MBAR 2000

Can a lawyer use unencrypted email to communicate confidential information with a client?

Short answer: The committee concluded that in usual circumstances using unencrypted internet email did not violate Rule 1.6, because lawyer and client have a reasonable expectation of privacy, subject to caveats about workplace email and the client's instructions.

Apply this to your situation

This page answers the general question as of 2000. Ezel answers yours: whether it's allowed on your facts, under the current Massachusetts Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2000
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

A lawyer wanted to communicate with a client by unencrypted internet email. Because of how the internet works, an unauthorized person could in some circumstances intercept and read such a message, though the risk was generally remote and interception would usually violate the Electronic Communications Privacy Act (ECPA), 18 U.S.C. section 2510 et seq. The committee framed the question as whether Rule 1.6(a)'s duty to avoid means of communication posing an unreasonable risk of inadvertent disclosure barred unencrypted email.

The committee concluded that, in most instances, using unencrypted internet email to transmit confidential or privileged client communications did not violate Rule 1.6 or any other applicable rule. It reasoned that both lawyer and client typically have a reasonable expectation that the communications will remain legally and effectively private, an expectation not diminished by the technological possibility of interception in violation of federal law. It drew an analogy to the telephone and the U.S. mail, which also carry some risk of interception but are made reasonably secure by legal prohibitions on unauthorized disclosure; in light of statutes like the ECPA, the committee concluded the same reasoning applied to unencrypted email.

The committee added several caveats. A lawyer should not send confidential messages, encrypted or not, to an individual client at the client's workplace without the client's express consent, because employers often reserve the right to review email on their systems, creating an unreasonable risk of disclosure to the employer. A lawyer is always bound by a client's express instruction not to use unencrypted email for confidential information. And the committee stated that lawyers would be advised to obtain the client's express consent before transmitting particularly sensitive confidential information by unencrypted email.

Currency note

This opinion was issued in 2000, before Massachusetts's adoption of the 2015 revisions to the Rules of Professional Conduct. Subsequent rule amendments or later opinions may have changed the analysis. Treat this page as historical context, not current guidance. Verify against current rules before relying on any specific rule, deadline, or requirement mentioned here.

Common questions

Q: Did using unencrypted email to reach a client breach confidentiality?

A: The committee concluded that, in usual circumstances, it did not violate Rule 1.6(a), because lawyer and client have a reasonable expectation of privacy supported by statutes such as the ECPA.

Q: Why treat email like the phone or regular mail?

A: The committee reasoned that all three carry some risk of interception, and that legal prohibitions on unauthorized interception, including the ECPA for email, make them reasonably secure for Rule 1.6 purposes.

Q: Were there situations where the lawyer should not use unencrypted email?

A: Yes. The committee identified emailing a client at the client's workplace without express consent, ignoring a client's express instruction against unencrypted email, and (as advised) sending particularly sensitive information without the client's express consent.

Background and rules framework

The opinion interpreted Mass. R. Prof. C. 1.6(a) (confidentiality of information), focusing on the duty to avoid means of communication posing an unreasonable risk of inadvertent disclosure, against the backdrop of the Electronic Communications Privacy Act. Rule 1.6 corresponded to the Model Rule of the same number as it stood at the time.

Citations and references

Rules of Professional Conduct:

  • Model Rule 1.6 / Mass. R. Prof. C. 1.6(a) (confidentiality; reasonable safeguards against inadvertent disclosure)

Statutes:

  • Electronic Communications Privacy Act, 18 U.S.C. section 2510 et seq.

See also

Source

Get today's answer for your situation

You just read a 2000 opinion on this question. Ezel checks the current Massachusetts Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.