Can a law firm let its lawyers access client files remotely so they can work from home?
Apply this to your situation
This page answers the general question as of 2014. Ezel answers yours: whether it's allowed on your facts, under the current New York Rules of Professional Conduct, with citations.
Plain-English summary
The committee was asked whether a law firm may provide its lawyers with remote access to its electronic files so they can work from home. It treated the question, like its other technology opinions, as turning on the duty to preserve client confidentiality (¶¶ 1-3).
The committee laid out the framework. Rule 1.6(a) bars knowing disclosure of confidential information absent the client's informed consent, and Rule 1.6(c) requires the lawyer to exercise reasonable care to prevent others whose services the lawyer uses from disclosing it. Comment 17 to Rule 1.6 provides that the lawyer must take reasonable precautions but need not use special security measures where the method affords a reasonable expectation of privacy, with special circumstances warranting special precautions. The key is whether the lawyer has determined that the technology affords reasonable protection and has taken reasonable precautions in using it (¶¶ 3-5).
The committee traced the evolution of its opinions. Earlier opinions had reached general conclusions (for example, that unencrypted email ordinarily affords a reasonable expectation of privacy, N.Y. State 709), but more recent opinions place the reasonableness determination squarely on the inquiring lawyer. N.Y. State 842 (cloud storage) listed steps that "reasonable care" may include, such as ensuring an enforceable confidentiality obligation from the provider, investigating its security measures, employing technology to guard against infiltration, and confirming the provider's ability to purge data, and suggested periodic reconfirmation and discontinuation if security proved inadequate (¶¶ 6-8).
Noting that cyber-criminals increasingly target law firms, especially where third parties have outside access, the committee concluded it is even more important for a firm to determine that its remote-access technology and devices provide reasonable assurance of protection. Given the fact-specific and evolving nature of the risks, it declined to prescribe particular steps. Where the firm makes a reasonableness determination, client consent is unnecessary; where it cannot, it may request the client's informed consent, but only after disclosing the risk that the system does not reasonably assure confidentiality, so the consent is "informed" within Rule 1.0(j) (¶¶ 9-12).
In practice
Under the New York rules as they stood at the time of the opinion, the opinion holds that a firm may provide remote access to client files if it takes reasonable steps to maintain confidentiality, and that when the firm can make that reasonableness determination, client consent is not required. Per the opinion, where the firm cannot conclude its precautions are reasonable, it may proceed only with the client's informed consent after disclosing the confidentiality risk. The committee declined to specify particular technical safeguards (such as the degree of password protection, device security, or whether encryption is required), citing the fact-specific and evolving nature of technology and cyber risks.
Common questions
Q: Can a firm let lawyers work from home with remote access to client files?
A: Yes, as long as the firm takes reasonable steps to ensure confidentiality is maintained (¶ 12).
Q: Does the firm have to get client consent first?
A: Not if the firm can determine that its precautions reasonably protect confidential information; in that case the committee said consent is not necessary (¶ 10).
Q: What if the firm cannot be confident the system is secure?
A: Then it may request the client's informed consent, after disclosing the risk that the system does not reasonably assure confidentiality, so the consent is "informed" under Rule 1.0(j) (¶ 11).
Q: Did the committee specify the required security measures?
A: No. Because of the evolving nature of technology and cyber risks, the committee declined to recommend particular steps (¶¶ 10, 12).
Background and rules framework
The opinion interprets New York Rule 1.6 (confidentiality, including 1.6(c) and the informed-consent exception under 1.0(j)) and references Rule 1.1 (competence) and Rule 1.15(d) (recordkeeping), corresponding to ABA Model Rules 1.6, 1.1, and 1.15. The analysis turns on whether the firm has determined that its remote-access technology affords reasonable protection against disclosure.
Citations and references
Rules of Professional Conduct:
- MR 1.6 / NY RPC 1.6, 1.6(c) (confidentiality; reasonable care; Cmt. 17)
- NY RPC 1.0(j) (informed consent)
- MR 1.1 / NY RPC 1.1 (competence); NY RPC 1.15(d) (recordkeeping)
Other opinions cited:
- N.Y. State 842 (2010): cloud storage; reasonable-care steps
- N.Y. State 709 (1998): reasonable expectation of privacy in email
- N.Y. State 940 (2012); N.Y. State 950 (2012): off-site backups; electronic email storage
See also
- NY State Bar Op. 1020: Cloud storage for sharing transaction documents
- NY State Bar Op. 1077: Scanning and destroying original retainer agreements
- NY State Bar Op. 1102: Insurance in-house counsel office confidentiality
Source
- Landing page: https://nysba.org/ethics-opinion-1019/
Get today's answer for your situation
You just read a 2014 opinion on this question. Ezel checks the current New York Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.