Over 3,200 data breaches were reported in the United States in 2024, exposing more than 1.3 billion records. That number keeps growing. So does the volume of people calling law firms to ask if they have a case.
The intake problem nobody talks about: most of these callers have no idea whether they have a viable claim. They saw the news. They got a settlement notice in the mail. Their email showed up on a breach-monitoring service. They are scared and confused and searching for answers.
Whoever picks up that phone call is making a qualification decision that most front desk staff and paralegals have never been trained to make. Data breach cases are not personal injury cases with a different fact pattern. The liability theory is different, the harm may not be tangible yet, the class action dimensions add complexity, and the statutes of limitations vary significantly by state and by type of data involved.
Here is what a high-performing data breach intake call actually looks like.
In a standard personal injury call, the harm is usually obvious. In a data breach call, three things are fundamentally different.
The caller may not know what data was exposed. They received a generic breach notification that said “certain personal information” may have been accessed. That could mean name and address. It could mean Social Security number and medical records. The difference in case value between those two scenarios is enormous, and the caller often does not know which applies to them.
The harm may not have materialized yet. Unlike a car accident where the injuries are immediate, data breach harm can take months or years to surface. Identity theft, fraudulent account openings, and credit damage can happen long after the breach itself. This means the caller may have a strong case even if they have not experienced any harm yet, or their harm may be under-recognized because they do not connect it to the breach.
Class action dynamics complicate the intake. Many data breach callers are already part of a class action they do not know about. Others received a settlement notice and are calling to find out whether to opt in or opt out. Understanding where the caller sits in relation to existing litigation is a critical intake function that requires specific questions.
Whoever handles intake needs to work through these questions on every data breach call. The order matters.
This one question tells you what you are dealing with. There are three paths:
A notification letter or email from the company means the caller is a confirmed affected party. The company has self-reported their data as part of the exposure. This is the strongest starting position.
News coverage or a breach-monitoring service (like HaveIBeenPwned) means the caller self-identified after seeing the breach covered publicly. They believe their data may have been exposed. You need to confirm whether they actually did business with the breached company.
A class action settlement notice in the mail is the most action-ready scenario. The caller is already a certified class member. The case is already litigated. The only question is whether the settlement is fair or whether they should opt out and pursue individual claims. Get that deadline immediately.
Get the name and, if possible, the date the breach was publicly disclosed. This matters because your firm may already be involved in existing litigation around this breach. There may be filing deadlines you need to flag for attorney review. Some breaches have been the subject of multiple competing class actions in different jurisdictions. The breached company’s headquarters determines which courts and which state laws apply.
Some callers will know exactly who was breached. Others will say something like “the hospital I went to a few years ago” or “some store I used to shop at.” Do not guess. Get specific enough for the attorney to identify the defendant.
The relationship determines standing and may surface additional claims.
Customer or account holder: standard consumer data breach claim.
Patient of a healthcare provider: HIPAA applies. Healthcare breaches carry additional regulatory penalties and a different damages framework. Flag this explicitly in your notes every time.
Employee: may have wage records, tax information, and other employment data exposed. In some states, biometric privacy laws like Illinois BIPA create additional claim pathways for employees whose biometric data was collected and then breached.
Former customer or patient: same claims, but you also need to understand how long ago the relationship ended, because some states apply shorter statutes of limitations to claims arising from expired commercial relationships.
Walk them through this. Do not assume they know the full scope of what was in the breach.
Name and address only: lower damages profile. Class claims are possible but individual awards are typically small.
Social Security number: this is a significant escalation. SSN exposure creates direct identity theft risk, and courts have been more willing to recognize standing even absent documented harm when SSN is involved.
Financial account information or credit card numbers: fraudulent use of financial data creates direct, documentable harm. Strong case.
Medical or health records: very high value. HIPAA violations, state medical privacy statutes, and the sensitivity of the data all support stronger damages claims.
Biometric data (fingerprints, face scans, voice data): state biometric privacy laws in Illinois, Texas, Washington, and several other states create statutory damages that do not require proof of actual harm. Illinois BIPA provides $1,000 to $5,000 per violation.
Government ID or driver’s license: significant. Used in identity theft and fraud.
The more sensitive the data, the stronger the damages case. Record exactly what the caller knows was in the breach.
This is the question that determines the strength of an individual claim versus a class claim. Ask them directly:
Even small documented harms matter. Courts have recognized that time spent on remediation is a compensable injury in data breach cases. A caller who spent 10 hours disputing fraud and placing credit freezes has documented damages, even if they recovered all unauthorized charges.
If the caller has zero documented harm and the breach only exposed name and address, be honest about the challenges. Class participation may be appropriate. An individual lawsuit is a harder case at that point.
Statutes of limitations for data breach claims run from one to three years depending on the state, and the clock starts either at the time of the breach or at the time of discovery, depending on jurisdiction. You need both dates.
If the breach was in 2021 and they are calling in 2026, you may have a tolling argument based on when they discovered the exposure. But you also may have a window problem that needs immediate attorney review. Flag time-sensitive cases for same-day escalation.
If yes, everything changes. You need the name of the case and court (usually on the notice), the settlement deadline and specifically the opt-out deadline, and a copy of the notice (ask them to email or text a photo).
Class action settlement notices typically give class members 30 to 60 days to opt out and pursue individual claims. If that deadline is coming up, this needs to go to attorney review today. Whether accepting the class settlement is the right call depends on the individual’s harm profile. That is an attorney decision, but intake needs to surface the deadline for that decision to get made in time.
Most data breach callers are not angry. They are anxious. They received a letter telling them their medical records may have been exposed, and they do not know what that means for their life. Whoever picks up the phone needs to simultaneously gather qualification information and provide enough reassurance that the caller stays engaged.
A framing that works:
“I completely understand why you called. This is worth looking into, and I want to make sure we capture everything the attorney needs to assess your situation properly. I am going to ask you a few specific questions. It will take about five minutes. Does that work for you?”
The structure of the intake call itself is reassuring, because it signals competence. A caller who hears a disorganized intake response loses confidence in the firm before they ever speak to an attorney.
Do not tell them they definitely have a case before the attorney has reviewed it. Do not promise specific outcomes. Do not minimize their concern. Listen, ask the questions, capture the information, and set clear expectations for next steps.
Not every caller has a viable individual claim. Be direct about the factors that work against a case.
Exposure-only with no documented harm and low-sensitivity data. Name and email address exposure with zero negative consequences is very difficult to litigate individually in most jurisdictions. Class participation may still be appropriate.
Time-barred claims. If the breach occurred more than three years ago, the caller learned about it at the time, and there is no credible tolling argument, you may not have a viable filing window.
Already settled. If the caller accepted a class action settlement payment and cashed the check, they have likely released all individual claims.
Low-sensitivity data, no harm, no class action. A one-person website breach that exposed name and address is not an individual lawsuit and is unlikely to attract a class action. Be honest about this with the caller.
Being clear about what does not qualify is as important as being clear about what does. Callers who get honest assessments from your firm trust it. That trust produces referrals.
Not asking about the settlement notice deadline. This is the single highest-consequence miss. A caller with an opt-out deadline three weeks out that you do not capture results in a missed attorney decision and a potentially released individual claim.
Treating all breach types the same. Healthcare breach, financial data breach, and credential breach each have different legal frameworks and different damages profiles. The intake questions should branch on data type.
Not confirming the caller’s relationship to the company. Customer, patient, employee. This changes the claim analysis materially and should always be captured.
Missing the HIPAA angle. When a caller mentions a hospital, clinic, health insurer, or any healthcare entity, flag it explicitly in the notes. HIPAA-related breaches have separate regulatory pathways and class action strategies that change the attorney’s analysis.
Moving too fast. Data breach callers are often uncertain about what they have. The intake call needs to be slower and more conversational than a standard PI call. The quality of what you capture on this call directly determines the quality of the attorney’s case assessment.
The challenge with data breach intake is branching complexity. When the caller mentions they were a patient, the HIPAA overlay changes the analysis. When they mention a settlement notice, the urgency and the framing change entirely. When they mention biometric data, state privacy laws create a completely different statutory framework.
Whoever picks up the phone cannot be expected to hold all of this in memory, especially if they are handling calls across multiple practice areas throughout the day.
Real-time AI coaching changes this by listening to the call and surfacing the right question at the right moment. When the caller mentions a healthcare provider, the coaching system flags HIPAA before the intake coordinator moves on. When a settlement notice comes up, the system immediately prompts for the deadline.
This is the difference between intake that captures what the caller volunteers and intake that actually extracts the information that determines case value. The same call, handled with real-time coaching, produces a materially better record for the attorney.
eNZeTi gives your intake coordinators real-time coaching, mid-call, so every conversation moves toward a signed case.
Get Your Free Intake Audit →