Does Malpractice Insurance Cover a Data Breach?
Does malpractice cover a data breach? The honest answer, before you need it.
- By Dallas Downey, CLCS
Published 2026-09-11 - Commercial Insurance
A wire moves. A server locks. A client file walks out the door. Your malpractice policy was built for a different kind of bad day, and every Houston litigator should know exactly where it stops before the phone rings.

The answer
Generally, no. Legal professional liability responds when your legal work is alleged to have harmed a client. A data breach or a stolen settlement wire is a crime committed against your firm, and the policy built to answer for it is standalone cyber coverage. The two contracts solve different problems, and the space between them is where Houston litigators get hurt.
How the scheme actually runs
Start with what makes litigation different. Your dockets are public. Anyone with a PACER login or an afternoon at the Harris County District Clerk can read the case number, the parties, the lawyers on each side, and the settlement timeline.
Criminals read them too. The playbook the FBI keeps documenting is patient. Someone studies a case for weeks, learns the names and the rhythm, then reaches out the week a settlement check is supposed to move. They sound like opposing counsel because they have read everything opposing counsel filed. When they ask a paralegal to confirm updated wiring instructions, the request lands as routine.
The money leaves. The malpractice carrier gets the call. The answer that comes back is the one nobody wants to hear on that day. This loss sits outside the contract.
I read these two contracts side by side for Houston firms, and the pattern repeats. The malpractice policy is strong at the job it was hired for. Everyone just assumed it was hired for two jobs. Nobody finds that out at a good time.
Dallas Downey, CLCS
Two contracts, two different jobs
Legal professional liability exists for one reason. When your legal work is alleged to have hurt a client, a missed deadline, bad advice, a mishandled matter, the policy defends you and pays what you owe. That is the box it was designed for, and it does that job well.
A standalone cyber policy was designed for the event itself. It funds the forensics team that figures out what was taken. It puts breach counsel on the phone to map your duties. It pays the cost of notifying every client whose file was exposed. And through a social engineering fraud endorsement, it can respond when someone tricks your staff into sending money to the wrong account, with a sublimit sized to the largest wire your firm actually sends.
None of that lives inside a malpractice contract. If nobody at your firm has read the two policies side by side, the boundary between them is an assumption. We translate the insurance contract before claim time. For a litigation practice, this is the translation that matters most.
The scale of the problem
Neither figure is a law firm number, and that is the point. The people behind those losses do not need a law firm number. They need a public docket and one busy afternoon.
Your duty of confidentiality survives the breach
Rule 1.05 of the Texas Disciplinary Rules of Professional Conduct makes client confidentiality your obligation, and a hacker does not release you from it. After a breach, the questions come fast. Which files were touched. Who has to be told, and how, and on what clock. Chapter 521 of the Texas Business and Commerce Code runs a 60 day notification deadline for affected individuals and carries its own trigger for reporting to the Texas Attorney General.
Breach counsel exists to walk you through those duties while you keep practicing law. A standalone cyber policy is how that counsel, and the forensics team behind them, get paid from day one. Your clients trusted you with the file. The coverage question is whether you have funded the response that trust deserves.
The side by side read I walk firms through
When a firm sends me their policies, here is the order I read them in. You can run the first pass yourself tonight.
- Pull both declarations pages. Your LPL dec page and whatever cyber coverage you hold, standalone or endorsement. Current term, actual pages.
- Find the insuring agreements. Read what each policy says it responds to. The LPL language will center on your professional services. Anything about wrongful acts in your legal work belongs to that box.
- Hunt the words social engineering. If they appear nowhere, you have found your gap. If they appear, find the sublimit printed beside them.
- Match that sublimit to your largest wire. Open a year of trust account activity and find the biggest disbursement. If the sublimit is smaller than that wire, the coverage was sized for a different firm.
- Write down who you would call first. The breach hotline on a cyber policy is worth more at 2 a.m. than any coverage summary. If you cannot find one, that tells you something too.
That is thirty minutes of reading. It is also the difference between knowing your boundary and assuming it.
Keep the boundary sharp
Sources worth opening before you decide.
This article uses public source material from the FBI Internet Crime Complaint Center 2025 Internet Crime Report, the IBM Cost of a Data Breach Report, Rule 1.05 of the Texas Disciplinary Rules of Professional Conduct, and Chapter 521 of the Texas Business and Commerce Code.
The purpose is to help you ask better questions before claim time.
Frequently asked questions
Does my malpractice insurance cover a data breach?
Generally no. Legal professional liability responds to claims that your legal work harmed a client. A breach or a stolen wire is a crime against the firm itself, so the response costs, forensics, breach counsel, and client notification belong to a standalone cyber policy.
What does a cyber policy actually pay for after a hack?
Most standalone policies fund the forensic investigation, put breach counsel on the phone to map your legal duties, cover client notification, and respond to cyber extortion when ransomware is involved. Social engineering fraud, where an employee is tricked into wiring money, is usually a separate endorsement with its own sublimit.
How much cyber coverage does a litigation firm need?
Size it to your practice instead of a rate sheet. The social engineering sublimit should match the largest wire your firm actually sends, and the overall limit should reflect your settlement sizes, your trust account activity, and how much client data you hold. A broker who reads your real numbers can put a figure to that in one meeting.
Is my firm too small to be a target?
No. Smaller firms often carry lighter security controls than large firms while holding the same kind of sensitive client information, and public dockets make every litigation practice easy to research. Attackers follow the paper trail, and the paper trail does not care about headcount.
One more thing, from the person who wrote this. The button below books a commercial review, and the calendar behind it is mine. You bring the policies. I bring the highlighter. You leave with your boundary marked on paper.
Our commercial desk places standalone cyber coverage for Texas law firms from 50+ top Texas carriers we know well.
You should not meet the edge of your malpractice policy for the first time during a breach.
See Where My Coverage StopsThe review is free. The decision is yours.
By