
In November 2025, a law firm data breach at Greenbaum Rowe Smith & Davis began with a compromised user account. The firm held protected health information while providing legal services to healthcare organizations. Potentially affected information included diagnoses, treatment history, provider information, medical costs, and health insurance information.
The medical information had already moved downstream from healthcare organizations into a law firm’s systems. That is the part legal teams should notice.
For purposes of ABA Formal Opinion 483, a law firm data breach can include a cyber event that compromises material client confidential information or significantly impairs the lawyer’s ability to perform legal services. Other privacy, breach notification, and regulatory frameworks can define a reportable breach differently.
Workflow discipline does not replace authentication, access controls, monitoring, training, or incident response.

Recent incidents show different ways sensitive information can become exposed after it enters a law firm’s environment.
Greenbaum personnel discovered unauthorized access on November 27, 2025. According to the firm’s official notice, access occurred through a compromised user account between November 25 and November 27. An unauthorized third party acquired information from its systems.
Affected health information could include medical record numbers, diagnoses, clinical information, treatment history, provider information, dates of service, medical costs, and health insurance information. Social Security numbers or dates of birth were included for some individuals.
The HHS Office for Civil Rights HIPAA Breach Reports page identifies Greenbaum as a business associate and lists the incident as affecting 12,801 individuals. Atlantic Health separately confirmed that Greenbaum provided legal services to healthcare providers and that the incident affected protected health information belonging to those providers’ patients.
Greenbaum’s business associate role matters. This incident does not mean every law firm holding medical records has the same HIPAA status. It does show how health information can enter a law firm’s systems through ordinary client work and become part of the environment an incident response must evaluate.
A May 2024 targeted cyberattack on Thompson Coburn later led to class action litigation.
According to official settlement materials related to that litigation, files accessed during the incident may have contained protected health information, health insurance information, treatment information, clinical information, and medical provider information. Other potentially affected data included names, dates of birth, government identification information, and Social Security numbers.
The incident shows how broadly sensitive information can accumulate inside systems supporting legal work. A firm may hold data connected to clients, patients, insured individuals, employees, or others whose information entered through the matters it handles.
Adamson Ahdoot reported another incident in December 2025 involving a third-party vendor with authorized access to certain cloud-hosted firm resources.
According to the firm’s data breach notice, the vendor may have unintentionally permitted unauthorized access to cloud-hosted documents. Potentially affected documents could have contained medical information and government-issued identification information.
Adamson Ahdoot said it was evaluating additional technical measures and reviewing its vendor vetting and supervision practices afterward.
When a vendor has authorized access, it becomes part of the firm’s information chain. The firm should be able to identify which matters, files, and users were within that vendor’s access.
These incidents reached sensitive information through different paths, including a compromised account, an attack on firm systems, and access involving an outside vendor.
They do not show that fragmented retrieval workflows caused the breaches. They show what firms have to account for once sensitive health information exists across more systems, accounts, and service relationships.
The attack vector explains how access occurred. The firm’s information workflow helps determine what that access could reach and how difficult the resulting incident may be to scope.
A breach can expose more than a technical weakness. It can expose whether the firm actually understands how sensitive information moves through its work.
Not every cybersecurity event meets the same definition of a data breach.
ABA Formal Opinion 483 uses an ethics-focused definition under the Model Rules. It covers events in which material client confidential information is misappropriated, destroyed, or otherwise compromised. It also covers events that significantly impair a lawyer’s ability to perform the legal services for which the lawyer was hired.
Other privacy laws can use different triggers and impose separate response or notification duties.
A failed login attempt, misdirected email, ransomware event, and confirmed acquisition of confidential files may therefore create different obligations.
The firm first needs enough information to understand what occurred. It can then identify the clients, individuals, systems, or information that may be affected and evaluate the professional, legal, contractual, insurance, or notification requirements that apply.
A law firm data breach can begin with compromised credentials, phishing, ransomware, malware, software vulnerabilities, or misconfigured cloud resources. Excessive permissions, lost devices, accidental disclosure, and third-party incidents create other paths to sensitive information.
Technical controls alone may not give legal operations a complete view of where staff saved, forwarded, or shared medical records during routine case work, particularly when the workflow spans multiple systems, vendors, and manual handoffs.
For medical-record-heavy firms, the attack vector is only part of the response. Teams also need to determine which records, matters, and systems the compromised access could reach.

Consider a routine production. A staff member downloads records from a provider portal. The file lands in a local Downloads folder before moving into a shared drive or case management system. Someone sends another copy to an attorney, and an expert receives the records for review.
Every step may serve a legitimate case purpose. The control problem begins when no one can account for the copies, permissions, and handoffs without rebuilding the history manually.
Local files can remain after staff move the working record elsewhere. Email attachments persist in inboxes and sent folders. Shared drive permissions can outlast the role that originally justified access.
One extra copy is easy to dismiss. Multiply that behavior across employees, matters, providers, and experts, and the burden changes. The firm may now have to determine which version is current, which copies still exist, who retained access, and where to look when something goes wrong.
A controlled workflow should make the working location clear. Staff should also be able to identify other active copies and determine whether access still matches current case responsibilities.
Case management systems, cloud platforms, and approved AI tools can centralize parts of the work while creating additional places where matter information may be transmitted, processed, or stored.
Before staff transfer matter information, the firm should understand what data a tool receives, what controls govern its use, and who can access the resulting information.
Legal workflows are unlikely to become less distributed as firms adopt specialized platforms, AI tools, experts, and outside providers. As that technology stack grows, the operational challenge is maintaining a clear account of how sensitive information moves between those tools.
Medical records often leave the firm for legitimate case purposes. Experts, consultants, litigation support providers, retrieval vendors, and other authorized parties may all receive sensitive information.
Third-party oversight therefore belongs in the record workflow. When firms compare medical record retrieval services, they should evaluate delivery methods, access controls, security evidence, and the operational work that remains with their staff.
The retrieval model also matters. If staff still chase providers and reconcile status across inboxes and spreadsheets, outsourcing the request has not necessarily simplified the workflow.
Use a simple test. Can the team quickly answer these questions?
If those answers require several employees, multiple systems, and manual reconstruction, the workflow is not giving leadership enough visibility.
A practical workflow visibility standard for medical-record-heavy firms is simple: the team should be able to identify what entered the matter, where the working records reside, who can access them, and which outside parties received them without reconstructing the case from scratch.
ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to client representation.
The ABA Model Rules provide a national reference point. They are not the controlling professional conduct rules in every jurisdiction. Formal Opinion 483 notes that the laws, court rules, regulations, professional conduct rules, and opinions adopted in individual jurisdictions control.
Privacy laws, breach notification requirements, contracts, and other obligations may also apply based on the incident and information involved.
A law firm does not become subject to HIPAA simply because it possesses medical records.
HHS business associate guidance explains that a law firm can be a business associate when it performs qualifying services involving protected health information for a covered entity or another business associate. HHS specifically identifies an attorney whose legal services to a health plan involve access to PHI as an example.
That is different from treating every attorney who obtains a client’s medical records for litigation as a HIPAA business associate. The relationship and work being performed determine whether the business associate framework applies.
When a lawyer is acting as a business associate, downstream obligations also depend on who receives PHI and why. HHS guidance for lawyer-business associates says agents or subcontractors assisting the lawyer in providing those services must agree to applicable restrictions and conditions on the PHI they receive.
Business associate status is separate from the disclosure pathway a provider uses to release records in litigation. HIPAA subpoena requirements for medical records address that distinct question.
Workflow discipline should complement the firm’s cybersecurity program. Appropriate technical safeguards, access management, staff training, backups, monitoring, incident planning, vendor oversight, and qualified cybersecurity support remain important.
For medical records, start by making routine handling predictable. Establish where completed productions belong and how they enter the matter. Define who needs access and give staff a standard path for sharing records when the case requires it.
Clear retrieval scope also helps. When a request identifies the provider, date range, and needed record types, staff have a defined target for checking what comes back. That same request discipline makes incomplete medical records easier to identify and correct before another follow-up cycle begins.
That does not mean narrowing legitimate evidence for security reasons. The retrieval workflow should reflect the scope the legal team intended to request.
Third-party relationships need the same discipline. Firms should know which vendors receive sensitive information and evaluate the controls relevant to those handoffs. Security documentation, access controls, delivery practices, contractual terms, and independent assurance can all inform that review.
The process also has to hold up as volume grows. A few employees using different methods may feel manageable, but more cases, providers, downloads, and outside parties make inconsistencies expensive to reconstruct.
Staff end up finding files, comparing copies, confirming access, and tracing handoffs while still managing active cases, provider follow-up, client responsibilities, and deadlines.
When a law firm data breach may involve medical records, the response team also needs to trace how that information moved through the matter.
A suspected breach should trigger the firm’s established incident response process and appropriate professional support. ABA Formal Opinion 483 calls for reasonable and prompt action after a breach involving protected client information is suspected or detected. It also recognizes that lawyers may need qualified technical experts.
The response team needs enough information to answer the core questions. Which systems or accounts were involved? What is the relevant timeframe? What information may have been accessed? Which matters or individuals may be affected? Which vendors or other third parties need to participate?
Those questions become harder when routine workflows have already scattered information across disconnected locations.
Teams also need to preserve the information necessary to understand what occurred. From there, they can evaluate the legal, ethical, contractual, insurance, and notification duties that apply.
Depending on the facts, that analysis may include obligations to notify affected clients or individuals, regulators, insurers, and other parties under applicable contracts. The required recipients and timing can vary by jurisdiction, the information involved, the firm’s relationships, and the applicable policy or agreement.
After the immediate response, examine how the affected information moved through the matter. Unnecessary local copies, stale permissions, unmanaged downloads, and unclear third-party handoffs can reveal process weaknesses worth correcting.

A law firm cannot centralize every system involved in litigation. It can simplify specific parts of the workflow. Medical record retrieval is one of them.
If provider follow-up, request status, and completed records still move through separate inboxes, spreadsheets, and portals, retrieval is a practical place to reduce that fragmentation.
With CaseBinder, we centralize that retrieval workflow. Legal teams can track request progress in one dashboard, while our retrieval experts handle provider follow-up and escalation.
We also remove information outside the defined request scope from the responsive production. Retention and destruction after retrieval remain the customer’s responsibility.
CaseBinder is not a cybersecurity program and cannot eliminate the possibility of a law firm data breach. It addresses a narrower operational problem by reducing disconnected retrieval work that would otherwise fall back on the firm’s staff.
If retrieval still requires your staff to coordinate provider portals, spreadsheets, inboxes, downloads, and manual follow-up, look beyond whether the process eventually gets the records.
Ask whether your team can see what is happening without reconstructing the workflow from scratch.
Schedule a CaseBinder consultation to see how we can centralize request submission, provider follow-up, status visibility, and record delivery for your legal team.
Not automatically. A law firm may be a HIPAA business associate when it performs qualifying services involving protected health information for a covered entity or another business associate. Possessing medical records while representing a client does not, by itself, establish business associate status.
No single reporting rule applies to every incident. Notification duties can depend on the affected information, jurisdiction, professional obligations, contracts, regulatory status, and facts of the event. Separate legal frameworks may impose different notice triggers and response requirements.
The firm should activate its established incident response process and involve appropriate legal and cybersecurity professionals. The response should establish what happened, which systems and information may be affected, and which professional, legal, contractual, insurance, or notification requirements apply.
Law firms need appropriate cybersecurity safeguards and clear operational controls. Teams should know where records enter the workflow, where working copies belong, who can access them, and which outside parties receive them.
Medical record retrieval requires sensitive information to move between organizations. Repeated downloads, forwarding, duplicate copies, and disconnected handling can make that movement harder to govern. A consistent retrieval process can make it easier to see how records enter the matter and reduce unnecessary operational fragmentation.