Find Lawyers

Theodore J. Kobus III
Partner

v-card

New York
45 Rockefeller Plaza
New York, NY 10111-0100

T 212.271.1504
F 212.589.4201

Admissions

  • U.S. Court of Appeals, Federal Circuit, 2002
  • U.S. Court of Appeals, Third Circuit, 2002
  • U.S. District Court, District of Colorado, 2009
  • U.S. District Court, Middle District of Pennsylvania, 2004
  • U.S. District Court, Western District of Pennsylvania, 1998
  • U.S. District Court, Eastern District of Pennsylvania, 1995
  • U.S. District Court, District of New Jersey, 1995
  • New York, 2011
  • New Jersey, 1995
  • Pennsylvania, 1994

Education

  • J.D., Widener University School of Law, 1994, cum laude
  • B.S., Chemical Engineering, Purdue University, 1987

Theodore J. Kobus III

SUBSCRIBE
BakerHostetler’s
BakerHostetler’s
Data Privacy Monitor Blog
Ted Kobus is National Co-Leader of the Privacy and Data Protection Team and focuses his practice in the areas of privacy, data breaches and intellectual property.

Ted advises clients, trade groups and organizations regarding data security and privacy risk management, breaches, response strategies, litigation and regulatory actions affecting organizations. He has counseled clients involved in significant breaches implicating state and federal laws, international laws and other regulations and requirements, including HITECH, the Massachusetts Data Privacy Law, California privacy laws (including the California Department of Public Health Law), Connecticut Insurance Department regulations, Puerto Rico’s Citizen Information on Data Banks Security Act, Mexico’s Data Protection Law, Canada’s data privacy requirements and PCI/CISP requirements. He has dealt with Offices of Attorneys General, state insurance departments, Office of Civil Rights (OCR)/Health and Human Services (HHS), Secret Service, FBI and local police and forensics professionals as part of their handling of data breaches.

Risk management is a key component of an organization’s mitigation plan. From advising clients regarding privacy and security compliance in cloud and virtual environments to the impact of social media on the way an organization conducts business, Ted’s services include:

  • Breach response workshops
  • Review and development of policies and procedures reflective of state breach notification laws, international data security laws, HIPAA, HITECH, COPPA, GLBA and other privacy-related laws and regulations
  • Preparation of written information security plans
  • Preparation of incident response plans
  • Drafting and updating of privacy policies, portal agreements, contracts and customer notices to reflect legal developments in privacy
  • Preparation of social media policies
  • Educational webinars and other presentations for employees

Ted has handled more than 350 breaches and his representative experience includes:

  • Healthcare, educational universities, banking, financial, technology service providers, hospitality and retail breaches involving state, local, federal and international laws
  • Breaches involving substantial crisis management and public relations efforts
  • Breaches resulting in identity theft
  • Breaches involving cloud computing services
  • Breaches involving sensitive employment issues
  • Multistate breaches involving high-profile law enforcement investigations and overseas criminals using malware
  • Breaches involving phishing scams and other social engineering tools
  • Breaches and litigation involving PCI DSS compliance
  • International breaches involving notification to both individuals and regulators

His experience extends to litigation of data breach, privacy, technology, media and intellectual property matters nationally, including litigation and audits and actions by governmental regulators such as state attorneys general, HHS and OCR, the Federal Trade Commission (FTC), Federal Communications Commission (FCC), state departments of health and insurance and state and professional licensing boards. Ted has a number of arbitrations, non-jury and jury trials and his representative experience includes:

  • Defense of clients against statutory damages claims, including the California Confidentiality of Medical Information Act (CMIA)
  • Defense of clients involved in class action litigation related to technology, privacy and PCI DSS issues
  • Defense of clients involved in healthcare invasion of privacy cases
  • Defense of clients during investigations by state attorneys general
  • Breaches implicating Family Educational Rights and Privacy Act (FERPA) and resulting investigations by the Department of Education (DOE)
  • Dismissal from a class action litigation involving the Fair and Accurate Credit Transactions Act (FACTA)
  • Defense of technology service providers in enterprise resource planning (ERP) litigation
  • Recent verdict in favor of his client in a matter involving computer source code copyright infringement and trade secret claims
  • Litigation of trademark cases

Ted is a regular contributor to BakerHostetler’s Data Privacy Monitor blog, available at www.dataprivacymonitor.com. He regularly speaks at major industry events regarding data breach response, risk management and litigation issues affecting privacy.

Ted’s presentations and publications include:

  • “The A to Z of Healthcare Data Breaches,” Journal of Healthcare Risk Management, Volume 32, Number 1 (Q3 2012)
  • “Key Steps to Reducing Data Breach Risks: Actions to take before and after a data breach,” The Risk Information Management Society (August 2012)
  • “The Anatomy of a Healthcare Data Breach,” AHLA Connections (June 2012)
  • “Network Security and Privacy Law: A Rapidly Developing Liability Landscape,” Webinar (March 28, 2012)
  • “The A to Zs of Healthcare Data Breaches,” Providence Health & Services’ Comply Rx (February 2012)
  • “Information Security Issues Facing Energy Companies,” New Orleans (2012)
  • “Changing Landscape of Privacy,” Data, Privacy & Risk Management Workshop, San Francisco (2012)
  • “State of the Cyber Nation—Cases, Theories and Damages,” Cyber Risk & Privacy Liability Forum (2012)
  • “Healthcare Cyber Risks and Privacy Breaches—Emergent Problem or Chronic Condition?” Professional Liability Underwriting Society International Conference, San Diego (November 4, 2011)
  • “Are You Ready for A Data Breach?” Association of Lloyd’s Brokers, Chicago (November 1, 2011)
  • “Data Breaches—A to Z,” American Society of Healthcare Risk Managers, Phoenix (October 17, 2011)
  • “Risk Manager’s Guide to Navigating the Evolving Legal, Regulatory and Cyber Liability Landscapes,” American Society of Healthcare Risk Managers, Phoenix, (October 17, 2011)
  • “Data Breaches—Coming to a Network Near You,” Houston and Minneapolis (October 2011)
  • “Cyber Liability: The Real Deal,” Graham University of the Graham Company, Webinar (September 28, 2011).
  • “The Current State of PCI, HIPAA and HITECH Compliance and How It’s Impacting Cyber Liability Coverage and Claims,” American Conference Institute’s Cyber & Data Risk Conference, New York (September 26, 2011)
  • “Regulatory Update,” Webinar (September 2011)
  • “Navigating the Evolving Legal, Regulatory and Cyber Liability Landscapes for Mid-Sized Healthcare Organizations,” Crittenden Chicago Conference (September 2011)
  • “Privacy Issues Facing Law Firms,” Webinar (July 2011)
  • “Social Media—Legal Risks,” Media Financial Management Association CFO Summit, Williamsburg (July 2011)
  • “NetDiligence Cyber Risk & Privacy Liability Forum,” Damages and Other Litigation Issues after A Data Breach Event (June 2011)
  • “Contractual Risk Transfer for Healthcare Organizations,” American Society for Healthcare Risk Management Webinar (May 2011)
  • “Contractual Risk Transfer; Privacy Breaches & Theft: What's Lurking in the Dusty Corners of Your Contract Files Can Hurt You,” Webinar (January 2011)
  • “The Gloves Are Off: Red Flag Enforcement Is Here,” Podcast (December 2010)
  • “Data Breach—A C-Level Issue,” Lutheran Services in America, Baltimore (November 2010)
  • “How Will South Shore’s Breach Impact Us?” Data Breach News (September 10, 2010)
  • “Complying with State Public Notification Requirements and Deadlines: Making Sense of Conflicting Priorities in the Event of a Breach,” 4th Annual Advanced Forum on Cyber & Data Risk Insurance, New York (September 2010)
  • “How The Rite Aid Settlement Impacts Your Disposal Practices,” Data Breach News (July 27, 2010)
  • “Nosey Employees Can Be Costly,” Data Breach News (June 18, 2010)
  • “HIPAA/HITECH Disclosures and Regulatory Enforcement—The ‘Do’s and Don’ts’ When Responding to Data Security and Privacy Breaches,” New Jersey Health Information Management Association's annual meeting, Atlantic City (June 2010)
  • “Data Breach Liability: An Unstable Legal Environment,” NetDiligence Cyber Risk and Privacy Liability Forum, Philadelphia (June 2010)
  • “Are Digital Copiers Leaving Us Vulnerable?” Data Breach News (May 5, 2010)
  • “Best Practices for Health Care Organizations to Keep the Cyber Liability Genie in the Bottle,” Webinar (April 2010)
  • “What Can We Expect in 2010,” Data Breach News (December 29, 2009)
  • “What REALLY Happens After A Breach or Electronic Data Loss Event,” PLUS International Conference, Chicago (November 2009)
  • “New Federal Regulatory Developments & Enforcement Action Regarding Privacy and Security of Information,” and “Third Party Vendors and Suppliers: Limiting Liability Contractually,” ACI 3rd National Advanced Forum on Cyber/Data Risk Insurance, Philadelphia (September 2009)
  • “FTC Red Flag Rules on ID Theft, Now Imminent, Have Broader Application Than Many Realize,” NRRDA Webinar (July 2009)
  • “Flagging Down Identity Theft,” PLUS Journal (Vol. XXII, No. 2) (February 2009)
  • “Data Breach and Security Exposures,” Philly I on Law Day, Philadelphia (December 2008)
  • “Is Your Company A Creditor? Identity Theft Prevention: Know Your Red Flags,” DRI In-House Defense Quarterly (Winter 2008)
  • “Walking The Data Security Tightrope: What Lies Below?” PLUS International Conference, San Francisco (2008)
  • “Evolution of Famous Name Litigation,” InRe Magazine (2007)
  • “Copyright Protection for Architectural Works,” Defense Digest (2006)
Events
2/14/2013 RECORDED WEBINAR: New Cybersecurity Executive Order
1/23/2013 WEBINAR: The HIPAA/HITECH Final Rule is Out
9/19/2012 WEBINAR: Employee Data, Customer Information and Trade Secrets: Are You Ready for a Data Breach?

Articles
1/24/2013 Better Provisions in Vendor Contracts Help Health Care Providers Comply in Increasingly Complex Regulatory Environment Write Kobus, Selby and Karp
7/25/2012 Ted Kobus Publishes “The A to Z of Healthcare Data Breaches” in Journal of Healthcare Risk Management
6/29/2012 Lynn Sessions and Ted Kobus Discuss the Anatomy of a Healthcare Data Breach in American Health Lawyers Association Magazine
3/21/2012 Kobus Publishes Article Discussing Data Security Breaches in the Retail Sector
3/7/2012 Waller and Kobus Write on Top Privacy Issues for Developers in Top Vacation Ownership Industry Magazine

News
5/17/2013 Sessions and Kobus Receive 2013 Distinguished Law Firm Writing Award
2/24/2013 Retail and Hospitality Litigation and Claims Management: Ted Kobus to Speak at Chicago Conference
3/19/2013 Ted Kobus to Speak at ACI Summit on Advertising Privacy Compliance
2/27/2013 Cybersecurity for General Counsels: Ted Kobus Panelist at Georgetown Corporate Counsel Conference
2/27/2013 Ted Kobus to Present “Surviving Data Breach in the Digital Age” at International Association of Privacy Professionals Global Privacy Summit
2/27/2013 Ted Kobus to Discuss HIPAA Omnibus Final Rule at Law Seminars International TeleBriefing
1/24/2013 HIPAA/HITECH Final Rule: What BakerHostetler Can Do to Help
8/8/2012 Kobus to Discuss the State of Cyber Nation at NetDiligence® Cyber Risk and Privacy Liability Forum
6/5/2012 Kobus and Sessions Participate in NetDiligence® Cyber Risk & Privacy Liability Forum
11/4/2011 Baker Hostetler Data Breach Emergency Response Team Launches Data Breach Hotline
9/27/2011 Theodore J. Kobus III Joins Intellectual Property Group

Executive Alert / Newsletters
4/18/2013 Health Law Update—April 18, 2013
4/4/2013 Health Law Update—April 4, 2013
3/21/2013 Health Law Update—March 21, 2013
3/7/2013 Health Law Update—March 7, 2013
2/28/2013 Special Edition: Health Law Update
2/26/2013 International Compendium of Data Privacy Laws
2/21/2013 Health Law Update—February 21, 2013
1/24/2013 Health Law Update—January 24, 2013
1/10/2013 Health Law Update—January 10, 2013
12/6/2012 Health Law Update—December 6, 2012
11/8/2012 Health Law Update—November 8, 2012
10/23/2012 Call Centers Increasingly Targeted in Class Action Lawsuits for Statutory Penalties Under Decades-Old California Law
9/27/2012 Health Law Update—September 27, 2012
7/19/2012 Health Law Update—July 19, 2012
3/29/2012 Health Law Update—March 29, 2012
2/16/2012 Health Law Update—February 16, 2012
2/2/2012 Health Law Update—February 2, 2012
1/5/2012 Health Law Update—January 5, 2012
1/3/2012 California's Privacy Class Action Litigation Du Jour: "Shine the Light" Law
12/13/2011 Focus on Healthcare Privacy
11/4/2011 Baker Hostetler Data Breach Emergency Response Team Launches Data Breach Hotline
10/27/2011 Health Law Update—October 27, 2011
10/26/2011 SEC Issues Guidance on Cyber-Risk Disclosure
10/13/2011 Health Law Update—October 13, 2011
9/29/2011 Health Law Update—September 29, 2011

Quotes
3/6/2013 Companies Need to Make State Regulators Aware of Data Breach, Ted Kobus Tells Law360
2/12/2013 Kobus and Ferguson Discuss Legal Issues Cybersecurity Executive Order Raises with National Law Journal, Law360, CFO.com, Business Insurance and ITT Today
1/24/2013 Better Provisions in Vendor Contracts Help Health Care Providers Comply in Increasingly Complex Regulatory Environment Write Kobus, Selby and Karp
1/25/2012 InformationWeek Quotes Ted Kobus’ Blog Post
10/31/2011 Infosecurity Quotes Ted Kobus’ Blog Post
10/4/2011 InformationWeek Quotes Ted Kobus’ Blog Post