ABA Model Rule 1.6 and Your IT Setup: What Every Managing Partner Must Know
Geek Heros War Stories
What the Rule Actually Says
ABA Model Rule 1.6(c) states that a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. This language, adopted by nearly every state bar association in some form, places a direct obligation on attorneys to protect client data—including the technology systems that store and transmit it.
The key phrase is "reasonable efforts." It's intentionally broad, and that breadth is what makes it both flexible and dangerous. Flexible because it adapts to different firm sizes and practice areas. Dangerous because "reasonable" is ultimately defined by courts, bar associations, and expert witnesses after a breach has already occurred.
How Courts and Bar Associations Interpret "Reasonable"
Over the past decade, multiple state bar ethics opinions have clarified what "reasonable efforts" means in the context of technology. The consensus is clear: attorneys have an affirmative duty to understand the technology they use and to implement appropriate safeguards.
ABA Formal Opinion 477R specifically addresses confidentiality obligations in the digital age, stating that lawyers must assess the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer's ability to represent clients.
Several state bar disciplinary proceedings have found attorneys in violation of Rule 1.6 for failures as basic as using unsecured email for sensitive communications, failing to implement password policies, and storing client data on unencrypted devices.
5 Technology Standards That Qualify as "Reasonable"
Based on current ethics opinions, case law, and industry standards, here are five technology requirements that any law firm should treat as mandatory under Rule 1.6:
1. Encryption at Rest and in Transit All client data must be encrypted—both when stored on your servers or cloud systems (at rest) and when being transmitted via email or file sharing (in transit). This means TLS-encrypted email, encrypted hard drives, and encrypted cloud storage. Sending unencrypted client documents via standard email is a compliance risk.
2. Multi-Factor Authentication Passwords alone are no longer sufficient. MFA adds a second verification layer that dramatically reduces the risk of unauthorized access. Every system that touches client data—email, document management, practice management software—should require MFA.
3. Access Logging and Audit Trails You need to know who accessed what data and when. This means implementing logging on your file systems, email accounts, and practice management platforms. If a breach occurs, the first question investigators will ask is: "Do you have logs?" If the answer is no, your "reasonable efforts" defense becomes extremely difficult.
4. Employee Security Training Your staff is your biggest vulnerability. Phishing attacks, social engineering, and accidental data exposure account for the majority of law firm breaches. Regular, documented security training—including phishing simulations—demonstrates that you're taking reasonable steps to prevent human error.
5. Incident Response Planning Having a written, tested incident response plan shows that you've anticipated the possibility of a breach and prepared accordingly. This plan should include immediate containment steps, client notification procedures, regulatory reporting requirements, and forensic investigation protocols.
Real-World Consequences of Non-Compliance
The consequences of failing to meet these standards are not theoretical. Attorneys have faced bar complaints for data breaches caused by inadequate security measures. Malpractice insurers have denied claims when firms couldn't demonstrate reasonable technology safeguards. Clients have sued for negligence when their confidential information was exposed due to a firm's failure to implement basic protections.
In one notable case, a mid-size firm faced disciplinary proceedings after a ransomware attack exposed thousands of client files. The investigating committee found that the firm had no MFA, no encryption, no backup verification, and no incident response plan. The managing partner's defense—"We relied on our IT guy"—was rejected. The committee noted that the duty to protect client data cannot be delegated without oversight.
What a Compliant IT Setup Looks Like
A Rule 1.6-compliant IT infrastructure isn't exotic or prohibitively expensive. It requires encrypted systems, enforced MFA, maintained access logs, regular staff training, and a documented incident response plan. At Geek Heros, every engagement includes these elements as standard. We provide the technical implementation and the documentation you need to demonstrate compliance to your bar association, your malpractice insurer, and your clients.
Your ethical obligation is clear. The question is whether your technology meets it. Contact us for a free compliance assessment.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.