Coughlin & Cerhart, LLP
| Primary URL | Location | Industry | www[.]coughlincerhart[.]com |
Country
United States of America
|
Commercial
|
|---|
Profile
Coughlin & Cerhart, LLP operates as a limited liability partnership that provides legal services to clients. The firm is headquartered in the United States, with its offices located in New York State. As a law firm, it engages in advising and representing clients across various legal matters. The partnership structure indicates shared ownership among the named partners. The firm's primary function is the delivery of counsel and advocacy in accordance with legal practice standards.
On April 1, 2021, the firm experienced a security breach that involved unauthorized access to its internal systems. The incident exposed a wide range of sensitive client information, including names, addresses, Social Security numbers, driver's license and passport details, financial account information, medical records, and health insurance data. Initial assessments suggested the breach may have been the result of a ransomware attack. The compromise of such data raised concerns about the protection of personally identifiable information and protected health details. The event was reported by cybersecurity news outlets as another example of a law firm being targeted.
The breach highlighted that the firm stores extensive personal and medical information that falls outside the scope of HIPAA coverage. Legal entities such as Coughlin & Cerhart, LLP are not considered covered entities under the Health Insurance Portability and Accountability Act. Nevertheless, the firm’s client matters involve the handling of health‑related data, as evidenced by the compromised medical records and health insurance information. This situation underscores the particular vulnerability of law firms that accumulate diverse datasets without the regulatory safeguards applied to healthcare providers. The incident illustrates the importance of robust security measures for protecting non‑HIPAA‑regulated sensitive information in legal practices.
The source does not provide information on the firm's size, number of attorneys, or annual revenue. No details are given about the firm's ownership structure beyond its designation as a limited liability partnership. The incident remains documented as a notable cybersecurity event involving a New York‑based law firm. The breach contributes to the public record of security incidents affecting legal service providers. No further public disclosures about subsequent actions or outcomes are available in the referenced material.
