ISBA 2010

Can a law firm let an outside IT vendor access its network and client files without breaking confidentiality rules?

Short answer: Yes, on or off site, if the firm makes reasonable efforts to protect client information under Rules 1.6 and 5.3, such as a written confidentiality agreement with the vendor. Whether access is remote or physical does not matter so long as adequate safeguards are in place.

Apply this to your situation

This page answers the general question as of 2010. Ezel answers yours: whether it's allowed on your facts, under the current Illinois Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2010
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

The opinion addresses a firm that wants an off-site vendor to manage and monitor its computer network, where the vendor would need access to the network on which electronic client files are stored, whether the server sits at the firm with remote access or physically at the vendor. The Committee frames the issue around two rules: Rule 1.6(a) (confidentiality of information) and Rule 5.3 (responsibilities regarding nonlawyer assistants).

Because the vendor is a nonlawyer who would have access to client files, the opinion concludes the firm must protect those files under Rules 1.6(a) and 5.3 by making reasonable efforts to ensure the vendor has or will institute reasonable procedures to safeguard confidentiality. The opinion aligns this with ABA Formal Op. 95-398 and ABA Formal Op. 08-451, which treat retaining outside service providers as commonplace and strongly advise written confidentiality agreements, and with Massachusetts Bar Op. 05-04 and Section 60 of the Restatement (Third) of the Law Governing Lawyers. It lists reasonable steps such as notifying the vendor of the confidential nature of the information, examining the vendor's policies, and obtaining written assurances that access is limited to technical support and that the vendor will protect all client information.

The opinion also notes that if the vendor breaches confidentiality, the lawyer may be obligated under Rule 1.4(b) to disclose the breach to the client where it is likely to affect the client's position or outcome, and that other laws (such as data-breach notification statutes) may require disclosure. Finally, it concludes the physical or remote nature of the vendor's access is irrelevant so long as adequate safeguards are taken, citing the ABA's view that even unencrypted internet communication does not by itself violate Rule 1.6.

In practice

Under the Illinois Rules, the opinion holds that outsourcing network administration to a third-party vendor is permissible if the firm takes reasonable steps to protect client confidentiality, and it treats a written confidentiality agreement as the advisable mechanism. The opinion further indicates that a vendor's breach may trigger a Rule 1.4(b) duty to inform the client, and that the choice between remote and on-site access does not change the analysis when safeguards are adequate.

Common questions

Q: Can a law firm outsource its IT to a vendor that can see client files?

A: Yes. The opinion concludes the arrangement does not violate confidentiality rules if the firm makes reasonable efforts under Rules 1.6 and 5.3 to ensure the vendor safeguards the client information.

Q: What steps should the firm take with the vendor?

A: The opinion points to obtaining a written confidentiality agreement and assurances that access is limited to technical support, and to examining the vendor's policies for handling confidential information.

Q: Does it matter whether the server is at the firm or at the vendor?

A: No. The opinion concludes the physical or remote nature of the vendor's access is irrelevant so long as adequate safeguards are in place.

Q: What if the vendor leaks client information?

A: The opinion concludes the lawyer may be required under Rule 1.4(b) to disclose the breach to the client if it is likely to affect the client's position or outcome, and that other laws may also require notification.

Background and rules framework

The opinion interprets Illinois Rule 1.6(a) (confidentiality of information), Rule 5.3 (responsibilities regarding nonlawyer assistants, which makes the lawyer responsible for nonlawyer conduct in defined circumstances), and Rule 1.4(b) (keeping the client informed). It relies on ABA Formal Opinions 95-398 and 08-451, Massachusetts Bar Op. 05-04, and Section 60 of the Restatement (Third) of the Law Governing Lawyers.

Citations and references

Rules of Professional Conduct:

  • MR 1.6 (confidentiality of information) / IL Rule 1.6(a)
  • MR 5.3 (responsibilities regarding nonlawyer assistants) / IL Rule 5.3
  • MR 1.4 (communication) / IL Rule 1.4(b)

Statutes:

  • Electronic Communications Privacy Act, 18 U.S.C. Section 2510

Other opinions cited:

  • ABA Formal Op. 95-398 (1995): outside service providers and client confidentiality
  • ABA Formal Op. 08-451 (2008): outsourcing legal and nonlegal services
  • Massachusetts Bar Op. 05-04: vendor access to a firm's computer system

See also

Source

Get today's answer for your situation

You just read a 2010 opinion on this question. Ezel checks the current Illinois Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.