October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why Companies Face More Lawsuits After Data Breaches

BakerHostetler’s data shows lawsuits tied to notified incidents rose from 2018 to 2022 and continued upward in its 2023 reporting cycle—but the figures reflect one firm’s cases, not the whole U.S. market.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Companies increasingly face lawsuits after data breaches, but the trend figures behind that headline describe one law firm’s cases—not the entire U.S. market. BakerHostetler reported 42 lawsuits arising from 494 incidents in which people were notified in 2022, up from four lawsuits among 394 notified incidents in 2018. Its next report counted 58 lawsuits arising from incidents disclosed in 2023. A breach does not automatically make a company liable, yet a small incident can still prompt a claim, and notification is only one part of a company’s legal and financial response.

What the lawsuit figures show—and what they do not

The headline originated in a May 1, 2023 SecurityWeek report about BakerHostetler’s 2023 Data Security Incident Response Report, which covered incidents handled in calendar year 2022. The firm’s dataset included more than 1,100 incidents. Network intrusions were the largest category; business-email compromise and inadvertent disclosure were also common. After unauthorized access, reported activity included ransomware deployment, data theft, email access, and malware installation. These are figures from the firm’s incident portfolio, not a census of all U.S. breaches or lawsuits. SecurityWeek’s report summarizes the figures, and BakerHostetler’s report page describes the underlying publication.

Reporting period Notified incidents reported Incidents producing lawsuits Approximate rate
2018 394 4 About 1.0% (calculated from the reported figures)
2022 494 42 About 8.5% (calculated from the reported figures)
2023 report cycle 493 incidents with notice in the report’s litigation section 58 Not calculated: the report’s litigation figure and denominator are not sufficiently aligned for a comparable rate

The table compares incidents that produced at least one lawsuit with incidents for which individuals were notified; it does not count every suit separately or measure the share of all U.S. breaches that led to litigation. The 2022 cases were not limited to massive events: four involved fewer than 1,000 affected people, while 14 involved between 1,000 and 100,000. In its 2024 report, covering the 2023 cycle, BakerHostetler said the 58 lawsuits exceeded the 42 it reported for 2022. The firm also said it was defending more than 300 privacy or data-security lawsuits. Those are the firm’s reported caseload and matter data, not nationwide totals. The figures establish growth through the 2023 reporting cycle; they do not establish a verified rate through 2026. BakerHostetler’s 2024 report provides the later figures.

Why a breach can lead to a lawsuit, even when the incident is small

Plaintiffs may argue that exposed information creates a risk of identity theft or fraud, or that they incurred expenses, lost time, suffered disruption or emotional distress, or lost control over private information. A claim can seek damages, attorneys’ fees, credit monitoring, security improvements, or other injunctive relief. Class actions can aggregate claims that would be too small to pursue individually. Some state laws also authorize statutory or enhanced remedies, depending on the claim and facts.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The sensitivity and use of the information matter. Medical, financial, government, employment, authentication, or account data may raise different concerns than less sensitive information, even when relatively few people are affected. But exposure alone does not establish that every affected person has a legally sufficient claim. Courts examine concrete injury, causation, whether information was misused, the applicable law, and other case-specific requirements.

Different incidents produce different kinds of claims

Intrusions, ransomware, and stolen records

After a conventional intrusion, plaintiffs may allege negligence, breach of contract or implied contract, unjust enrichment, invasion of privacy, or violations of consumer-protection, data-security, or breach-notification laws. Some complaints argue that a company’s security practices fell short of what it promised or what the law required. The unauthorized access itself does not prove negligence: a court must assess the duty, conduct, causation, and harm under the applicable law.

Healthcare privacy and website tracking

Not every privacy case involves a hacker. BakerHostetler reported more than 50 lawsuits since August 2022 against hospital systems alleging that third-party analytics tools shared patient identities and online activity without adequate knowledge or consent. Its later report said more than 100 of the firm’s cases involved website-tracking technologies. The allegations concerned tools such as tracking pixels, session-replay, advertising, or analytics identifiers on pages where people might seek appointments or information about symptoms. These cases raise distinct privacy questions; they should not be treated as technically identical to ransomware or theft of records. The allegations are not findings that every tool or hospital violated the law. The 2024 BakerHostetler report describes the firm’s tracking-related caseload.

Vendors and supply chains

A company may depend on a cloud provider, software vendor, managed file-transfer platform, or analytics service that stores or handles its data. A vendor’s failure can still lead to direct claims against the company that collected the information. Contract terms, indemnities, insurance, data ownership, and actual control over access help determine how costs and responsibilities are allocated; outsourcing does not automatically transfer liability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The MOVEit incident illustrates how vendor-related exposure can spread. The Justice Department’s cyber-law publication described hundreds of affected organizations and more than 240 related federal cases consolidated into multidistrict litigation by December 2023. The Justice Department publication describes that litigation context.

A lawsuit is only one layer of exposure

Private claims can overlap with government investigations, state attorneys general, sector regulators, contractual disputes, insurance claims, employment issues, securities disclosures, or government-contract requirements. Which apply depends on the organization, data, promises, and incident. Uber’s 2016 breach, for example, ultimately led to a $148 million settlement with attorneys general from all 50 states and the District of Columbia, alongside other obligations; that outcome illustrates government exposure, not a typical result for every breach. The Department of Justice’s announcement describes the agreement.

Cyber insurance may include first-party response costs and third-party claims, litigation, settlements, or regulatory inquiries, but terms, exclusions, sublimits, consent requirements, and policy conditions govern. A company should review its actual policy and reporting obligations rather than assume a category of loss is covered. The FTC’s small-business cybersecurity guidance explains the general distinction between first- and third-party coverage.

Why notification is not a reason to delay

Notices can make a company, incident dates, affected data categories, and population visible to potential plaintiffs. They may also provide information used to frame a claim. But notification is required in many circumstances, and avoiding notice is not a sound way to manage litigation risk. Delaying required notice can create separate legal and regulatory problems. The practical goal is to investigate promptly, determine applicable duties, and communicate accurately as facts develop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FTC advises businesses to secure operations, mobilize a response team, consult privacy counsel, determine what information was compromised, notify appropriate parties, and avoid misleading statements. Its Data Breach Response Guide recommends involving legal, forensic, security, IT, communications, human-resources, and management functions as appropriate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What courts examine when deciding breach claims

  • Standing and injury: Has the plaintiff suffered a concrete harm, or alleged only a speculative future risk?
  • Misuse and sensitivity: Was information used fraudulently or merely exposed, and what kind of data was involved?
  • Causation: Can the claimed loss be linked to this incident rather than another breach or source?
  • Duty and security practices: What did the company promise, what controls did it maintain, and what legal standard applies?
  • Class certification: Are the proposed class members’ claims sufficiently similar to proceed together?
  • Contractual and timing defenses: Do arbitration clauses, releases, or statutes of limitation affect the case?
  • Remediation and relief: Does credit monitoring or other corrective action affect damages or a request for injunctive relief?

These questions explain why the filing of a complaint is not proof of liability. Outcomes depend on the claims, evidence, governing law, and procedural posture.

What to do when an incident is discovered

  1. Activate the incident-response plan. Bring together security, IT, legal, leadership, communications, and other functions needed for the incident.
  2. Preserve evidence and contain the threat. Preserve logs and relevant records; contain access while taking care not to destroy forensic evidence.
  3. Engage appropriate counsel and investigators. Outside breach counsel and qualified forensic investigators can help coordinate legal analysis and determine what happened. Legal involvement does not automatically make every forensic report privileged.
  4. Establish scope. Determine which systems and data were accessed, whether information was exfiltrated or misused, and when the incident began and was detected.
  5. Map duties and affected parties. Identify affected individuals, jurisdictions, contracts, regulators, law-enforcement considerations, and insurance-reporting requirements.
  6. Communicate accurately and on time. Coordinate notices and public statements with what is known, applicable deadlines, and security needs. Avoid unsupported assurances about whether data was accessed.
  7. Remediate and document. Fix the exploited weakness, record decisions and timelines, and preserve the evidence supporting those decisions.

Waiting for a perfect forensic picture can delay required notices, while premature statements that later prove inaccurate can add exposure. The response should distinguish confirmed facts from what remains under investigation.

How to reduce exposure before an incident

  • Use multifactor authentication, least-privilege access, and network segmentation, especially for privileged accounts and sensitive systems.
  • Patch known vulnerabilities promptly and maintain endpoint detection, centralized logging, and monitoring capable of identifying suspicious access.
  • Keep tested backups and rehearse recovery, not just backup creation.
  • Minimize the data collected and retained; restrict access and use encryption where appropriate.
  • Review vendors’ security controls, access, incident-notification terms, indemnities, and insurance; reassess relationships that handle sensitive information.
  • Inventory tracking pixels, analytics, and session-replay tools, particularly on healthcare or other sensitive pages, and align deployment with privacy notices and consent practices.
  • Run tabletop exercises that include counsel, security, communications, leadership, and relevant vendors.
  • Review cyber-insurance limits, exclusions, consent provisions, reporting duties, and control warranties with a qualified adviser.

These measures cannot guarantee immunity from suit. They can reduce the likelihood and impact of incidents, improve detection and containment, and help demonstrate that the organization maintained a considered security and privacy program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.