If an insurer's automated software (no human reviewer) processes a defense firm's legal bills, does the firm need the insured's consent under the confidentiality rule?
Apply this to your situation
This page answers the general question as of 2002. Ezel answers yours: whether it's allowed on your facts, under the current South Carolina Rules of Professional Conduct, with citations.
Plain-English summary
A firm whose practice was concentrated in insurance-defense litigation (representing insureds on behalf of an insurer) described the insurer's use of an independent software provider to process the firm's invoices. The software aggregated billing data, transmitted it to the insurer, paid law firms and vendors promptly, and supplied the insurer with analyses of representation expenses, all programmatically and without human intervention. The firm asked whether running its legal bills through such a program, with no human reviewer, breached the duty of confidentiality to the insured under Rule 1.6.
The committee concluded it would, absent consent. It relied on two prior opinions: Opinion 97-22 held that sending legal bills to an outside auditor who recommends payment does not violate the rules only if there is fully informed consent by both the insurer and the insured, and Opinion 98-36 clarified that the firm must still obtain the insured's consent even if the bills state that the information is, in the lawyer's professional judgment, confidential or privileged. Together, those opinions required the insured's informed consent any time an insurer submits legal bills to an auditor, even with confidential information redacted.
The committee found the automated scenario factually different only in that no person reviews the bills, which are programmatically sorted, paid, and reported to the insurer. Even so, confidential client information would be revealed to a nonclient and could be accessed, so consent of the insured and the insurer was still required. The committee added that a prudent lawyer will recognize that any information, however automated the process, can be accessed by knowledgeable programmers.
In practice
The opinion holds that, under the South Carolina rule as it stood at the time, the automation of an insurer's bill-auditing process does not remove the Rule 1.6 confidentiality concern: because confidential client information is disclosed to a nonclient (the software provider) and can be accessed, the defense firm must obtain the informed consent of both the insured and the insurer before transmitting the bills, consistent with Opinions 97-22 and 98-36. The committee observed that any information, no matter how automated the handling, can be reached by knowledgeable programmers. South Carolina revised its Rules of Professional Conduct effective 2005; verify the current text of Rule 1.6 before relying on the specific requirement here.
Common questions
Q: Does using automated software instead of a human auditor avoid the confidentiality problem?
A: The committee concluded no: even with no human intervention, confidential client information is revealed to a nonclient and could be accessed, so Rule 1.6 still requires consent.
Q: Whose consent does the defense firm need?
A: The committee concluded the firm needs the informed consent of both the insured and the insurance company before the bills are submitted, consistent with Opinions 97-22 and 98-36.
Q: Does redacting confidential information from the bills remove the consent requirement?
A: The committee concluded no: under Opinions 97-22 and 98-36, the lawyer must obtain the insured's consent any time bills go to an auditor, even if confidential information has been redacted.
Background and rules framework
The opinion interpreted South Carolina RPC 1.6 (confidentiality of information relating to the representation), corresponding to Model Rule 1.6, in the insurance-defense tripartite setting where the insurer pays for representation of the insured. It built directly on the committee's Opinions 97-22 (outside bill auditors) and 98-36 (consent required despite confidentiality legends).
Citations and references
Rules of Professional Conduct:
- South Carolina RPC 1.6 / Model Rule 1.6: confidentiality of information relating to the representation.
Other opinions cited:
- S.C. Bar Ethics Advisory Op. 97-22 (outside bill auditor permissible only with informed consent of insurer and insured).
- S.C. Bar Ethics Advisory Op. 98-36 (insured's consent required despite a confidentiality legend on the bills).
See also
- Alabama Op. 1998-02: Third-Party Auditing of Lawyer Billings
- ABA Formal Op. 01-421: Lawyer Under Insurance Company Guidelines
- SC Bar Ethics Op. 10-08: Billing a Contract Attorney
Source
- Landing page: https://www.scbar.org/for-lawyers/quicklinks/legal-resources/ethics-advisory-opinions/ethics-advisory-opinion-02-01/
Original opinion text
Reproduced from the official source for research purposes. The linked source is authoritative.
UPON THE REQUEST OF A MEMBER OF THE SOUTH CAROLINA BAR, THE ETHICS ADVISORY COMMITTEE HAS RENDERED THIS OPINION ON THE ETHICAL PROPRIETY OF THE INQUIRER’S CONTEMPLATED CONDUCT. THIS COMMITTEE HAS NO DISCIPLINARY AUTHORITY. LAWYER DISCIPLINE IS ADMINISTERED SOLELY BY THE SOUTH CAROLINA SUPREME COURT THROUGH ITS COMMISSION ON LAWYER CONDUCT.
Ethics Advisory Opinion 02-01
Law Firm's practice is concentrated in insurance defense litigation, representing insured persons on behalf of an insurance company. The insurance company utilizes the services of an independent software provider to aid in payment of Law Firm's invoices. The software provider aggregates billing data and transmits it to the insurance company, provides prompt payment to law firms and other vendors, and supplies the insurance company with analyses of the financial data regarding the expenses of representation. These services all occur programmatically and without any human intervention. According to the insurance company, the software is helpful in allowing the insurance company to approve payments promptly. This situation is similar that of Ethics Advisory Opinion 97-22, except for the fact that the third party auditor in this situation is not a person but is essentially a computer program which automatically compiles and disseminates information to the insurance company.
QUESTION
If an independent software provider examines the legal bills of an insurance company, through a computer program with no human intervention, has there been a breach of confidentiality regarding the third party insured under Rule 1.6 of the Rules of Professional Conduct?
OPINION
Although the process described in the question involves the use of an automated software program, confidential client information would be revealed to a nonclient and could be accessed. Based on opinions 97-22 and 98-36 the attorney may not reveal this information without the consent of the insured and the insurance company.
DISCUSSION
There are two previous South Carolina Ethics Advisory Opinions dealing with similar issues.
Opinion 97-22 concerned an insurance company which sent its legal bills to an outside auditor who would then recommend payment or nonpayment of the bills. The opinion concluded that this would not violate the Rules of Professional Conduct as long as there is fully informed consent by the insurance company and the insured (emphasis added). Under the particular facts in Opinion 97-22, an independent auditor was hired to examine the law firm's bills, which necessarily required the auditor to review confidential client information.
Opinion 98-36 dealt with the same topic but clarified that the law firm would still need to obtain the consent of the insured even if the firm stated on the bills that the information, in the lawyer's professional judgment, was confidential or privileged.
These two opinions take the position that any time an insurance company submits its legal bills to an auditor, even if confidential information has been redacted from the bills, the lawyer must obtain the informed consent of the insured.
The instant situation is factually different from the situation in Opinion 97-22, in that there are no persons reviewing the bills, as the bills are merely programmatically sorted, paid, and that information transmitted to the insurance company. Presumably, there is no reason why persons other than employees of the insurance company should ever see the bills. The prudent lawyer will recognize that any information, no matter how automated, can be accessed by knowledgeable programmers.
Get today's answer for your situation
You just read a 2002 opinion on this question. Ezel checks the current South Carolina Rules of Professional Conduct and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the rules it relies on.