Can a lawyer deliver or manage client files through a password-protected website instead of on paper?
Apply this to your situation
This page answers the general question as of 2008. Ezel answers yours: whether it's allowed on your facts, under the current North Carolina Rules of Professional Conduct, with citations.
Plain-English summary
The opinion addresses two ways lawyers want to manage client records online. The first is a real estate lawyer who wants to upload closing documents to a secure website and email each client a link and password to download and print them, rather than mailing paper, while still offering paper copies on request.
The opinion concludes this is permitted. Rule 1.16(d) requires a lawyer to surrender papers and property the client is entitled to when the representation ends, and Comment [10] entitles the client to anything in the file helpful to successor counsel, but the file need not be turned over on paper. Citing RPC 234, which allows storing client files electronically, the opinion concludes that with the client's consent the file may be delivered on a disk or by emailing a password-protected download link. The lawyer must protect the confidentiality and security of each file (Rules 1.6 and 1.15) by ensuring each client can reach only his or her own file and that third parties cannot reach any client file.
The second inquiry is a patent lawyer who wants a web-based docketing system giving both the firm and corporate clients online access, where the firm's system holds the docket information for all of its patent clients. The opinion concludes such a shared system is permissible only if the lawyer can protect the confidential information of all clients. The lawyer must take steps to minimize the risk of disclosing one client's confidential information to another client or to third parties (RPC 133, RPC 215). Importantly, the opinion concludes a client's contractual agreement (or its in-house counsel's agreement) not to view another client's information does not cure the risk; a security-code access procedure that lets each client reach only its own information is an appropriate safeguard. If the firm contracts with a third party to run the system, the firm must ensure that vendor also uses measures that effectively minimize the risk of loss or disclosure (RPC 133).
In practice
Under the North Carolina rules as they stood at the time of the opinion, a lawyer may move client-file delivery and management online, including password-protected download links and web-based docketing portals, provided the system protects the confidentiality and security of each client's file (Rules 1.6 and 1.15). Per the opinion, the analysis turns on access controls: each client must be able to reach only its own information, and third parties must be excluded.
Per the opinion, a promise by one client not to view another client's data is not an adequate safeguard for a shared system; a per-client security-code access procedure is. Where a third-party vendor maintains the system, the lawyer must ensure the vendor also employs measures that effectively minimize the risk that confidential information is lost or disclosed.
Common questions
Q: Can a lawyer email clients a download link to their closing documents instead of mailing paper?
A: Yes, with consent and security. The opinion concludes that, with the client's consent, the file may be delivered by emailing a password-protected download link rather than on paper, as long as confidentiality and security are protected (Rules 1.16(d), 1.6, 1.15).
Q: Can a firm give corporate clients online access to a shared docketing system?
A: Yes, if other clients' data is walled off. The opinion concludes a web-based system giving clients access to their own docket is permissible only if the lawyer can protect the confidential information of all clients and minimize the risk of disclosure to other clients or third parties (RPC 133, RPC 215).
Q: Is it enough to have the client agree not to look at other clients' information?
A: No. The opinion concludes that an agreement by a client or its in-house counsel not to view another client's confidential information does not cure the risk; a security-code access procedure that limits each client to its own information is required.
Q: What if a third-party vendor hosts the system?
A: The firm must vet the vendor's safeguards. The opinion concludes that when the firm contracts with a third party to maintain the system, the firm must ensure the vendor also employs measures that effectively minimize the risk that confidential information is lost or disclosed (RPC 133).
Background and rules framework
The opinion applies North Carolina Rule 1.16(d) (surrender of the client's papers and property at the end of the representation), Rule 1.6 (confidentiality of information), and Rule 1.15 (safekeeping of client property), the analogues of Model Rules 1.16, 1.6, and 1.15. It builds on earlier North Carolina ethics decisions allowing electronic file storage and requiring lawyers to minimize the risk of disclosure when client information is held in a shared system (RPC 234, RPC 133, RPC 215).
Citations and references
Rules of Professional Conduct:
- MR 1.16 / NC Rule 1.16(d), Comment [10] (surrender of file at end of representation)
- MR 1.6 / NC Rule 1.6 (confidentiality of information)
- MR 1.15 / NC Rule 1.15 (safekeeping client property)
Other opinions cited:
- NC RPC 234: client files may be stored in electronic format.
- NC RPC 133: a lawyer must minimize the risk of disclosing confidential information held in a shared system, including by a third-party vendor.
- NC RPC 215: protecting confidential client information from access by other clients.
See also
- NC 2011 FEO 6: Software as a Service and Client Confidentiality
- ABA Formal Op. 498: Virtual Practice
- ABA Formal Op. 95-398: Nonlawyer Access to a Lawyer's Database
- ABA Formal Op. 471: Surrender of Papers and Property to a Former Client
Source
- Landing page: https://www.ncbar.gov/for-lawyers/ethics-and-governing-rules/ethics-opinions/opinions/2008-formal-ethics-opinion-5/
Original opinion text
Reproduced from the official source for research purposes. The linked source is authoritative.
Inquiry #1:
Rather than provide clients with hard copies of real estate closing documents, a lawyer would like to upload the files to a secure website and then email a link to his clients with a password so that they can download their files and print them if desired. The lawyer would offer his clients the option of receiving a hard copy of the closing documents rather than access to the website.
Does such a practice comply with the lawyer's responsibilities under the Rules of Professional Conduct?
Opinion #1:
Rule 1.16(d) provides that a lawyer must surrender papers and property to which the client is entitled upon the termination of the representation. Comment [10] to the rule adds that the client it entitled to anything in the file that would be helpful to successor counsel. However, the file documents do not have to be turned over in a paper format. RPC 234 allows lawyers to store client files in an electronic format. With the client's consent, the client's file may be turned over to the client in the form of a computer disk or by emailing a link to the client with a password so that the client can download the files from a website.
If the law firm chooses to use a system that allows clients to access and download their own files at the end of the representation, the confidentiality and security of each client's file must be protected. See Rules 1.6 and 1.15. Therefore, the law firm must enact appropriate measures to ensure that each client only has access to his or her own file. In addition, the law firm must ensure that third parties cannot gain access any client file.
Inquiry #2:
A patent lawyer would like to use a web-based management system that allows both the law firm and corporate clients access to a web-based docketing system. A large part of the lawyer's patent practice is the maintenance of patent dockets. The law firm currently has a docketing system that could be made available to clients via online access. However, the information for all patent clients of the firm is available on the system.
May the patent lawyer protect the confidential information of other clients by contractually obligating the in-house lawyer for a corporate client to view only information specific to his employer? Would the use of a web-based management system be acceptable if the law firm installed a security code access system that allows access only to the specific client's docket information?
Opinion #2:
The use of a web-based management system that allows both the law firm and the client access to the client's docketing information or other information in the client's file is permissible provided the lawyer can fulfill his obligation to protect the confidential information of all clients. A lawyer must take steps to minimize the risk that confidential client information will be disclosed to other clients or to third parties. See RPC 133 and RPC 215. It is not acceptable for one client to have access to another client's information absent client consent. This risk is not cured by an agreement from a client or a client's in-house counsel not to view the confidential information of another client. A security code access procedure that only allows a client to access its own confidential information would be an appropriate measure to protect confidential client information.
If the law firm will be contracting with a third party to maintain the web-based management system, the law firm must ensure that the third party also employs measures which effectively minimize the risk that confidential information might be lost or disclosed. See RPC 133.
Get today's answer for your situation
You just read a 2008 opinion on this question. Ezel checks the current North Carolina Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.