MBAR March 3, 2005

Can a law firm let a software vendor access client files on its system for technical support?

Short answer: Yes. Clients are deemed to impliedly authorize the access under Rule 1.6(a), as with a billing service, but the firm must make reasonable efforts under Rule 5.3(b) to ensure the vendor protects the confidential information. Remote internet access does not change the result.

Apply this to your situation

This page answers the general question as of 2005. Ezel answers yours: whether it's allowed on your facts, under the current Massachusetts Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2005
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

A law firm stored confidential client information (privileged correspondence, financial data, legal memoranda) on a networked computer system that ran a document-management application built by a third-party vendor. The vendor wanted periodic access to the firm's servers and document database to support and update the software, which would unavoidably expose some or all of the stored client information. The firm had not obtained client approval. The question was whether granting that access is consistent with the duty to preserve client confidences under Rule 1.6(a).

The committee concludes the access is permissible because the clients are deemed to have impliedly authorized it. Rule 1.6(a) lets a lawyer reveal confidential information through disclosures impliedly authorized to carry out the representation. Reading Rule 1.6(a) together with Rule 5.3(b) and (c), and relying on its earlier Opinion 89-3 (which permitted disclosure to an independent billing service under former DR 4-101(D)), the committee sees no significant difference between a billing service and a software vendor: computer systems are an essential tool of modern practice, and it is unrealistic to expect a lawyer to scrub all client information before the system can be serviced, especially after an unexpected failure.

The committee stresses that these practical considerations do not relieve the firm of its Rule 5.3(b) duty to make reasonable efforts to ensure the vendor's conduct is compatible with the lawyers' confidentiality obligation. It describes steps that could qualify as reasonable efforts: notifying the vendor of the confidential nature of the data, examining the vendor's confidentiality policies, obtaining written assurances that client information will be used only for technical support and accessed only as needed, and agreeing on additional safeguards for particularly sensitive information. Finally, the committee concludes that providing support remotely over the internet does not change its analysis, citing its Opinion 2000-01 (unencrypted email does not violate Rule 1.6(a) in ordinary circumstances) and noting the firm should still use standard protections such as a firewall and passwords.

In practice

Under this opinion, conduct in which a firm grants a software vendor access to client data for support and maintenance is permitted, on the implied-authorization theory of Rule 1.6(a), provided the firm makes the reasonable efforts Rule 5.3(b) requires to ensure the vendor safeguards confidentiality. Per the opinion, those efforts may include notifying the vendor of the data's confidential nature, reviewing the vendor's policies, obtaining written use-and-access assurances, and arranging extra safeguards for sensitive information. The committee concludes that remote internet-based support does not alter the result.

Common questions

Q: Do clients have to consent before a vendor can access their files?

A: No. The committee concludes clients are deemed to have impliedly authorized the access under Rule 1.6(a), the same way they impliedly authorize use of secretaries, billing services, and other support personnel.

Q: What must the firm do to make this proper?

A: Under Rule 5.3(b) the firm must make reasonable efforts to ensure the vendor's conduct is compatible with the confidentiality duty. The committee lists steps such as notifying the vendor, reviewing its policies, and getting written assurances limiting use and access.

Q: Does it matter that the vendor supports the software remotely over the internet?

A: No. The committee concludes remote internet support does not change the analysis, citing its prior conclusion that ordinary unencrypted email use does not violate Rule 1.6(a), while still expecting standard protections like firewalls and passwords.

Background and rules framework

The opinion interprets Mass. R. Prof. C. 1.6(a) (confidentiality; implied authorization) and Rule 5.3 (responsibilities regarding nonlawyer assistance), corresponding to the Model Rules of the same numbers. It traces the duty to former DR 4-101(D) and applies its earlier Opinions 89-3 and 2000-01.

Citations and references

Rules of Professional Conduct:

  • Model Rule 1.6 / Mass. R. Prof. C. 1.6(a) (confidentiality; impliedly authorized disclosures)
  • Model Rule 5.3 / Mass. R. Prof. C. 5.3(b)-(c) (responsibilities regarding nonlawyer assistants)

Statutes:

  • 18 U.S.C. 2510 et seq. (Electronic Communications Privacy Act), cited on the expectation of privacy in electronic communications

Other opinions cited:

  • MBA Opinion 89-3 (disclosure of client information to an independent billing service)
  • MBA Opinion 2000-01 (unencrypted email does not violate Rule 1.6(a) in ordinary circumstances)

See also

Source

Get today's answer for your situation

You just read a 2005 opinion on this question. Ezel checks the current Massachusetts Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.