A client trusted the firm with its data. The firm got breached.
On May 29, 2024, the national law firm Thompson Coburn LLP detected unauthorized activity on its network. The intrusion was brief investigators later pinned the access window to roughly May 28–29 but the damage was not. The files the attacker viewed or took didn’t belong to the firm. They belonged to the firm’s client, Presbyterian Healthcare Services, a New Mexico nonprofit health system whose health plan serves more than 580,000 members.
Thompson Coburn was holding protected health information on Presbyterian’s patients in connection with its legal work. When the firm’s network was compromised, that PHI was compromised too. The law firm ultimately reported to the U.S. Department of Health and Human Services that 305,088 individuals were affected.
No known ransomware group ever claimed the attack, and the firm said it found no evidence of resulting identity theft. But that’s cold comfort for a third of a million people whose Social Security numbers and medical records were sitting on a law firm’s server they had never heard of and whose exposure was entirely outside their control.
The scale of a single client’s exposure
What was exposed
A full medical and financial profile on a law firm’s network
- Full names and Social Security numbers
- Dates of birth and medical record numbers
- Patient account numbers and health insurance information
- Prescription and treatment information and clinical data
- Medical provider information
- Data belonged to a client’s patients not to the firm’s own staff
This is the part that should stop every firm owner cold. Thompson Coburn wasn’t breached to steal Thompson Coburn’s secrets. It was breached because it was the easiest door into someone else’s data. The law firm became the weak link in the hospital’s security and the patients paid for it.
Your firm is a vault for other people’s most sensitive information
Every professional services firm runs on the same uncomfortable arrangement: clients hand over their most sensitive material, and trust you to guard it as well as they would. A law firm’s servers can hold medical records, Social Security numbers, financial statements, merger plans, and privileged communications data its clients are legally and ethically obligated to protect, now sitting one network away from the client’s own controls.
That makes your firm a force multiplier for attackers. One intrusion at Thompson Coburn reached 305,088 people who were never the firm’s clients at all they were a client’s patients. Breach a hospital and you get one hospital’s data. Breach the hospital’s law firm, and you may get the same data with a fraction of the security in the way.
And the exposure flows in both directions. When your firm is breached, your client’s name ends up in the headline next to yours and your client starts asking hard questions about whether they should trust you with the next matter. In this case both Thompson Coburn and Presbyterian were named as defendants. The firm’s security failure became its client’s problem, its client’s lawsuit, and its client’s reputational hit.
The lawsuit collapsed. The consequences didn’t.
A proposed class action was filed in federal court in Missouri, naming both Thompson Coburn and Presbyterian Healthcare Services and alleging negligent cybersecurity practices that led to the exposure of patients’ personal and health information. For a while it looked like a textbook data-breach suit.
Then it unraveled. In February 2026, ten of the eleven named plaintiffs voluntarily dismissed their claims, and the case was dismissed without prejudice. On paper, the defendants “won.” But here’s the trap business owners should understand: a dismissed lawsuit doesn’t undo the breach. The HHS filing is permanent. The 305,088 notification letters were still sent. The credit-monitoring bill, the forensic investigation, the legal fees, and the client’s loss of confidence all happened regardless of how the litigation ended.
For a firm holding healthcare data, the regulatory stakes are higher still. PHI exposure can implicate HIPAA obligations and a patchwork of state breach-notification laws, each with its own deadlines and penalties and a law firm carries its own ethical duty to safeguard client confidences on top of all of it. Winning the lawsuit is the best-case outcome, and it’s still expensive, public, and permanent.
What your firm should do this week
- Map where your clients’ sensitive data actually lives. You can’t protect what you can’t see. Inventory every place SSNs, health records, and financial data sit across your network, email, file shares, and laptops most firms badly underestimate how much they hold and where.
- Minimize and segregate the data you keep. If a matter is closed, you may not need to keep a client’s full PHI on a live server. Archive or purge what you no longer need, and isolate the most sensitive client data so one intrusion can’t reach all of it.
- Encrypt sensitive data at rest and in transit. If attackers reach an encrypted file store, what they steal is useless. Encryption is one of the few controls that turns a catastrophic breach into a non-event and regulators take note of it.
- Tighten access and watch for unusual activity. Limit who can reach client data to those who actually need it, enforce multi-factor authentication, and monitor for the kind of unauthorized network access Thompson Coburn caught ideally before files are taken, not after.
- Have a tested incident and notification plan ready. Know in advance who you call, how you preserve evidence, and how you meet HIPAA and state breach-notification deadlines and brief your clients on your safeguards before they have to ask.
When clients trust you with their data, your security is their security
Thompson Coburn didn’t lose its own confidential files it lost a client’s. That’s the quiet truth of this breach: a law firm’s biggest cyber liability often isn’t its own information at all. It’s the mountain of sensitive client data it has agreed to protect, sitting on a network that may not be guarded the way the client assumes it is.
The lawsuit went away. The breach never will. For 305,088 people, a law firm they’d never heard of became the reason their medical records and Social Security numbers were exposed. If your firm holds clients’ confidential, financial, or health data and almost every firm does the question isn’t whether you’d be sued. It’s whether you’d survive being the headline. If you’re not sure your safeguards would hold up to that scrutiny, that’s the gap to close now, while it’s still hypothetical.