When a lawyer gives an outside vendor, like a computer maintenance company, access to client files, what must the lawyer do to protect client confidentiality, and must a breach be reported to the client?
Apply this to your situation
This page answers the general question as of 1995. Ezel answers yours: whether it's allowed on your facts, under the current rules of professional conduct in your state, with citations.
Plain-English summary
The committee considered a law firm that stored all client files on a central computer and gave a computer maintenance company remote terminal access so the company could fix problems without traveling to the firm. In the course of that work, the company's employees could view all or part of the firm's client files. The opinion analyzed the arrangement under the confidentiality duty of Rule 1.6 and the supervision duty of Rule 5.3.
The committee held that giving an outside provider access to client files is a retention of nonlawyers that "triggers the application of Rule 5.3," whose obligation to maintain confidentiality "extends to the activities of nonlawyers who are permitted by the lawyer to come into contact with client file information." Under that rule the lawyer "is required to make reasonable efforts to ensure that the service provider will not make unauthorized disclosures of client information," which means confirming the provider has, or will establish, reasonable procedures to protect confidentiality and fully understands that obligation. The opinion treated the question as one example of a broader pattern, noting that lawyers routinely use outside agencies for accounting, data processing and storage, printing, photocopying, computer servicing, and paper disposal, all of which can entail access to client files.
On breaches, the committee concluded that should a significant breach of confidentiality occur within such a provider, "a lawyer may be obligated to disclose such breach to the client or clients whose information has been revealed" under Rule 1.4(b). Where an unauthorized release could reasonably be viewed as a significant factor in the representation, for example because it is likely to affect the client's position or the outcome of the matter, the opinion stated that disclosure of the breach would be required.
Currency note
This opinion was issued in 1995, before the American Bar Association's adoption of the 2002 (Ethics 2000) revisions to the Model Rules of Professional Conduct, and well before the 2012 technology amendments that added Rule 1.6(c) and reframed Rule 5.3 around "nonlawyer assistance." Subsequent rule amendments and later opinions (including those on data breaches and electronic client information) may have changed the analysis. Treat this page as historical context, not current guidance. Verify against current rules before relying on any specific rule, deadline, or requirement mentioned here.
Common questions
Q: Could a law firm give an IT or maintenance vendor access to client files?
A: Yes, but the opinion held the lawyer had to make reasonable efforts under Rule 5.3 to ensure the vendor had, or would establish, reasonable procedures to protect the confidentiality of client information.
Q: What specific step did the opinion suggest for vetting the vendor?
A: The committee suggested that a lawyer might be well advised to secure from the provider a written statement of its assurance of confidentiality, separate from or alongside any services contract.
Q: Did a confidentiality breach by the vendor have to be reported to the client?
A: The opinion concluded that a significant breach may have to be disclosed to the affected client under Rule 1.4(b), particularly where the unauthorized release could be a significant factor in the representation.
Background and rules framework
The opinion interpreted Rule 1.6 (confidentiality of information), which bars revealing information relating to the representation, and Rule 5.3 (responsibilities regarding nonlawyer assistants), which the committee read to require reasonable efforts to ensure that nonlawyers with access to client information act compatibly with the lawyer's confidentiality duty. It applied Rule 1.4(b) (communication) to the duty to tell a client about a significant breach. Because the ABA interprets the Model Rules directly, there is no state-rule analogue.
Citations and references
Rules of Professional Conduct:
- MR 1.6 (confidentiality of information)
- MR 5.3 (responsibilities regarding nonlawyer assistants)
- MR 1.4(b) (communication; explaining a matter so the client can make informed decisions)
Other opinions cited:
- Oregon State Bar Formal Op. 1995-141: a firm contracting with a recycling firm to dispose of office files must instruct it on confidentiality and secrecy
See also
- ABA Formal Op. 506: Responsibilities regarding nonlawyer assistants
- ABA Formal Op. 08-451: Outsourcing legal and nonlegal support services
- ABA Formal Op. 483: Obligations after an electronic data breach
- ABA Formal Op. 477R: Securing communication of protected client information
Source
- Landing page: ABA Formal Ethics Opinions index
- Original PDF: 95-398.pdf
Get today's answer for your situation
You just read a 1995 opinion on this question. Ezel checks the current rules of professional conduct in your state and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.