Data Breach

data-breach

A data breach starts as a technical event and ends as a personal one. What began as a compromised server at a Frisco medical clinic or a stolen laptop at a San Antonio law office turns, within weeks, into thousands of individual letters warning that a Social Security number is now circulating outside anyone's control. Texas Business and Commerce Code Section 521.053 frames this moment as the unauthorized acquisition of computerized data that compromises confidentiality, security, or integrity, and once that threshold is crossed, the clock on legal duties starts running.

What is a Data Breach?

Data breach incidents share one trait regardless of industry: information meant to stay private ends up in front of someone who was never supposed to see it. A hospital record system, a payroll database, or a customer loyalty app can all fail the same way. Under Texas Business and Commerce Code Section 521.053, the trigger is unauthorized acquisition, not intent, meaning a careless configuration error can carry the same legal weight as a coordinated ransomware attack once sensitive personal information changes hands without permission.

How is a Data Breach Defined Under Data Protection Laws?

Ask three different states what counts as a breach and three different statutes answer. Texas Section 521.053(a) settles the question for residents here: a breach of system security means unauthorized acquisition of computerized data that compromises confidentiality, security, or integrity of sensitive personal information, including encrypted data if the intruder also holds the decryption key. A small accounting firm in Waco and a national retailer headquartered in Dallas answer to the identical statutory language the moment an outsider gains that access.

What Qualifies as a Personal Data Breach?

Not every exposed file rises to the level of a personal data breach. Section 521.002 narrows the category to specific identifiers, a first name or initial paired with a last name, combined with a Social Security number, driver's license number, or financial account information. In Hays v. Frost & Sullivan, Inc., No. SA-23-CV-01490-FB (W.D. Tex. Aug. 16, 2024), 279 individuals had exactly this combination exposed after a ransomware group calling itself Akira infiltrated the company's network, and that combination alone was enough to anchor a federal lawsuit.

What is the Difference Between a Data Breach and a Data Leak?

Picture two companies on the same afternoon. One gets hacked by an outside group that forces its way past a firewall. The other accidentally leaves a customer database open to the public internet with no password at all. Both events expose the same type of information, yet only one involves an intruder. A data leak describes that second scenario, an exposure caused by misconfiguration, human error, or careless storage rather than a break-in. Texas notification law under Section 521.053 does not care which label applies; both paths trigger the same duty once sensitive personal information reaches someone unauthorized.

When Does Unauthorized Access Become a Data Breach?

The line is not about how skilled the intruder was. It is about permission. Section 521.053(a) draws the boundary at the point where a person outside the organization, or an insider acting beyond any legitimate business purpose, obtains or views sensitive personal information. Good faith access by an employee performing an ordinary job function does not cross that line, but the moment a former employee logs into a system using old credentials to copy client files, the statute treats that access as a breach.

What are the Causes of Data Breaches?

Every breach traces back to one of a handful of recurring failure points inside an organization's systems or its people.

  • Phishing Emails: A convincing fake login page or invoice attachment tricks an employee into typing credentials that attackers immediately reuse to enter company servers undetected.
  • Recycled Passwords: One password used across a personal account and a work account gives attackers a shortcut once either system is compromised in an unrelated incident.
  • Unpatched Software: Outdated systems running known, publicly documented vulnerabilities give intruders a mapped path into a network without needing a single stolen credential.
  • Vendor and Contractor Gaps: A third party holding client data on a company's behalf, as Blackbaud did for thousands of nonprofits and hospitals, can expose records the client company never directly controlled.
  • Misplaced Physical Records: A discarded hard drive, an unshredded file box, or a lost company phone can leak years of records without any digital intrusion at all.

How Do Hackers Typically Cause Data Breaches in Companies?

Most intrusions begin quietly, days or weeks before anyone notices. A hacker identifies one weak entry point, often a single employee credential obtained through phishing, and uses it to move laterally across connected systems until reaching a database worth stealing. The complaint in Hays v. Frost & Sullivan alleged that the Akira ransomware group followed this exact pattern, gaining entry, extracting files, and later posting stolen data on a darknet site when the company did not meet its ransom demand.

What is a Ransomware-Related Data Breach?

Money, not curiosity, drives most ransomware intrusions. Attackers first copy a company's files, then encrypt the originals and demand payment for the decryption key, turning a single intrusion into a double threat of both data loss and public exposure. This qualifies as a ransomware attack combined with an unauthorized acquisition under Section 521.053, and Texas notification duties apply whether or not the company pays. Courts often treat this deliberate targeting as stronger evidence of harm than an accidental leak, since it shows the data was valuable enough for someone to plan around it.

Can Insider Threats Lead to Data Breaches?

Yes, and the exposure can be harder to detect than an outside attack because the access already looks legitimate. A departing employee who copies a client list before resigning, or a staff member who sells account records for cash, both fall under Texas Business and Commerce Code Section 521.051, which separately criminalizes obtaining or using another person's identifying information without consent. The company's firewall never triggers an alert because the person walking out the door already had the keys.

What are Accidental Data Breaches in Organizations?

No hacker, no malware, no ransom note, and the outcome can still be identical. A spreadsheet of client Social Security numbers sent to the wrong email address, a database migrated to a cloud server without access restrictions, or account statements mailed to years-old addresses all qualify. Section 521.053 does not distinguish between malicious and accidental exposure once sensitive personal information reaches an unauthorized party, and the same 60 day notification window applies regardless of how the mistake happened.

What Laws Apply to Data Breaches?

Several overlapping statutes govern how a Texas business must guard and disclose sensitive personal information.

  • Texas Identity Theft Enforcement and Protection Act, codified at Business and Commerce Code Chapter 521, requiring reasonable safeguards and resident notification.
  • Texas Data Privacy and Security Act, Business and Commerce Code Chapter 541, effective July 1, 2024, governing consumer data collection and processing statewide.
  • Health Insurance Portability and Accountability Act, a federal statute imposing separate breach reporting duties on covered health entities and their contractors.
  • Gramm-Leach-Bliley Act, a federal law requiring banks, lenders, and insurers to protect nonpublic financial information.
  • Federal Trade Commission Act Section 5, authorizing federal action against companies whose data practices amount to unfair or deceptive conduct.

What are the Legal Obligations After a Data Breach Occurs?

The obligations start immediately, not once the investigation wraps up. A company must contain the intrusion, determine its scope, and then disclose the breach to affected residents, with Section 521.053(b) setting a deadline of no later than 60 days after the determination date, subject to a limited delay if law enforcement requests it under Subsection (d). Once notice reaches more than 10,000 people at one time, Subsection (h) adds a separate duty to alert nationwide consumer reporting agencies.

When Must a Company Report a Data Breach to Authorities?

Thirty days, not sixty, is the number that matters once the breach crosses a size threshold. Section 521.053(i) requires notice to the Texas Attorney General no later than the 30th day after a company determines that a breach affecting 250 or more state residents occurred, filed through the Attorney General's online portal. The Frost & Sullivan breach, involving 279 people, sat squarely within this reporting requirement.

What Penalties Apply for Failing to Report a Data Breach?

The price of silence is steep and grows daily. Section 521.151 sets a civil penalty between $2,000 and $50,000 per violation, recoverable directly by the Texas Attorney General, and a violation of the identity theft provisions in Section 521.051 doubles as a deceptive trade practice under Section 521.152, opening additional consumer protection remedies. Attorney General Ken Paxton's office collected more than $2.7 million from Blackbaud alone after the company's breach disclosures fell short of what state law required.

How Do Courts Determine Damages in Data Breach Lawsuits?

Judges are not persuaded by fear alone. Courts weigh documented financial losses, fraudulent charges, credit monitoring expenses, and time spent repairing damaged credit, alongside any statutory damages a specific statute provides. In Hays v. Frost & Sullivan, negligence and negligence per se claims survived dismissal because the plaintiff pointed to concrete mitigation costs and evidence that stolen data had actually surfaced on a hacker forum, not merely a theoretical risk that it might someday be misused.

Which Authorities Must Be Informed After a Data Breach?

The size and type of a breach determines which recipients Texas law requires a company to notify.

  • Texas Attorney General: Notice required within 30 days once a breach affects 250 or more Texas residents.
  • Affected Individuals: Notice required within 60 days for anyone whose sensitive personal information was exposed.
  • Consumer Reporting Agencies: Notice required without delay when a single incident affects more than 10,000 people.
  • Federal Regulators: Notice required separately under HIPAA or Gramm-Leach-Bliley for health or financial records.

Can a Personal Injury Attorney Handle Data Breach Cases?

A personal injury attorney handling identity theft or exposure claims typically reviews the breach notification letter, the company's privacy policy, and any bank or credit records showing fraud tied to the exposed data before filing suit. Texas courts, as shown in the Frost & Sullivan litigation, have allowed negligence claims tied to poor data security to move forward once the plaintiff connects specific losses to the breach itself.

Who is Legally Responsible for a Data Breach in a Company?

Responsibility rarely rests in one place alone. The company that owns or licenses the compromised data carries the primary duty under Section 521.052, which requires reasonable procedures to protect sensitive personal information and corrective action once a gap is found. But a vendor handling that data under contract, such as a cloud host or payment processor, can share or shift that liability depending on the indemnity terms both parties signed before the breach ever happened.

How is Negligence Proven in a Data Breach Case?

Four pieces have to fit together. A plaintiff must show the company owed a duty to protect the data, that reasonable security measures were not in place, that this gap allowed the breach to happen, and that real damages followed. This mirrors ordinary negligence in law applied to a digital record instead of a physical hazard. In Hays v. Frost & Sullivan, the court let negligence and negligence per se claims proceed because the complaint tied specific security shortcomings to a documented ransomware intrusion and quantifiable financial harm.

Can Companies be Sued for Failing to Prevent Data Breaches?

Yes, though a lawsuit alone does not guarantee the courthouse door stays open. Federal standing still requires a concrete injury under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), so a bare claim of increased future risk rarely survives a motion to dismiss on its own. The magistrate judge in Hays found standing anyway, pointing to the deliberate, targeted nature of the Akira ransomware intrusion and the plaintiff's actual mitigation expenses as the difference between speculation and a real injury.

What is the Difference Between Negligence and Cyber Liability in Breaches?

One is a lawsuit theory. The other is a business exposure. Negligence asks a narrow question: did this company fail to exercise reasonable care in protecting a specific person's data? Cyber liability covers far more ground, including regulatory fines under Section 521.151, contractual indemnity disputes with vendors, and notification costs that arrive whether or not a single plaintiff ever files suit. A Texas court evaluating a negligence claim applies ordinary tort elements, while an insurer assessing cyber liability exposure is reading policy language and vendor contracts long before any courtroom gets involved.

Is Strict Liability Applicable in Data Breach Cases?

Texas requires proof of fault, not automatic liability, before a company answers for a data breach. Unlike strict liability claims involving defective products under Civil Practice and Remedies Code Chapter 82, a data breach plaintiff must still show the company fell short of the reasonable care standard set by Section 521.052 or broke a specific promise made in a privacy policy or contract. The court in Hays v. Frost & Sullivan analyzed the claims through negligence and contract principles, not a strict liability framework, consistent with how Texas courts have approached this area of law.