Does a Pennsylvania lawyer have to encrypt email to clients?
Apply this to your situation
This page answers the general question as of 2022. Ezel answers yours: whether it's allowed on your facts, under the current Pennsylvania Rules of Professional Conduct, with citations.
Plain-English summary
The opinion revisits earlier guidance permitting lawyers to use email. It observes that "while prior ethical guidance has concluded that attorneys may use email to transmit this type of information, those opinions do not always address the fact that email, absent the use of other electronic protections such as encryption, may be neither private nor secure." It concludes that "given the changes in technology and the rise of cyberattacks, this Formal Opinion concludes that the Rules of Professional Conduct require more."
The opinion reassesses the ABA's 1999 view in Formal Opinion 99-413, which treated email as posing no greater interception risk than other media. The Committee concludes "the guidance in Formal Opinion 99-413 is no longer valid" and instead endorses ABA Formal Opinion 477R, which recognizes that lawyers must make reasonable efforts to prevent inadvertent or unauthorized access and may need special precautions depending on the circumstances. It grounds the obligations in Rule 1.1 (competence, including understanding the benefits and risks of technology), Rule 1.4 (communication and reasonable consultation about means), and Rule 1.6(d) (reasonable efforts to prevent inadvertent or unauthorized disclosure). Citing Comments [25] and [26] to Rule 1.6, the opinion measures reasonableness by factors such as the sensitivity of the information, the likelihood of disclosure, and the cost and difficulty of safeguards.
The opinion sets conditions on email use. It states that "an attorney communicating through email is under the same obligations to maintain client confidentiality as is the attorney communicating by more traditional means," and that certain information "should never be sent by email" without additional security precautions such as a password or encryption, including information for which the client has requested maximum security. It also invokes Rules 5.1 and 5.3 to require supervisory lawyers to ensure that other lawyers and nonlawyers handling confidential information comply with these obligations.
In practice
Under this opinion, a Pennsylvania lawyer may keep using email but must assess its security risks under the Rule 1.6(d) reasonable-efforts standard, decide when competence under Rule 1.1 calls for encryption or secure file-sharing, and refrain from emailing certain highly sensitive information without a password or encryption. The opinion holds that the lawyer must advise clients of email's risks and consult them about how to communicate, and that supervisory lawyers must ensure others in the firm comply.
Common questions
Q: Do I have to encrypt all email to clients?
A: No. The opinion does not require encryption for all email, but concludes the Rules "require more" than they once did and that competence may require encryption or secure file-sharing for specific communications.
Q: Is there information I should not email at all?
A: Yes. The opinion concludes certain information "should never be sent by email" without additional precautions such as a password or encryption, including information for which the client has requested maximum security.
Q: Do I need to talk to clients about email risk?
A: Yes. The opinion concludes that under Rule 1.4 lawyers must advise clients of email's risks and consult them about whether and how to communicate by email.
Q: Is the old guidance that email is as safe as a phone call still good?
A: No. The opinion concludes the guidance in ABA Formal Opinion 99-413 "is no longer valid" given changes in technology and the rise of cyberattacks, and endorses ABA Formal Opinion 477R instead.
Background and rules framework
The opinion interprets Pennsylvania Rule of Professional Conduct 1.6 (confidentiality, including 1.6(d) and Comments [25]-[26]), Rule 1.1 (competence, including Comment [8]), and Rule 1.4 (communication), together with Rules 5.1 and 5.3 (supervision). These track ABA Model Rules of the same numbers, and the opinion builds on ABA Formal Opinion 477R.
Citations and references
Rules of Professional Conduct:
- Pa.R.P.C. 1.6, including 1.6(d) and Comments [25]-[26]; ABA Model Rule 1.6
- Pa.R.P.C. 1.1, 1.4; ABA Model Rules 1.1, 1.4
- Pa.R.P.C. 5.1, 5.3; ABA Model Rules 5.1, 5.3
Other opinions cited:
- ABA Formal Op. 477R: securing electronic client communication
- ABA Formal Op. 99-413: email and the expectation of privacy (treated as no longer valid)
- PBA Formal Op. 2011-200: cloud computing confidentiality
See also
- ABA Formal Op. 477R: Securing Communication of Protected Client Information
- PA Bar Ethics Op. 2022-500: Storing Client Information on a Smartphone
- PA Bar Ethics Op. 2024-100: Third-Party Vendors With Access to Confidential Information
Source
- Landing page: PBA Ethics Opinions (Public)
- Original PDF: F2022-400.pdf
Get today's answer for your situation
You just read a 2022 opinion on this question. Ezel checks the current Pennsylvania Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.