.

Chair, Privacy and Data Security

Chair, Intellectual Property, Technology and Media Litigation

Portrait of David J. Shannon

Defense Digest

On the Pulse…Data Breaches and Ransomware Attacks: Getting to Know Marshall Dennehey’s Privacy and Data Security Practice Group

Defense Digest, Vol. 27, No. 4, September 2021

September 1, 2021

by David J. Shannon

Solar Winds, JBS, Kaseya…the list goes on and on each week, as more and more ransomware cyberattacks occur. The public is inundated with announcements of businesses being crippled by data breaches and ransomware attacks by foreign hackers and state-sponsored cyberterrorists. Here at Marshall Dennehey, our Privacy and Data Security Practice Group is focused on helping clients, large and small, in reducing their cyber risk exposures and guiding them through the inevitable incident response, containment and compliance measures that are needed after a data breach or ransomware attack occurs. Our firm is staffed to respond to time critical situations 24-7, and we work with clients to reduce their exposure to the risk and liability that happens when a cyberattack occurs.

Marshall Dennehey has been focused on data breach litigation since 2010, handling hundreds of data breaches and helping clients respond and recover. As we have seen, the rise of criminal ransomware and other data breach attacks can lead to crippling business interruption for businesses throughout the United States. Our ability to provide a customized approach is the key to our success in resolving all types of cyber incidents. We partner with each client, focusing on not only the future defense to litigation or regulatory action, but also the business’s ability to get back up and running as quickly as possible.

Our attorneys have assisted in corporate ransomware attacks where hundreds of thousands of dollars have been at stake. We have also helped smaller businesses, such as health care providers, with data breach mitigation to allow them to treat their patients in an uninterrupted environment.

In Philadelphia, Karen Grethlein and I handle a large portion of this litigation. Karen is a graduate of Johns Hopkins University and Drexel University Thomas R. Kline School of Law, and she has been with us since 2017. She is active in the Pennsylvania Bar Association and is the current president of the Philadelphia Chapter of the National Association of Women in Construction, where she has lectured on cybersecurity in the construction industry. Karen often advises clients of their statutory reporting obligations following a data breach and encourages them to adopt a proactive approach to data security.

R. David Lane, Jr., shareholder in our New York City office, devotes the entirety of his practice to privacy and data security, representing clients through all stages of data breach response, including investigations, compliance with data breach notification laws and regulatory investigations. Accredited by the International Association of Privacy Professionals as a Certified Information Privacy Professional CIPP/US, David routinely advises clients on legal compliance with state, federal, and international privacy and data security laws. He is a graduate of the University of Florida and the University of Florida Levin College of Law.

As chair of the practice group, I have been handling data breach litigation since the practice’s inception more than 10 years ago. When a breach involves the theft or disclosure of trade secrets, or the violation of a company’s social media policy, my experience as leader of the firm’s Technology, Media, and Intellectual Property Litigation Practice Group is put to good use. In this capacity, I am able to provide critical and immediate counsel, including assisting clients in appropriately and effectively communicating with employees who may be suspected of involvement with a breach incident. I am a graduate of Denison University and Widener University School of Law, and I frequently lecture on cybersecurity and data breach topics to insurance and legal audiences.

            As a full-service insurance defense firm, we have assisted health care, education, finance, banking, retail, energy and utility services throughout the United States in responding to data breaches. Our firm has handled these incidents in all 50 states, and also has handled international events. We work with the clients in notifying either a small number of individuals or hundreds of thousands of affected customers or patients. Working with our health care group, we are able to ensure that HIPAA/Hitech compliance occurs. We are able to ensure that educational FERPA regulations are complied with, as well as all financial and banking SEC and FINRA regulations.

Finally, we continue to assist retail entities in complying with the Payment Card Industry-Data Security Standards (PCI-DSS) compliance. With our extensive experience in defending business entities in consumer-related litigation, we have the attorney resources to manage every aspect of a data breach, from the initial scoping calls with forensic companies to class actions lawsuits that are filed by affected individuals.

If worries about cyberattacks keep you up at night, please don’t hesitate to get in touch. We are here to help and look forward to working with you.

*David, a shareholder, chairs the Privacy & Data Security Practice Group at Marshall Dennehey. He may be reached at djshannon@mdwcg.com or 215.5752615.

Defense Digest, Vol. 27, No. 4, September 2021 is prepared by Marshall Dennehey Warner Coleman & Goggin to provide information on recent legal developments of interest to our readers. This publication is not intended to provide legal advice for a specific situation or to create an attorney-client relationship. ATTORNEY ADVERTISING pursuant to New York RPC 7.1. © 2021 Marshall Dennehey Warner Coleman & Goggin. All Rights Reserved. This article may not be reprinted without the express written permission of our firm. For reprints, contact tamontemuro@mdwcg.com.

Firm Highlights

Thought Leadership

New Jersey Expands Family Leave Protections Effective July 17, 2026

On January 17, 2026, Governor Murphy signed into law legislation expanding the New Jersey Family Leave Act (NJFLA). Beginning July 17, 2026, significant amendments to the NJFLA will expand job-protected family leave to smaller businesses and more employees across the state. The new law broadens coverage by lowering the threshold for private employers from 30 employees to 15 employees, meaning many smaller businesses will now be subject to the NJFLA. Employees of state and local government agencies will continue to be covered regardless of the size of the employer. The amendments also make it easier for employees to qualify for leave. Under the revised law, an employee will be eligible after three months of employment and at least 250 hours worked during the preceding 12 months, replacing the previous requirement of 12 months of employment and 1,000 hours worked. Currently, New Jersey's Temporary Disability Insurance (TDI) and Family Leave Insurance (FLI) programs provide eligible employees with wage replacement while they are on leave but do not independently guarantee job protection. The recent amendments to the New Jersey Family Leave Act (NJFLA) expand these protections by extending job-protected leave to additional employees. Under the amended law, employees receiving TDI or FLI benefits may be entitled to return to the same position they held before taking leave, or to an equivalent position with the same seniority, status, pay, and benefits. Although the legislation also states that it does not expand or modify an employee's reinstatement rights under the NJFLA, the amendments appear to provide job protection to eligible employees receiving TDI or FLI benefits without requiring them to separately satisfy the eligibility requirements of the NJFLA or the federal Family and Medical Leave Act (FMLA). As a result, some employees may be entitled to longer periods of job-protected leave than were previously available under existing law. With these amendments, New Jersey continues to strengthen workplace protections by expanding access to job-protected family leave for eligible employees. These changes significantly expand access to job-protected family leave and may require employers to update their leave policies, employee handbooks, and HR practices. Notably, employers who were previously not required to administer NJFLA may need to amend their policies and/or create new protocols to come into compliance with the NJFLA. Failure to do so would prove costly, as the penalties for non-compliance are significant.

Thought Leadership

SIU Gets a Boost: NJ Supreme Court Affirms Insurers' Right to Litigate, Not Arbitrate, Fraud Claims

In a significant win for insurers' Special Investigation Units, the New Jersey Supreme Court clarified that statutory insurance fraud and racketeering claims may proceed in court rather than through PIP arbitration. At issue was whether insurance fraud claims brought under New Jersey's Insurance Fraud Prevention Act (IFPA) and the state's Anti-Racketeering Act (NJ RICO) are subject to mandatory arbitration under the Automobile Insurance Cost Reduction Act’s (AICRA) PIP dispute-resolution framework. Allstate had sued a network of medical practices, physicians, and related corporate entities, alleging a scheme to extract more than $1.7 million in PIP benefits through fraudulent and misleading billing. The trial court dismissed Allstate's complaint and compelled arbitration, reading AICRA's arbitration clause — which covers "any dispute regarding the recovery of... benefits" under PIP coverage, N.J.S.A. 39:6A-5.1(a) — as sweeping in fraud and racketeering claims along with routine benefit disputes. The Supreme Court affirmed the Appellate Division's reversal, adopting Judge Gilson's opinion below (480 N.J. Super. 566 (App. Div. 2025)) as its own reasoning. The Court held that IFPA and RICO claims fall outside the scope of AICRA's PIP arbitration mechanism because that "streamlined and specialized" process cannot grant the relief those statutes contemplate — treble damages, injunctive relief, broad discovery, and joinder of third parties — and because arbitrators lack authority to award compensatory or treble damages to an insurer. The Court also rejected the argument that Allstate's own Decision Point Review Plans independently compel arbitration, finding those plan provisions no broader than AICRA's own arbitration clause. Notably, the Court expressly disagreed with the Third Circuit's contrary holding in GEICO v. Mt. Prospect Chiropractic Center, 98 F.4th 463 (3d Cir. 2024), concluding it is not bound by that federal interpretation of New Jersey law. Insurers retain the right to pursue IFPA and RICO claims in the Law Division, with a jury trial. For SIU units and NJ insurance carriers, this decision is a significant win: it forecloses defense clinics' primary procedural tool for shunting fraud investigations into limited-scope PIP arbitration, where treble damages, RICO relief, and meaningful discovery were never realistically available. Carriers building cases against fraudulently structured clinics, straw-owned practices, or coordinated billing networks can now proceed with confidence that a well-pleaded IFPA/RICO complaint stays in the Law Division rather than being diverted to arbitration on a motion to compel. Practically, this strengthens SIU's leverage in settlement negotiations, preserves civil discovery tools (subpoenas, depositions, joinder of related corporate entities) critical to unwinding complex ownership and referral schemes, and resolves the split with the Third Circuit in favor of NJ insurers — at least as a matter of state law. Expect increased reliance on IFPA civil actions, rather than PIP arbitration demands, as SIU's primary enforcement vehicle going forward.

Result

No-Cause Jury Verdict Secured in Wrongful Death Trial

We successfully obtained a no-cause jury verdict in a 13-day wrongful death trial. The decedent, a 59-year-old man, was admitted to the emergency room on February 15, 2019, with complaints of abdominal pain, decreased appetite, and constipation, despite the use of laxatives. The patient did not complain of any nausea, vomiting, or diarrhea. He had a significant medical history including diabetes, hypertension, prior coronary artery stenting, morbid obesity (with past gastric bypass surgery), longstanding ventral hernia, and back pain. A CT scan revealed multiple hernias and a potential closed-loop bowel obstruction, leading to a surgery consultation. Our client, an emergency general surgeon, interpreted that the patient did not have a closed loop or any significant obstruction and recommended non-surgical management. The patient was approved to have clear liquids, and had a vomiting incident shortly after, but our client was not notified. The patient was returned to NPO status, and after improving overnight, he was returned to “clears” and additional medical and renal consults were ordered. Our client did not receive any communications from the residents/nurses of any changes in the patient’s condition. On February 18, 2019, two rapid responses were called due to increased heart rate and vomiting. It is believed that the vomiting resulted in aspiration, causing sepsis, ultimately leading to the patient’s death. During the trial, the plaintiff’s sole medical expert highlighted imaging on the wrong hernia, which called into question all of his opinions in the case. We made key objections related to the expert testimony, limiting what the allegations were, and preventing new allegations from being made. After approximately two and a half hours of deliberating, the jury returned a no-cause verdict. 

Thought Leadership

Congress Passes Financial Exploitation Prevention Act

On June 25, 2026, the House passed the Financial Exploitation Prevention Act of 2025 (“the Act”) by a vote of 414 to 2. The Act allows financial advisors and firms to delay suspicious transactions regarding the accounts of clients who are 65 or older, if they believe financial exploitation has occurred or is about to take place. With the advancement of technology and AI, the House’s overwhelming bipartisan passage of the Financial Exploitation Prevention Act represents an important step in strengthening the financial industry’s ability to combat the growing threat of elder financial exploitation. The Act recognizes what advisors have long known that financial professionals are often the first to detect suspicious behavior but have historically lacked clear legal authority to intervene before irreversible financial harm occurs. From the industry’s perspective, the bill accomplishes several important objectives, including the following: (1) Provides a practical “pause button” by allowing financial professionals to temporarily delay certain transaction requests when there is a reasonable belief that a senior or vulnerable adult is being financially exploited; (2) Empowers financial professionals to act by providing greater certainty that firms can act in good faith to protect clients without unnecessary legal risk; and (3) Strengthens investor protection without sacrificing client rights by allowing temporary delays based on a reasonable suspicion of exploitation, which is intended only to allow additional review and not to deny clients access to their money indefinitely. In sum, the Financial Exploitation Prevention Act will equip financial professionals with practical, carefully tailored tools to stop suspected financial exploitation before client assets are lost. By allowing firms to temporarily delay suspicious transactions under defined circumstances, Congress is recognizing the critical role advisors play as the first line of defense against increasingly sophisticated fraud schemes. The Act strikes an appropriate balance between protecting vulnerable investors and preserving individual financial autonomy, while reinforcing collaboration among advisors, families, and law enforcement to combat financial exploitation. The bill now awaits Senate action.