MICHBAR January 25, 2002

Can a government law department let the agency's general IT department maintain a network holding confidential client files?

Short answer: The opinion concludes a government law department may use the governmental unit's technical support staff to service a network containing client confidences without violating MRPC 1.6, provided the lawyer takes reasonable care under MRPC 1.6(d) to communicate the confidentiality obligations to that staff.

Apply this to your situation

This page answers the general question as of 2002. Ezel answers yours: whether it's allowed on your facts, under the current Michigan Rules of Professional Conduct, with citations.

Currency note: this opinion is from 2002
Subsequent statutory amendments, court decisions, or later opinions or rule amendments may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page) is the authoritative source for any reliance.

Plain-English summary

A lawyer in a local-government law department helped maintain a local area network (LAN) holding confidential client information (word processing, case-management data, and stored documents). The governmental unit's technology department, which is not part of the law department, provides technical support for the LAN. The lawyer asked whether giving that department access for support purposes violates the duty of confidentiality under MRPC 1.6.

The Committee compared the situation to prior opinions. In RI-77 and RI-111 it had found impermissible disclosures where the facts fit no exception (sending client names to a bank lender; reporting client information to regulators or prosecutors); in RI-311 it allowed disclosure of client names to the Legal Services Corporation because federal law required it. Here, the technical-support employees would have access to client information but would not be using it to the client's disadvantage. Drawing on ABA Informal Opinion 1364 (allowing bookkeepers, accountants, and data-processing professionals access to a lawyer's records to assist in practice), the Committee concluded that using the governmental unit's technical-support personnel to assist with computer issues does not by itself violate MRPC 1.6(b).

Under the reasonable-care requirement of MRPC 1.6(d), the Committee said the law department should clearly communicate the confidentiality obligations to the technical-support personnel, and noted it would be prudent to obtain a written acknowledgment that they have been advised of and agree to the requirements. The degree of care scales with the sensitivity of the information, and the lawyer must take necessary steps to keep particularly sensitive confidences outside the view of support personnel. The opinion assumed those personnel have no specific interest in the substance of the information and no likelihood of using it to the client's disadvantage.

In practice

The opinion holds that, under the Michigan rule as it stood at the time, a government law office's use of the agency's general technical-support staff to service a network containing client confidences does not, by itself, violate MRPC 1.6(b). Per the opinion, the lawyer's obligation under MRPC 1.6(d) is to communicate the confidentiality requirements to that staff and to exercise care proportionate to the sensitivity of the information, with a written acknowledgment described as prudent.

Common questions

Q: Does letting shared IT staff access client files breach confidentiality?

A: Per the opinion, no, not by itself. The Committee concluded that using technical-support personnel to assist with computer-related issues does not violate MRPC 1.6(b), treating them like bookkeepers or data-processing professionals under ABA Informal Opinion 1364.

Q: What must the lawyer do before granting that access?

A: The opinion concludes the lawyer should clearly communicate the confidentiality obligations to the support staff under the reasonable-care requirement of MRPC 1.6(d).

Q: Is a written confidentiality acknowledgment required?

A: The opinion does not require one; it states it would be prudent to secure a written acknowledgment that the staff have been advised of the requirements and agree not to disclose the information.

Q: Does the analysis change for highly sensitive client information?

A: Yes. The opinion states the degree of confidentiality affects the degree of care required, and the lawyer must take necessary steps to keep particularly sensitive confidences outside the view of support personnel.

Background and rules framework

The opinion interprets MRPC 1.6(b) / Model Rule 1.6 (the duty not to reveal a client's confidences or secrets) and MRPC 1.6(d) / Model Rule 5.3 (the duty to exercise reasonable care so that nonlawyers whose services the lawyer uses do not disclose client information). It applies these to in-house government technical-support staff who service a shared network.

Citations and references

Rules of Professional Conduct:

  • MRPC 1.6(b) / Model Rule 1.6 (confidentiality of confidences and secrets)
  • MRPC 1.6(d) / Model Rule 5.3 (reasonable care to prevent disclosure by nonlawyer assistants)

Other opinions cited:

  • RI-77; RI-111; RI-311: prior Michigan opinions on disclosure of client information to third parties
  • ABA Informal Opinion 1364: access by bookkeepers, accountants, and data-processing professionals to a lawyer's records

See also

Source

Original opinion text

Reproduced from the official source for research purposes. The linked source is authoritative.

RI-328

January 25, 2002

SYLLABUS

A law department of a governmental unit may utilize the services of the technical support department of the governmental unit without violating the client confidentiality rules.

The law department of the governmental unit should clearly communicate the confidentiality rules to the technical support personnel.

References: MRPC 1.6(b) and (d); RI-77; RI-111; RI-311; ABA Informal Opinion 1364.

TEXT

A lawyer working for a local government law department helps maintain a local area network (LAN) containing confidential client information. Information contained in the computer's storage includes word processing, case management information and storage of other documents. The local government's technology department, not directly connected with the law department, provides the technical support of the LAN.

The lawyer asks the committee to opine on whether or not granting access to the governmental unit's LAN for technical support purposes violates the lawyer's duty of confidentiality as required by MRPC 1.6.

MRPC 1.6 (b) provides:

"Except when permitted under paragraph (c), a lawyer shall not knowingly:

(1) reveal a confidence or secret of a client; or

(2) use a confidence or secret of a client to the disadvantage of the client; or

(3) use a confidence or secret of a client for the advantage of the lawyer or of a third person, unless the client consents after full disclosure."

Further, MRPC 1.6(d) provides:

"A lawyer shall exercise reasonable care to prevent employees, associates, and others whose services are utilized by the lawyer from disclosing or using confidences or secrets of a client, except that a lawyer may reveal the information allowed by paragraph (c) through an employee."

The comment to MRPC 1.6 points out that a lawyer is impliedly authorized to make disclosures about a client when appropriate in carrying out the representation.

This committee has addressed confidentiality issues in many previous opinions. In RI-77, this committee opined that a law firm may not submit client names and addresses to the law firm's bank lender unless the client consents after consultation. Similarly, in RI-111, the committee offered the opinion that a lawyer may not disclose information learned during the course of representing multiple clients to medical regulatory authorities or to prosecutors without client consent.

Both RI-77 and RI-111 arose from facts that did not fit under any exception to the non-disclosure rule. However, in RI-311, this committee concluded that a legal services agency may report to the Legal Services Corporation the names and addresses of clients of that agency "when required to do so by law," since there is a federal law that requires that disclosure.

The confidentiality mandates of MRPC 1.6(b)(1) prohibit revealing confidences or secrets of the client. Under the facts presented to the committee, the technical support employees who service the legal department's LAN would have access to the client information, but would not be using that information in any way detrimental to the client.

In ABA Informal Opinion 1364, the American Bar Association concluded that it is not a violation of the confidentiality rules to allow bookkeepers, accountants or data processing professionals to have access to lawyers' records to assist the lawyer in the practice of law. Although this opinion was offered under the former Disciplinary Rules, the result is consistent with the current Model Rules of Professional Conduct.

In this matter, the technical support personnel of the local government unit are providing business assistance to the legal department, in the same way as accountants, bookkeepers or other data processing professionals perform services for lawyers. Therefore, consistent with ABA Informal Opinion 1364, this committee finds that the use of technical support personnel to assist a law department with computer-related issues does not in itself violate the mandates of MRPC 1.6(b).

Pursuant to the "reasonable care" requirement of MRPC 1.6(d), the legal department of the local governmental unit should clearly communicate the confidentiality mandates to the technical support personnel. It would be prudent for the lawyer giving that notification to secure a written acknowledgement from the technical support personnel that they have been advised of the confidentiality requirements and that they agree not to disclose confidential information learned as a result of their access to the data. The degree of confidentiality that attaches to the information affects the degree of care the lawyer needs to exercise to protect it. The lawyer must take all necessary steps to assure that particularly sensitive client confidences be maintained outside of the view of technical support personnel.

This opinion assumes there is no reason to believe that individuals obtaining access to the information have any specific interest in the substance of the information obtained. It also assumes that counsel has no reason to expect that any particular individuals with access to the confidential information have any likelihood of using this information to the disadvantage of the client as prohibited by MRPC 1.6(b).

Get today's answer for your situation

You just read a 2002 opinion on this question. Ezel checks the current Michigan Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.