OVERVIEW

The Cybersecurity and Data Privacy group is comprised of a multidisciplinary team of highly qualified lawyers with intimate knowledge of the insurance industry and experienced in compliance, corporate governance, first and third-party coverage, and litigation. 

Insurance carriers long have turned to White and Williams for advice. For cybersecurity and data privacy, it is no different. Our attorneys bring a deep breadth of experience in the insurance industry, and advise insurance carriers in a wide array of matters from compliance and corporate governance to first-party and third-party coverage matters, and litigation.

Compliance with Data Security and Privacy Laws and Regulations (Pre-Breach Services)

If your company has data, it's a target. Depending upon the industry, your company likely has legal requirements to develop and implement an adequate data security program to safeguard the confidentiality, integrity and availability of information and your company’s information systems. Data security programs include written policies and procedures, documented employee training, vendor oversight, and sometimes personal certification of compliance with a cybersecurity law or regulation by a C-Suite officer. 

White and Williams assists clients with developing and implementing comprehensive data security and privacy programs to meet their legal needs under growing state and federal data protection laws and regulations, including the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HI-TECH Act), the Gramm-Leach-Bliley Act (GLBA), and the New York Department of Financial Services cyber regulations. We also help clients comply with the EU’s General Data Protection Regulation (GDPR) as well as the California Consumer Privacy Act (CCPA). Our lawyers help clients draft policies and procedures, including incident response plans, respond to requests for certification of compliance from regulators and business partners, conduct training and tabletop exercises, and establish third-party vendor management programs.

Mergers, Acquisitions, and Corporation Disclosures

An entity’s cybersecurity health is critical to its value in the context of a merger or sale. A prior cybersecurity incident or lax safeguards that fail to mitigate risk represent significant potential liability (and decreased value). White and Williams helps clients conduct the required and critical due diligence to assess and evaluate cybersecurity policies, programs, and incidents, whether they are the subject of a potential sale and looking for fair value, or to provide an evaluation of risks a client may inherit through a transaction. Our lawyers also review technology contracts and transactions to strengthen our client's interests and protection.

Cybersecurity Incident Response and Notification

When an organization sustains a suspected cybersecurity incident they are required by law (or sometimes by contract, or both) to undertake a prompt investigation and provide notification of the incident in a short period of time. Sometimes, a company's notification window is a mere 72 hours after knowledge of the event. White and Williams provides clients with critical crisis management to investigate and respond to cybersecurity incidents. From ransomware to data breaches, our lawyers work with forensic investigators to determine the “who, what, why and how” of an incident. We help companies with coordinated public relations efforts, potential interactions with law enforcement, and determination of required third-party notifications to consumers, business partners, regulators, State Attorneys General, and others.

Litigation

A dispute involving a cybersecurity incident can devolve into litigation, whether a business-to-business lawsuit or a data breach class action. White and Williams represents corporations in a wide variety of business sectors in litigation in state and federal courts across the country. The firm’s approach to complex litigation matters is to staff them with senior litigators who assemble efficient teams of attorneys.

Insurance

Insurance carriers long have turned to White and Williams for first-party and third-party coverage matters. For cyber liability, it is no different. Our lawyers provide exposure analysis and litigate complex coverage matters for cybersecurity incidents, from data breaches and business email compromises (BECs) to wrongful collection and use of personal identifiable information (PII), media liability, and e-surveillance. Our lawyers regularly write and lecture on insurance law, including on cyber and privacy insurance, and assist with policy drafting. White and Williams also offers in-house instruction and continuing education courses to insurance claims professionals on cyber liability and coverage issues.


Explore

Representative Matters

  • Assisted with drafting and implementing information security programs under GDPR
  • Advised with compliance under New York DFS cyber regulations 23 NYCRR 500, including certification and implementation of cybersecurity programs
  • Led multiple investigations of cybersecurity incidents
  • Led and coordinated response effort to data breach suffered by corporate client, including coordination with law enforcement
  • Coordinated the investigation for an international corporation concerning internal and external fraud committed through its computer systems
  • Represented insurer in coverage matter involving high-profile security data breach
  • Coordinated and negotiated with law enforcement following contact with corporate client regarding potential data breach and identified theft ring involving former employee
  • Represented insurers in coverage litigation and related matters involving unlawful acquisition and use of PII
  • Helped client evaluate cybersecurity protocols, revise employee handbook for cybersecurity and privacy matters, and created in-house cyber response teams with corporate cybersecurity response plan
  • Advised client on compliance under NIST SP 800-171 Standard for DOD Contracting, including development and implementation of a cybersecurity program 
  • Represented clients in response to government subpoenas for their electronic data
  • Counseled clients in addressing cyber-harassment issues
  • Drafted and updated online service agreements, privacy policies and terms of use for client’s websites and intranet sites

NEWS & RESOURCES

  • Event

    Coverage College 2024
  • Event

    Coverage College 2023
  • Publication

    It’s “Personal”– An Expansion of What Qualifies As “Personal Information” Under Pennsylvania’s Data Breach Notification Law
  • In The News

    Christopher Erb Joins White and Williams as Counsel in Philadelphia
  • Publication

    Are Insurance Brokers the Next Target for Claims Arising From the Pandemic?
  • Publication

    SCOTUS Decision on Autodialers Under TCPA Provides Handy Primer on Statutory Construction and Interpretation
  • Publication

    NYDFS Announces Cyber Insurance Risk Framework to Address Increasing Cyber Risk
  • Publication

    Recent Case Impacts HIPAA and HITECH Act Penalties
  • Publication

    HITECH Act Amendment Offers New Incentive to Reduce Fines and Other Remedies
  • Publication

    HHS Proposes Significant HIPAA Privacy Rule Changes: Amendments Would Increase Individual and Institutional Access and Coordination of Care
  • In The News

    Congratulations 2020 DE, MA, NY and PA Super Lawyers and Rising Stars
  • Publication

    Between a Rock and a Hard Place: Advisories Target Ransomware Victims, Insurers
  • Publication

    Federal Advisory Warns Hospitals Facing “Increased and Imminent” Cyber Threat; 400 Hospitals Already Targeted
  • Event

    COVID-19 Insurance Program
  • Event

    Creating a Data Privacy Compliance Program on a Limited Budget
  • Publication

    Return to Work: Guidance for Workplace Reopening
  • In The News

    Chambers USA 2020 Ranks White and Williams as a Leading Law Firm
  • Event

    Electronic Information in Criminal Investigations and Proceedings
  • In The News

    13th Annual Coverage College Hosts Over 400 Insurance Professionals
  • Event

    ACC: Annual Ethics & Diversity CLE
  • In The News

    Mike Kassak and Josh Mooney Reappointed as Vice-Chairs of American Bar Association's Cybersecurity and Data Privacy Committee
  • Publication

    Threats, Opportunities Presented by New Technology in the Insurance Industry
  • Event

    Electronic Information in Criminal Investigations & Proceedings
  • Event

    2019 Lehigh Valley Employment Law Seminar
  • In The News

    Chambers USA 2019 Ranks White and Williams as a Leading Law Firm
  • Publication

    Higher Ed Falls Victim to New Data Breach
  • Event

    Electronic Information in Criminal Investigations & Proceedings
  • Publication

    Best Practices For Personal Data Security #DataPrivacyDay
  • Publication

    Security of Critical Infrastructure Relies on Businesses to Build Resilience
  • In The News

    12th Annual Coverage College Features Current Trends and State of the Insurance Claims Industry
  • In The News

    Mike Kassak and Josh Mooney Appointed Vice-Chairs of American Bar Association's Cybersecurity and Data Privacy Committee
  • Publication

    Supreme Court Alert: The Government Must Obtain a Warrant for Cell-Site Records
  • Event

    Policy, Deals and Disclosure: A Lawyer's Role in Managing Security and Data
  • Publication

    CEO Zuckerberg: Facebook User Settings Protect Individual Data – Congress Is Not So Sure
  • Event

    2017 NAIC Insurance Data Security Model Law
  • Publication

    Coalition of State Attorneys General Send Letter Demanding Answers from Facebook
  • Publication

    United States v. Microsoft Raises Significant Questions Regarding Application of the Stored Communications Act
  • Publication

    Washington Suburb Targeted by Cybercrime and Ransomware Attacks
  • Event

    The Implications of Cross-Border Discovery on Cybersecurity and Privacy Compliance
  • Event

    Beat the Breach: Cyber and Data Protection and Regulatory Compliance
  • Publication

    How Employers Can Respond to the Equifax Breach
  • Publication

    UPDATE: U.S. DHS Issues Revised Alert on WannaCry Ransomware
  • Publication

    Critical Security Updates Released by Leading Software and Technology Companies
  • Publication

    Department of Homeland Security Issues Internet Security Alert Ahead of Easter Holiday
  • Event

    Employment Law Seminar - Philadelphia
  • In The News

    Linda Perkins Joins White and Williams Philadelphia Office
  • Event

    Employment Law Seminar - Lehigh Valley
  • Event

    Managing Cybersecurity in the Healthcare Industry: Best Practices Every Healthcare Organization Needs to Know
  • Publication

    Reasonable Expectations of Privacy in a Not-So-Private Electronic World
  • Publication

    U.S. Department of Health and Human Services Issues New “Guidance” on Mobile Health Applications
  • In The News

    Jay Shapiro Comments on Proposed Broadband Privacy Rules and Verizon Settlement
  • Publication

    FCC Issues Proposed Privacy Rules Applicable to Broadband Internet Service Providers
  • Publication

    Hospital Pays Ransom to Hacker in Response to Malware Attack: An Eye-Opening Reality
  • Publication

    The Supreme Court Upholds a Cyber Trespass Conviction
  • Event

    Cyber Risk and Cyber Insurance - What You May Know and May Not Know
  • Event

    Cybersecurity Panel Discussion
  • Publication

    Administrative Law Judge Rules Against FTC in Data Security Enforcement Action
  • Event

    Finance Forum: Cybersecurity in Financial Transactions
  • Event

    Ethical Issues Facing In-House Counsel Today: Data Breaches, Confidentiality and Compliance
  • Publication

    Creating a Culture of Cybersecurity in the Workplace
  • Publication

    Securing Electronic Medical Records on Mobile Devices
  • Event

    Employment Law Seminar
  • Event

    Healthcare and Data Breaches - Vulnerability and Consequences
  • Publication

    Full House To Begin Debate On Data Security and Breach Notification Act After Approval Of Energy and Commerce Committee
Arrow Back To Top
Jump to Page

By using this site, you agree to our updated Privacy Policy and our Terms of Use.