The lawsuits were filed Monday, July 6, 2026, in U.S. District Court for the Eastern District of Pennsylvania. Plaintiff Laura Delapaz, represented by Strauss Borrelli PLLC, brought the case titled Delapaz v. Blank Rome LLP (No. 2:26-cv-04655). The plaintiffs allege the firm violated HIPAA, the FTC Act, and California consumer protection laws by failing to implement reasonable data security measures and adequately train staff. The FBI has previously warned the legal industry about cybercriminal groups that specifically target law firms using social engineering tactics.
Attorneys should monitor this case as the latest in a rising trend of class-action litigation against law firms for inadequate data protection. The scale of the breach and the sensitivity of exposed data—particularly medical records and government identification numbers—create significant liability exposure. The one-month delay between the breach and client notification may also become a focal point in litigation over whether the firm met statutory notice requirements. Law firms should review their own social engineering protocols and staff training programs, particularly around requests to upload files to third-party services.