PBA 2022

Does a Pennsylvania lawyer have to encrypt email to clients?

Short answer: Not always, but more than before. The opinion concludes lawyers may still use email but must evaluate its security risks, that some highly sensitive information should not be sent by email without precautions like a password or encryption, and that lawyers must advise clients of the risks.

Apply this to your situation

This page answers the general question as of 2022. Ezel answers yours: whether it's allowed on your facts, under the current Pennsylvania Rules of Professional Conduct, with citations.

Disclaimer: Advisory only. Not binding precedent.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official ethics opinion. The original opinion (linked on this page as a PDF) is the authoritative source for any reliance.
View original ethics opinion (PDF)

Plain-English summary

The opinion revisits earlier guidance permitting lawyers to use email. It observes that "while prior ethical guidance has concluded that attorneys may use email to transmit this type of information, those opinions do not always address the fact that email, absent the use of other electronic protections such as encryption, may be neither private nor secure." It concludes that "given the changes in technology and the rise of cyberattacks, this Formal Opinion concludes that the Rules of Professional Conduct require more."

The opinion reassesses the ABA's 1999 view in Formal Opinion 99-413, which treated email as posing no greater interception risk than other media. The Committee concludes "the guidance in Formal Opinion 99-413 is no longer valid" and instead endorses ABA Formal Opinion 477R, which recognizes that lawyers must make reasonable efforts to prevent inadvertent or unauthorized access and may need special precautions depending on the circumstances. It grounds the obligations in Rule 1.1 (competence, including understanding the benefits and risks of technology), Rule 1.4 (communication and reasonable consultation about means), and Rule 1.6(d) (reasonable efforts to prevent inadvertent or unauthorized disclosure). Citing Comments [25] and [26] to Rule 1.6, the opinion measures reasonableness by factors such as the sensitivity of the information, the likelihood of disclosure, and the cost and difficulty of safeguards.

The opinion sets conditions on email use. It states that "an attorney communicating through email is under the same obligations to maintain client confidentiality as is the attorney communicating by more traditional means," and that certain information "should never be sent by email" without additional security precautions such as a password or encryption, including information for which the client has requested maximum security. It also invokes Rules 5.1 and 5.3 to require supervisory lawyers to ensure that other lawyers and nonlawyers handling confidential information comply with these obligations.

In practice

Under this opinion, a Pennsylvania lawyer may keep using email but must assess its security risks under the Rule 1.6(d) reasonable-efforts standard, decide when competence under Rule 1.1 calls for encryption or secure file-sharing, and refrain from emailing certain highly sensitive information without a password or encryption. The opinion holds that the lawyer must advise clients of email's risks and consult them about how to communicate, and that supervisory lawyers must ensure others in the firm comply.

Common questions

Q: Do I have to encrypt all email to clients?

A: No. The opinion does not require encryption for all email, but concludes the Rules "require more" than they once did and that competence may require encryption or secure file-sharing for specific communications.

Q: Is there information I should not email at all?

A: Yes. The opinion concludes certain information "should never be sent by email" without additional precautions such as a password or encryption, including information for which the client has requested maximum security.

Q: Do I need to talk to clients about email risk?

A: Yes. The opinion concludes that under Rule 1.4 lawyers must advise clients of email's risks and consult them about whether and how to communicate by email.

Q: Is the old guidance that email is as safe as a phone call still good?

A: No. The opinion concludes the guidance in ABA Formal Opinion 99-413 "is no longer valid" given changes in technology and the rise of cyberattacks, and endorses ABA Formal Opinion 477R instead.

Background and rules framework

The opinion interprets Pennsylvania Rule of Professional Conduct 1.6 (confidentiality, including 1.6(d) and Comments [25]-[26]), Rule 1.1 (competence, including Comment [8]), and Rule 1.4 (communication), together with Rules 5.1 and 5.3 (supervision). These track ABA Model Rules of the same numbers, and the opinion builds on ABA Formal Opinion 477R.

Citations and references

Rules of Professional Conduct:

  • Pa.R.P.C. 1.6, including 1.6(d) and Comments [25]-[26]; ABA Model Rule 1.6
  • Pa.R.P.C. 1.1, 1.4; ABA Model Rules 1.1, 1.4
  • Pa.R.P.C. 5.1, 5.3; ABA Model Rules 5.1, 5.3

Other opinions cited:

  • ABA Formal Op. 477R: securing electronic client communication
  • ABA Formal Op. 99-413: email and the expectation of privacy (treated as no longer valid)
  • PBA Formal Op. 2011-200: cloud computing confidentiality

See also

Source

Get today's answer for your situation

You just read a 2022 opinion on this question. Ezel checks the current Pennsylvania Rules of Professional Conduct and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the rules it relies on.