Thompson Coburn LLP Data Breach
Thompson Coburn LLP Network Server Breach Affects 305K
What happened in the Thompson Coburn LLP data breach?
The Thompson Coburn LLP data breach was reported on November 4, 2024 and affected 305,088 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Thompson Coburn LLP Breach Details
Thompson Coburn LLP Data Breach Report
Incident Overview
Thompson Coburn LLP, a major law firm based in Missouri, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was reported to the U.S. Department of Health and Human Services on November 4, 2024, affecting approximately 305,088 individuals. The unauthorized access to the firm's network server represents a serious compromise of protected health information (PHI) and other sensitive data that the organization maintained in its capacity as a business associate to covered entities in the healthcare industry.
Discovery and Response Timeline
While specific discovery dates were not detailed in the breach submission, Thompson Coburn LLP initiated an investigation upon detecting the unauthorized access to its network infrastructure. The organization's response included a comprehensive forensic investigation to determine the scope of the breach, identify affected individuals, and assess what data may have been accessed or exfiltrated. The firm notified affected parties in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. The November 4, 2024 submission date indicates the firm met its obligation to report the incident to HHS within the required timeframe.
Technical Details of the Breach
Network Server Compromise
The breach involved unauthorized access to Thompson Coburn LLP's network server infrastructure. Network server compromises typically occur through one or more of the following vectors: exploitation of unpatched software vulnerabilities, credential compromise through phishing or social engineering, weak authentication mechanisms, or lateral movement following initial system compromise. Network-based breaches are particularly concerning because they may provide threat actors with broad access to multiple systems and data repositories simultaneously. The fact that this breach affected over 300,000 individuals suggests the compromised server(s) contained centralized repositories of client and patient information, likely including healthcare-related data given the firm's business associate status.
Business Associate Context
Thompson Coburn LLP's designation as a business associate indicates the firm provides services to covered entities under HIPAA—such as healthcare providers, health plans, or healthcare clearinghouses. Law firms frequently serve as business associates when they handle PHI on behalf of healthcare clients, such as in litigation support, compliance matters, or administrative functions. As a business associate, Thompson Coburn LLP was contractually and legally obligated to implement administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule. The breach suggests that despite these obligations, the firm's network security controls were insufficient to prevent unauthorized access.
Organizational Context
Thompson Coburn LLP is a substantial law firm with offices across multiple states and a diverse client base spanning various industries, including healthcare. The firm's size and multi-state operations mean it likely maintains significant volumes of sensitive client information across distributed network infrastructure. The organization's role as a business associate places it within the regulated healthcare ecosystem, subject to HIPAA compliance requirements and breach notification obligations. The scale of this breach—affecting over 305,000 individuals—indicates the compromised systems contained aggregated data from multiple healthcare clients or covered entities.
Impact on Affected Individuals
Number of People Affected
Approximately 305,088 individuals were affected by this breach. This substantial number places the incident in the national visibility category and indicates a critical severity level. The large number of affected individuals suggests the breach involved centralized data repositories or multiple client datasets stored on the compromised network server(s).
Notification and Timeline
Affected individuals were notified of the breach in accordance with HIPAA requirements. Notifications typically include information about the nature of the breach, the types of information compromised, steps individuals should take to protect themselves, and contact information for the organization's breach response team. Given the November 4, 2024 submission date, notifications to affected individuals and to HHS were completed within the required 60-day window.
Data Exposure Assessment
Personal Information Involved
While the specific data elements exposed were not enumerated in the breach submission, the nature of Thompson Coburn LLP's business as a healthcare law firm suggests the compromised information likely included:
- Protected Health Information (PHI): Medical records, diagnoses, treatment information, and healthcare provider notes
- Personally Identifiable Information (PII): Names, addresses, dates of birth, and contact information
- Financial Information: Insurance information, billing records, and payment details
- Government Identifiers: Social Security numbers and potentially state identification numbers
- Healthcare-Specific Data: Patient account numbers, health plan member IDs, and provider identification numbers
- Legal and Administrative Records: Case files, correspondence, and litigation-related documents containing sensitive health information
The exposure of this combination of data types creates significant risk for identity theft, medical fraud, and unauthorized use of healthcare benefits.
Regulatory and Compliance Context
HIPAA Breach Notification Requirements
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities and business associates must notify affected individuals, the media, and HHS when a breach of unsecured PHI occurs. A breach is defined as unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. The notification must include: (1) a description of what happened and the date of the breach; (2) a description of the types of information involved; (3) steps individuals should take to protect themselves; (4) what the organization is doing to investigate and prevent future breaches; and (5) contact information for further inquiries.
Industry Context
Network server breaches affecting business associates have become increasingly common in the healthcare industry. These incidents often result from sophisticated threat actors targeting law firms, billing companies, and other entities that maintain access to large volumes of healthcare data. The healthcare sector remains a high-value target for cybercriminals due to the sensitivity and marketability of PHI combined with the critical nature of healthcare operations, which may incentivize payment of ransom demands.
Recommended Actions for Patients
Individuals affected by this breach should take the following protective measures:
-
Monitor Credit Reports: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at www.annualcreditreport.com and review them for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
-
Monitor Healthcare Accounts: Review explanation of benefits (EOB) statements from your health insurance plan for unauthorized claims or services. Contact your healthcare providers and insurance company if you identify suspicious activity. Monitor your healthcare accounts for unauthorized access.
-
Watch for Identity Theft: Monitor financial accounts, credit card statements, and bank accounts for unauthorized transactions. Be alert for suspicious communications claiming to be from healthcare providers or financial institutions. Consider enrolling in identity theft monitoring services if offered by Thompson Coburn LLP or your healthcare providers.
-
Place Fraud Alerts: Contact the Federal Trade Commission (FTC) at IdentityTheft.gov to report suspected identity theft and create a recovery plan. File a police report if you become a victim of identity theft or fraud related to this breach.
-
Change Passwords and Enable Multi-Factor Authentication: Update passwords for healthcare portals, insurance accounts, and financial accounts. Enable multi-factor authentication wherever available to add an additional layer of security to your accounts.
-
Review Privacy Notices: Carefully review any privacy notices or breach notification letters received from Thompson Coburn LLP or your healthcare providers for specific information about what data was exposed and what protections are being offered.
-
Consider Credit Monitoring Services: If offered by the organization, enroll in complimentary credit monitoring or identity theft protection services. These services can provide early warning of suspicious activity.
-
Report Suspicious Activity: If you notice any suspicious activity related to your healthcare or financial accounts, report it immediately to the relevant institution and consider filing a report with the FTC.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Thompson Coburn LLP Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare accounts and explanation of benefits (EOB) statements for unauthorized claims or services; contact healthcare providers and insurance companies immediately if suspicious activity is detected
Watch for identity theft by monitoring financial accounts, credit card statements, and bank accounts for unauthorized transactions; be alert for suspicious communications from healthcare providers or financial institutions
Place fraud alerts with credit bureaus and report suspected identity theft to the Federal Trade Commission at IdentityTheft.gov; file a police report if you become a victim of fraud related to this breach
Change passwords for healthcare portals, insurance accounts, and financial accounts; enable multi-factor authentication wherever available to add additional security layers
Enroll in complimentary credit monitoring or identity theft protection services if offered by Thompson Coburn LLP or your healthcare providers for early warning of suspicious activity
Review all privacy notices and breach notification letters carefully for specific information about exposed data types and available protections
Report any suspicious activity related to healthcare or financial accounts immediately to the relevant institution and file a report with the FTC if fraud occurs
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits