidence of resulting identity theft. But that’s cold comfort for a third of a million people whose Social Security numbers and medical records were sitting on a law firm’s server they had never heard of and whose exposure was entirely outside their control.

By the Numbers

The scale of a single client’s exposure

305,088
Patients whose data was exposed in the breach
May 29
Date unauthorized network activity was detected
580K+
Members served by the affected client’s health plan
1
Client relationship that put all those records on the firm’s network
11
Named plaintiffs in the class action that followed
0
Ransomware groups that ever claimed the attack
Key Facts

What was exposed

A full medical and financial profile on a law firm’s network

  • Full names and Social Security numbers
  • Dates of birth and medical record numbers
  • Patient account numbers and health insurance information
  • Prescription and treatment information and clinical data
  • Medical provider information
  • Data belonged to a client’s patients not to the firm’s own staff

This is the part that should stop every firm owner cold. Thompson Coburn wasn’t breached to steal Thompson Coburn’s secrets. It was breached because it was the easiest door into someone else’s data. The law firm became the weak link in the hospital’s security and the patients paid for it.

The Cascade

Your firm is a vault for other people’s most sensitive information

Every professional services firm runs on the same uncomfortable arrangement: clients hand over their most sensitive material, and trust you to guard it as well as they would. A law firm’s servers can hold medical records, Social Security numbers, financial statements, merger plans, and privileged communications data its clients are legally and ethically obligated to protect, now sitting one network away from the client’s own controls.

That makes your firm a force multiplier for attackers. One intrusion at Thompson Coburn reached 305,088 people who were never the firm’s clients at all they were a client’s patients. Breach a hospital and you get one hospital’s data. Breach the hospital’s law firm, and you may get the same data with a fraction of the security in the way.

And the exposure flows in both directions. When your firm is breached, your client’s name ends up in the headline next to yours and your client starts asking hard questions about whether they should trust you with the next matter. In this case both Thompson Coburn and Presbyterian were named as defendants. The firm’s security failure became its client’s problem, its client’s lawsuit, and its client’s reputational hit.

Legal & Regulatory Fallout

The lawsuit collapsed. The consequences didn’t.

A proposed class action was filed in federal court in Missouri, naming both Thompson Coburn and Presbyterian Healthcare Services and alleging negligent cybersecurity practices that led to the exposure of patients’ personal and health information. For a while it looked like a textbook data-breach suit.

Then it unraveled. In February 2026, ten of the eleven named plaintiffs voluntarily dismissed their claims, and the case was dismissed without prejudice. On paper, the defendants “won.” But here’s the trap business owners should understand: a dismissed lawsuit doesn’t undo the breach. The HHS filing is permanent. The 305,088 notification letters were still sent. The credit-monitoring bill, the forensic investigation, the legal fees, and the client’s loss of confidence all happened regardless of how the litigation ended.

For a firm holding healthcare data, the regulatory stakes are higher still. PHI exposure can implicate HIPAA obligations and a patchwork of state breach-notification laws, each with its own deadlines and penalties and a law firm carries its own ethical duty to safeguard client confidences on top of all of it. Winning the lawsuit is the best-case outcome, and it’s still expensive, public, and permanent.

Action Steps

What your firm should do this week

  1. Map where your clients’ sensitive data actually lives. You can’t protect what you can’t see. Inventory every place SSNs, health records, and financial data sit across your network, email, file shares, and laptops most firms badly underestimate how much they hold and where.
  2. Minimize and segregate the data you keep. If a matter is closed, you may not need to keep a client’s full PHI on a live server. Archive or purge what you no longer need, and isolate the most sensitive client data so one intrusion can’t reach all of it.
  3. Encrypt sensitive data at rest and in transit. If attackers reach an encrypted file store, what they steal is useless. Encryption is one of the few controls that turns a catastrophic breach into a non-event and regulators take note of it.
  4. Tighten access and watch for unusual activity. Limit who can reach client data to those who actually need it, enforce multi-factor authentication, and monitor for the kind of unauthorized network access Thompson Coburn caught ideally before files are taken, not after.
  5. Have a tested incident and notification plan ready. Know in advance who you call, how you preserve evidence, and how you meet HIPAA and state breach-notification deadlines and brief your clients on your safeguards before they have to ask.
The Bottom Line

When clients trust you with their data, your security is their security

Thompson Coburn didn’t lose its own confidential files it lost a client’s. That’s the quiet truth of this breach: a law firm’s biggest cyber liability often isn’t its own information at all. It’s the mountain of sensitive client data it has agreed to protect, sitting on a network that may not be guarded the way the client assumes it is.

The lawsuit went away. The breach never will. For 305,088 people, a law firm they’d never heard of became the reason their medical records and Social Security numbers were exposed. If your firm holds clients’ confidential, financial, or health data and almost every firm does the question isn’t whether you’d be sued. It’s whether you’d survive being the headline. If you’re not sure your safeguards would hold up to that scrutiny, that’s the gap to close now, while it’s still hypothetical.

Stay Ahead of Threats

Get weekly insights on the latest vulnerabilities, breach analysis, and defense strategies delivered directly to your inbox.

End-to-end encrypted delivery