MEBAR June 30, 2008

Can a Maine lawyer communicate with clients by unencrypted email without violating the duty of confidentiality?

Short answer: Yes, as a general matter and subject to appropriate safeguards. The opinion concludes lawyers have a reasonable expectation of privacy in unencrypted email, but reasonable judgment may require a more secure method for highly sensitive information.

Apply this to your situation

This page answers the general question as of 2008. Ezel answers yours: whether it's allowed on your facts, under the current Maine Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2008
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

Bar Counsel asked whether using unencrypted email to communicate with clients violates the confidentiality duty in former Maine Bar Rule 3.6(h). The Commission concludes that, as a general matter and subject to appropriate safeguards, an attorney may use unencrypted email without violating the obligation to maintain client confidentiality.

The opinion relies on ABA Formal Opinion 99-413, which found lawyers have "a reasonable expectation of privacy in communications made by all forms of e-mail, including unencrypted e-mail sent on the Internet, despite some risk of interception and disclosure." The ABA grounded that conclusion in both law (federal statutes criminalizing unauthorized interception of email and regulating ISPs) and technology (transmissions are fragmented and routed separately before reassembly). The Commission finds that reasoning, and the majority of other jurisdictions following it, persuasive.

The opinion then frames the limits through Maine Bar Rule 3.6(a)'s reasonable-care standard. When choosing a form of communication, a lawyer should weigh both the content and the security of the recipient's email address; the opinion gives the example of a divorce client whose spouse may share access to a home account, and notes employers often monitor workplace email. It identifies misaddressed email and "reply to all" mistakes as a greater concern than interception, to be handled through diligence rather than encryption. Finally, the opinion states that because interception, though unlikely, is possible, lawyers should use a means other than the internet when information is so highly confidential that disclosure would significantly damage the client's interests.

In practice

Under the former Maine Bar Rules in effect when the opinion issued (the Commission has treated this conclusion as carrying forward under the Maine Rules of Professional Conduct, and Opinion 207 (2013) cites it as such), the opinion holds that routine attorney-client communication by unencrypted email does not, by itself, breach the duty of confidentiality. The opinion conditions that conclusion on reasonable care: considering the sensitivity of the content and the security of the recipient's address, guarding against misaddressed or "reply to all" email through ordinary diligence, and selecting a more secure method where the information is highly confidential and disclosure would cause significant damage. The opinion also frames discussing the client's preferred communication method, and following the client's wishes, as part of that reasonable judgment.

Common questions

Q: Is unencrypted email to a client a confidentiality violation in Maine?

A: No, as a general matter. The opinion concludes that, subject to appropriate safeguards, a lawyer may use unencrypted email without violating the duty to maintain client confidentiality.

Q: Why is unencrypted email considered private enough?

A: The opinion adopts the ABA's reasoning that lawyers have a reasonable expectation of privacy in unencrypted email, given federal laws criminalizing interception and the way transmissions are fragmented and routed across the internet before reassembly.

Q: When should a lawyer use something more secure than email?

A: When the information is so highly confidential that disclosure would result in significant damage to the client's interests. The opinion states lawyers should then employ reasonable judgment in selecting a means of communication other than the internet.

Q: What everyday email mistakes does the opinion flag?

A: Misaddressed email and replying "to all" so that unintended recipients receive a message. The opinion treats these as a greater concern than interception and says they are addressed through diligence, not encryption.

Background and rules framework

The opinion interprets former Maine Bar Rule 3.6(h)(1), which barred a lawyer from knowingly disclosing confidential information without informed consent, together with the general reasonable-care standard of Maine Bar Rule 3.6(a). These correspond to ABA Model Rule 1.6 (confidentiality) and Model Rule 1.1 (competence). The analysis rests on ABA Formal Opinion 99-413 and a majority of state opinions reaching the same conclusion.

Citations and references

Rules of Professional Conduct:

  • Model Rules 1.6, 1.1
  • Maine Bar Rules 3.6(a), 3.6(h)

Statutes:

  • 18 U.S.C. §§ 2510 et seq. (interception of electronic communications).

Other opinions cited:

  • ABA Formal Op. 99-413 (1999).
  • Ohio Op. 99-2; Hawaii Op. 40; Utah Op. 00-01; Florida Op. 00-4; Delaware Op. 2001-2; Virginia Op. 1791; Iowa Op. 1997-1.
  • Maine Prof. Ethics Comm'n Op. #134.

See also

Source

Original opinion text

Reproduced from the official source for research purposes. The linked source is authoritative.

Issued by the Professional Ethics Commission

Date Issued: June 30, 2008

Question

Bar Counsel has requested a formal opinion on the following question:

Is it a violation of Maine Bar Rule 3.6(h) (confidentiality of information) for an attorney to communicate with clients by unencrypted e-mail.

Opinion

The Commission concludes that, as a general matter and subject to appropriate safeguards, an attorney may utilize unencrypted e-mail without violating the attorney's ethical obligation to maintain client confidentiality.

Bar Rule 3.6(h)(1) provides that ?a lawyer shall not, without informed consent, knowingly disclose? confidential information ?except as permitted by these rules, or when authorized in order to carry out the representation, or as required by law or by order of the court.? Whether in paper or e-mail form, much correspondence between attorneys and clients is obviously confidential under Rule 3.6(h)(1).

In 1999, the American Bar Association Standing Committee on Ethics and Professional Responsibility (ABA) issued Formal Opinion No. 99-413, providing a comprehensive analysis of the obligations of lawyers regarding e-mail communication under the Model Rules of Professional Conduct.[1] The opinion discusses the risks of disclosure inherent in many of the forms of communication available today to attorneys and their clients, including different e-mail technologies. [2] Internet e-mail was considered to be the least secure, although of course it is the most common method of e-mail transmission. The ABA concluded that lawyers had:

?a reasonable expectation of privacy in communications made by all forms of e-mail, including unencrypted e-mail sent on the Internet, despite some risk of interception and disclosure.?

In reaching this conclusion, the ABA relied on both law and science for reasons that remain relevant today. Federal law criminalizes unauthorized interception or disclosure of e-mail in transit or storage and strictly regulates the rights of internet service providers (ISPs), through whose computers internet e-mail passes, to inspect traffic. [3] In addition, the electronic process of sending e-mail divides individual transmissions into fragments of information, each of which follows a different path through the internet before being reassembled on the receiver?s computer. In view of the federal legal prohibitions and the technological difficulties of intercepting more than a fragment of any communication, the ABA concluded that there was a reasonable expectation of privacy in unencrypted e-mail.

Most other jurisdictions that have considered this question have arrived at the same conclusion. [4] Opinions to the contrary have noted the possibility of interception despite these legal and technological safeguards and have advised attorneys to either obtain informed consent from clients or use encryption prior to sending confidential information by e-mail. [5]

The Commission finds the reasoning in the ABA and majority opinions to be persuasive and hence concludes that an attorney generally may utilize unencrypted e-mail without violating the attorney's ethical obligation to maintain client confidentiality, subject to the caveats discussed below.

The Commission, however, notes that Maine Bar Rule 3.6(a) sets forth a general standard requiring lawyers to "employ reasonable care and skill and apply the lawyer's best judgment in the performance of professional services.? When exercising professional judgment in choosing a particular form of communication, lawyers should consider both the content of the communication as well as the security of the email address to which it is being sent. For example, an attorney representing a client in a divorce would generally not send sensitive advice in a letter to the client?s home address if the couple had not yet separated. Similarly, lawyers should be sensitive to the fact that others may have access to a client?s e-mail address, especially at home. Likewise, some places of business routinely monitor their employees? e-mail and often have access to it.

Of greater concern is the prospect of misaddressed email or that which is replied ?to all? in response to a broadcast email when some of the original recipients are not intended to receive the reply. [6] However, that potential problem must be dealt with through the routine application of diligence and is not corrected by use of encrypted email. Finally, since e-mail interception, though unlikely, is a possibility, attorneys should employ reasonable judgment in selecting a means of communication other than the internet when the information is of such a highly confidential nature that disclosure would result in significant damage to the client?s interests.

While it is impractical to try to fashion precise rules concerning email conduct geared to specific circumstances and ever-changing technology, as general guidance attorneys should discuss with clients their preferred method(s) of communication and follow the client?s wishes, should consider the degree of confidentiality of particular information in determining appropriate means to send it, and should take reasonable precautions to make sure that the address is correct and properly targeted. With these general cautions in mind, and noting that reasonable judgment may require additional safeguards depending upon the circumstances, an attorney may utilize unencrypted e-mail without violating the attorney's ethical obligation to maintain the confidentiality of client information. [7]

Footnotes

[1] Model Rule 1.6 provides that ?a lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent.?

[2] The opinion discusses postal service and commercial mail systems, landline telephones, cordless and cellular phones and facsimile, in addition to e-mail.

[3] See 18 U.S.C. §§ 2510 et. seq.

[4] See for example Ohio Ethics Opinion No. 99-2 (April 9, 1999), Hawaii Ethics Opinion No. 40 (April 26, 2001), Utah Ethics Opinion No. 00-01 (March 9, 2000), Florida Ethics Opinion No. 00-4 (July 15, 2000), Delaware Ethics Opinion No. 2001-2 (2001), Virginia Ethics Opinion No. 1791 (December 22, 2003), and the other authorities set forth in footnote 40 of ABA Formal Opinion No. 99-413.

[5] See Iowa Bar Ass?n. Op No. 1997-1 (1997). Missouri Bar Disciplinary Counsel requires lawyers to notify all recipients of e-mail that (1) e-mail communication is not a secure method of communication; (2) any e-mail that is sent may be copied and held by various computers it passes through; and (3) persons not participating in a communication may intercept it by improperly accessing a computer through which email has passed.

[6] For example, if an attorney sends her client a copy of an email to opposing counsel, that client may inadvertently also receive a copy of a reply ?to all? from opposing counsel. In addition to the simple miscommunication, this could implicate Bar Rule 3.6(f), which prohibits communication with a represented party.

[7] Since non-lawyer staff may participate in client communications, attorneys should be aware of Maine Bar Rule 3.13(c) as regards training non-lawyer staff on office policies and any specific constraints relevant to a particular client. See for reference Opinion #134.

Get today's answer for your situation

You just read a 2008 opinion on this question. Ezel checks the current Maine Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.