ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

ABA Formal Opinion 477R: When Email Is Enough and When It Is Not

A plain-English look at ABA Formal Opinion 477R on securing client communications, including the reasonable-efforts factors and when extra safeguards may fit.

3 min readBy Counsel Cyber Team

Few lawyers today would send a settlement offer by postal mail when a quick email would do. The question the ABA asked in Formal Opinion 477R, titled in substance "Securing Communication of Protected Client Information," is what lawyers must do to keep electronic communications confidential. The opinion was first issued in 2017 and revised in 2018.

This post summarizes its main ideas in general terms. It is not legal advice, and state bars may have their own opinions, so check with yours.

The starting point: Rule 1.6(c)

Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Opinion 477R explains how that duty applies to technology-based communication. It notes that the rule is not a guarantee of perfect security. It calls for reasonable efforts, judged by circumstances.

The factors for reasonableness

The opinion points to factors that comment to the Model Rules identify, including:

  1. The sensitivity of the information.
  2. The likelihood of disclosure if additional safeguards are not employed.
  3. The cost of employing additional safeguards.
  4. The difficulty of implementing the safeguards.
  5. The extent to which the safeguards adversely affect the lawyer's ability to represent clients, for example by making a device or software excessively difficult to use.

Taken together, these suggest a sliding scale. A routine scheduling email carries a different risk than a document containing health records, trade secrets or details of an acquisition.

The ordinary case: standard email

The opinion recognizes that, for many matters, using ordinary email with appropriate precautions can be reasonable. It also notes that the analysis is fact-specific and changes over time as technology and threats change. "Appropriate precautions" in a modern firm typically include:

  • MFA and strong passwords on email accounts.
  • Encryption in transit, which most modern email systems support.
  • Device security: encryption, screen locks and prompt updates.
  • Care with recipients, such as checking addresses and avoiding "reply all" mistakes.
  • Cautious use of public Wi-Fi and unsecured networks.

When more may be called for

The opinion discusses circumstances where a lawyer may need to take special security precautions, such as a client requiring them, or information so sensitive that ordinary email would not be reasonable. Examples to consider with your attorneys include:

Highly sensitive matters

Merger negotiations, health information, intellectual property, criminal defense strategy and certain family law matters might justify stronger measures, such as encrypted email, secure client portals or file transfer links with expiration and access controls.

Client instructions

If a client asks for particular methods or restricts others in an engagement letter or outside counsel guidelines, follow them and document them.

Known risk

If you have reason to believe a client's email account is compromised, shared with others, or monitored, such as a spouse accessing a shared account or an employer reading a work email, using that channel may be unwise. The opinion discusses attention to employer or shared devices in this respect.

Practical safeguards by communication type

  • Email attachments: use a portal or secure link for sensitive documents, and set expiration.
  • Text messaging and messaging apps: decide which, if any, are approved, and retain records according to policy.
  • Video conferences: use waiting rooms, unique meeting links and updated software.
  • Cloud file sharing: limit access to specific people, avoid anyone-links and review sharing regularly.
  • Mobile devices: require passcodes, encryption and remote wipe capability.

Understanding clients

The opinion encourages lawyers to understand the nature of the threat and how client information is stored and sent, and to use a reasonable electronic security measure, understand how those measures work or consult someone who does, label client information as privileged and confidential, train lawyers and nonlawyers in technology and information security, and conduct due diligence on vendors. Those themes track well with a practical firm program.

Turning the opinion into a firm practice

  1. Classify information. Define a simple tier system and the communication methods allowed for each.
  2. Offer a default secure option. A client portal makes the right way the easy way.
  3. Document client preferences. Capture them at intake.
  4. Train staff. Include examples of misdirected email and fake sign-in pages.
  5. Review annually. Threats and tools evolve.

Where Counsel Cyber fits

We help law firms choose and configure secure communication tools, set classification rules and train staff. If you would like to review how your attorneys currently share sensitive files with clients, we can help you identify low-friction improvements.