The Client File as a Target: Lawyer Data-Security Duties and Breach Obligations

Kathryn C. Nadro
Kathryn C. Nadro
Levenfeld Pearlstein, LLC

Katie Nadro is a Partner in the Corporate Group of Levenfeld Pearlstein, LLC in Chicago, where she advises clients on cybersecurity, data privacy, and artificial intelligence matters.

Tricia Y. Wagner
Tricia Y. Wagner
Lowenstein Sandler LLP

Tricia Wagner is Counsel in the Data Privacy, Security, Safety & Risk Management practice of Lowenstein Sandler LLP, based in the firm's Washington, D.C. office.

Live Video-Broadcast: November 5, 2026

2 hour CLE

Tuition: $195.00
Subscribe to Federal Bar Association CLE Pass...
Co-Sponsored by myLawCLE
Get this course, plus over 1,000+ of live webinars.
Learn More
Training 5 or more people?

Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs

Program Summary

 

Someone Else Now Defines What Reasonable Efforts Means for Your Firm

Reasonable efforts under Model Rule 1.6(c) is no longer a firm’s own judgment call. Ethics opinions, enforcement actions, state safe-harbor statutes, and class action litigation now define the controls, vendor oversight, and governance a small firm must have. After a breach, ABA Formal Opinion 483 and NYC Bar Formal Opinion 2024-3 frame what the lawyer must do next.

The exposure runs on two parallel tracks. Leave a gap in the security program and Rule 1.6(c) and Comment 18 are in play. Suffer a breach and the duties under Rules 1.1, 1.4, 5.1, and 5.3 attach. Confuse ethics-triggered notification with statute-triggered notification and disciplinary and malpractice exposure follow. Skip the documentation and regulators and plaintiffs’ attorneys will demand it after the breach. Handle the forensic investigation loosely and privilege over it can be lost.

This two-session program gives attorneys a working framework for both tracks. Attendees leave with a security assessment method anchored in the NIST Cybersecurity Framework and ABA formal guidance. They can evaluate gaps, prioritize fixes, and build the documentation record. They gain a breach response framework that satisfies bar authorities and state breach-notification laws while preserving privilege over forensic investigations.

Key topics to be discussed:

  • The Reasonable Efforts Standard
    How Rule 1.6(c), Comment 18, and the controlling ethics opinions define the security a small firm must have.
  • The Small Firm Threat Landscape
    Read breach data, enforcement actions, and class action exposure to see where the small firm is the target.
  • The Security Assessment Framework
    Evaluate technical controls, governance, vendor oversight, and documentation against the NIST Cybersecurity Framework and ABA formal guidance.
  • Safe Harbors and Multi-State Compliance
    Apply state safe-harbor statutes, emerging legislation, and multi-state compliance duties to the firm’s security program.
  • Post-Breach Ethics Duties
    Identify the Model Rules a breach triggers and how ABA Formal Opinion 483 and NYC Bar Formal Opinion 2024-3 frame post-breach duties.
  • Notification Tracks and Response Mistakes
    Distinguish ethics-triggered from statute-triggered notification and avoid the breach response mistakes that create disciplinary and malpractice liability.

This course is co-sponsored with myLawCLE.

Date / Time: November 5, 2026

  • 12:00 pm – 2:10 pm Eastern
  • 11:00 am – 1:10 pm Central
  • 10:00 am – 12:10 pm Mountain
  • 9:00 am – 11:10 am Pacific

Closed-captioning available

Speakers

Kathryn (Katie) C. Nadro, CIPP/US, AIGP, Partner, Corporate Group | Levenfeld Pearlstein, LLC

Katie Nadro is a Partner in the Corporate Group of Levenfeld Pearlstein, LLC in Chicago, where she advises clients on cybersecurity, data privacy, and artificial intelligence matters. She counsels businesses and their leadership on the full data lifecycle — from how information is collected, used, and shared to how it is secured, governed, and defended when something goes wrong. Ms. Nadro drafts and implements privacy and security policies, manages compliance programs under evolving state, federal, and international data-protection regimes, and leads clients through data breach response when an incident occurs. Uniquely, she pairs that counseling practice with a deep background as a seasoned business litigator and former in-house counsel, giving her a first-hand understanding of how a lawyer’s own data-security duties, privilege obligations, and breach-notification requirements play out in real disputes.

  • Education & Credentials

Ms. Nadro earned her J.D., with honors, from the University of Chicago Law School and her B.A., with honors, from the University of California, Berkeley. She is a Certified Information Privacy Professional (CIPP/US) and an Artificial Intelligence Governance Professional (AIGP), both credentials issued by the International Association of Privacy Professionals (IAPP). She is admitted to practice in Illinois and before the U.S. District Court for the Northern District of Illinois.

  • Recognition & Leadership

Ms. Nadro is a sought-after voice on cybersecurity, privacy, and AI liability. Her commentary on emerging technology risk has been featured in national outlets, including TechTarget, where she has analyzed liability, indemnification, and cyber-insurance exposure arising from AI-related security incidents. She is a frequent faculty member for accredited continuing legal education programs, including Strafford/BARBRI, Financial Poise, and the Illinois Institute for Continuing Legal Education, where she has taught on legal ethics and cybersecurity, U.S. privacy and data-security law, and privacy-policy fundamentals. Earlier in her career, she led the Data Security and Privacy practice at a Chicago business law firm.

  • Professional Involvement

Ms. Nadro is an active member of the International Association of Privacy Professionals (IAPP) and the American Bar Association’s Tort Trial and Insurance Practice Section Cybersecurity and Data Privacy Committee, for which she regularly writes and presents. She has served on the ABA Section of Litigation’s Ethics & Professionalism Committee, including as its Newsletter Editor, and is a member of the American Bankruptcy Institute and the Chicago Bar Association. She has also participated in the University of Chicago Law School’s Women’s Mentoring Program.

  • Experience

Ms. Nadro joined Levenfeld Pearlstein in 2024 from Raines Feldman Littrell LLP, where she was a partner, and previously was a partner at Sugar Felsenthal Grais & Helsinger LLP, where she led the firm’s Data Security and Privacy practice. Her practice spans policy drafting and program management, data-collection and use protocols, vendor and contract risk allocation, incident response and breach notification, and compliance with laws such as the GDPR, HIPAA, the CCPA, and the growing patchwork of state privacy statutes. Her earlier career as a trial lawyer handling commercial, contract, trade-secret, fiduciary-duty, and employment disputes — as both outside and in-house counsel — informs her practical, litigation-tested approach to helping law firms and other professionals protect client data, meet their ethical and statutory obligations, and respond when the client file itself becomes the target.

 

Tricia Y. Wagner, CIPP/US, CISSP, CISA, Counsel, Data Privacy, Security, Safety & Risk Management | Lowenstein Sandler LLP

Tricia Wagner is Counsel in the Data Privacy, Security, Safety & Risk Management practice of Lowenstein Sandler LLP, based in the firm’s Washington, D.C. office. A rare lawyer-technologist, she brings more than 20 years of hands-on experience in cybersecurity, information governance, and compliance to her practice, having spent most of her career on the operational side of security before advising clients from the law-firm side. Ms. Wagner develops strategies that address data across its entire lifecycle, translating complex regulatory requirements under frameworks such as the CCPA, HIPAA, and the GDPR into concrete operational practices. She leads multidisciplinary teams, designs incident response protocols, and helps organizations build the security programs and governance evidence they need to withstand regulatory, client, and litigation scrutiny after a breach.

  • Education & Credentials

Ms. Wagner earned both her J.D. and her M.B.A. from the University of San Francisco, and her B.A. from the University of California, Davis. In addition to being a Certified Information Privacy Professional (CIPP/US), she holds two of the most rigorous technical security credentials in the industry: Certified Information Systems Security Professional (CISSP) and Certified Information Systems Auditor (CISA). She is also a former PCI Qualified Security Assessor (QSA), the credential required to formally audit organizations against the Payment Card Industry Data Security Standard. She is admitted to practice in the District of Columbia and Pennsylvania.

  • Recognition & Leadership

Ms. Wagner is a core member of Lowenstein Sandler’s Data360 team, the firm’s technology-forward, multidisciplinary approach to data risk that is built around lawyers who have served as CISOs, CISSPs, PCI-QSAs, and ethical hackers. Her published work with the practice’s chair includes client alerts on AI platform risk assessments and the NIST AI Risk Management Framework, California’s mandatory risk-assessment
regulations, new state comprehensive privacy laws, and universal opt-out signal requirements, and her analysis appears regularly on JD Supra. Her hallmark approach to incident response emphasizes candor with regulators and stakeholders and rapid, durable remediation.

  • Professional Involvement

Ms. Wagner’s practice sits at the intersection of law and security operations. She regularly works alongside chief information security officers, internal auditors, and compliance officers, and she maintains active certifications through the International Association of Privacy Professionals (CIPP/US), ISC2 (CISSP), and ISACA (CISA) — a combination that allows her to speak the language of the boardroom, the security operations center, and the regulator alike. She counsels organizations that hold highly sensitive personal, financial, and confidential client data on privacy program design, security-control implementation, vendor and third-party risk management, incident response planning, and regulatory compliance.

  • Experience

Before joining Lowenstein Sandler, Ms. Wagner served as Associate Director of Privacy and Security at a global consulting firm, and for more than a decade she led Governance, Risk, and Compliance at H5, a Silicon Valley AI/machine-learning eDiscovery technology company (acquired by Lighthouse in 2021), where she oversaw security, risk, and compliance for a platform entrusted with large volumes of sensitive and privileged legal data. That background — building and auditing security programs, managing incidents, and protecting legal data at scale — gives her an unusually practical perspective on what “reasonable” security actually looks like inside a law practice, how breaches unfold, and what regulators, clients, and courts expect afterward. She is uniquely positioned to translate lawyers’ ethical and statutory data-security duties into the concrete technical and operational steps a firm must take before, during, and after a breach.

Agenda

SESSION 1 – Anatomy of a Small Firm Security Assessment Under the Reasonable Efforts Standard | 12:00pm – 1:00pm

This session teaches small firm attorneys how to conduct and document a security assessment that satisfies the ‘reasonable efforts’ standard under Model Rule 1.6(c) and its state equivalents. Attendees learn how ethics opinions, enforcement actions, state safe-harbor statutes, and class action litigation define what security controls, vendor oversight, and governance policies a small firm must have in place. Attorneys leave with a practical framework — anchored in the NIST Cybersecurity Framework and ABA formal guidance — for evaluating gaps, prioritizing fixes, and creating the documentation that regulators and plaintiffs’ attorneys will demand after a breach.

BREAK | 1:00pm – 1:10pm

SESSION 2 – After the Breach: Ethics Obligations, Client Notice, and Disciplinary Exposure | 1:10pm – 2:10pm

This session examines what attorneys must do after a data breach has occurred, covering the parallel tracks of ethics obligations and statutory breach-notification duties, client communication requirements under Model Rules 1.1, 1.4, 1.6(c), 5.1, and 5.3, and the disciplinary and malpractice exposure that follows inadequate response. Attorneys will learn how to distinguish ethics-triggered notification from statute-triggered notification, how ABA Formal Opinion 483 and NYC Bar Formal Opinion 2024-3 frame post-breach duties, and what common mistakes create disciplinary and civil liability. Attendees leave with a framework for managing breach response in a way that satisfies both bar authorities and state breach-notification laws while preserving privilege over forensic investigations.

Credits

Alaska

Approved for CLE Credits
2 Ethics

Our programs are CLE-eligible through Alaska’s recognition of multi-jurisdictional reciprocity.
Alabama

Pending CLE Approval
2 Ethics

Arkansas

Approved for CLE Credits
2 Ethics

Arizona

Approved for CLE Credits
2 Professional Responsibility/Ethics

California

Approved for CLE Credits
2 Ethics

Colorado

Pending CLE Approval
2 Ethics / Professionalism

Connecticut

Approved for CLE Credits
2 Ethics / Professionalism

District of Columbia

No MCLE Required
2 CLE Hour(s)

Delaware

Pending CLE Approval
2 Enhanced Ethics

Florida

Pending CLE Approval
2 Ethics

Georgia

Pending CLE Approval
2 Ethics

Hawaii

Approved for CLE Credits
2 Ethics or Professional Responsibility Education

Iowa

Pending CLE Approval
2 Ethics

Idaho

Pending CLE Approval
2 Ethics / Professionalism

Illinois

Pending CLE Approval
2 Ethics, Civility, Professionalism

Indiana

Pending CLE Approval
2 Ethics

Kansas

Pending CLE Approval
2 Ethics / Professionalism

Kentucky

Pending CLE Approval
2 Ethics

Louisiana

Pending CLE Approval
2 Ethics

Massachusetts

No MCLE Required
2 CLE Hour(s)

Maryland

No MCLE Required
2 CLE Hour(s)

Maine

Pending CLE Approval
2 Ethics / Professionalism

Michigan

No MCLE Required
2 CLE Hour(s)

Minnesota

Pending CLE Approval
2 Ethics

Missouri

Approved for CLE Credits
2.4 Ethics

Mississippi

Pending CLE Approval
2 Ethics

Montana

Pending CLE Approval
2 Professional Fitness and Integrity

North Carolina

Pending CLE Approval
2 Ethics

North Dakota

Approved for CLE Credits
2 Ethics

Our programs are CLE-eligible through North Dakota’s recognition of multi-jurisdictional reciprocity. Section 1, Policy 1.14
Nebraska

Pending CLE Approval
2 Professional Responsibility

myLawCLE reports attendance to Nebraska on each attorney’s behalf for all programs. Please do not self-report.
New Hampshire

Approved for CLE Credits
120 Ethics / Professionalism minutes

As of July 1, 2014, the NHMCLE Board no longer provides pre- or post-approval of courses. Attendees must self-determine whether a program is eligible for credit, and self-report their attendance online at www.nhbar.org, based on qualification provisions of Rule 53.
New Jersey

Approved for CLE Credits
2 Ethics / Professionalism

Our programs are CLE-eligible through New Jersey’s recognition of multi-jurisdictional reciprocity, except for the courses required under BCLE Reg. 201:2
New Mexico

Approved for CLE Credits
2 Ethics / Professionalism

Nevada

Pending CLE Approval
2 Ethics / Professionalism

New York

Approved for CLE Credits
2 Ethics / Professionalism

Our programs are CLE-eligible through New York’s Approved Jurisdiction Group “B”.
Ohio

Pending CLE Approval
2 Professional Conduct

Oklahoma

Pending CLE Approval
2.5 Ethics / Professionalism

Oregon

Pending CLE Approval
2 Ethics

Pennsylvania

Approved for CLE Credits
2 Ethics / Professionalism

Rhode Island

Pending CLE Approval
2.5 Ethics / Professionalism

South Carolina

Pending CLE Approval
2 Ethics / Professionalism

South Dakota

No MCLE Required
2 CLE Hour(s)

Tennessee

Pending CLE Approval
2 Dual

Texas

Approved for CLE Credits
2 Ethics / Professionalism

Utah

Pending CLE Approval
2 Ethics / Professionalism

Virginia

Not Eligible
2 Ethics / Professionalism Hours

Vermont

Approved for CLE Credits
2 Ethics

Washington

Approved via Attorney Submission
2 Ethics Hours

Receive CLE credit in Washington via attorney submission.
Wisconsin

Pending CLE Approval
2 Ethics

West Virginia

Pending CLE Approval
2.4 Ethics / Professionalism

Wyoming

Pending CLE Approval
2 Ethics / Professionalism

More CLE Webinars
Upcoming CLE Webinars
Getting Rid of Tax Penalties (Presented by Tax Rep)
Getting Rid of Tax Penalties (Presented by Tax Rep) Mon, October 12, 2026
Live Webcast