ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

ABA Opinion 477R and Email: When Standard Security Is Not Enough

ABA Formal Opinion 477R discusses securing client communications. Learn its fact-based approach and when email may call for additional safeguards.

3 min readBy Counsel Cyber Team

Email is how lawyers communicate, and most clients are comfortable with it. For decades the working assumption has been that unencrypted email is generally acceptable for routine matters. ABA Formal Opinion 477R, "Securing Communication of Protected Client Information," revised in 2017, takes a more nuanced position: the duty to make reasonable efforts to protect client information is fact-specific, and the right level of protection depends on circumstances.

This post summarizes the opinion in general terms and translates the idea into steps a firm can take. It is not legal advice, and your state may have its own opinions. Confirm with your bar.

The central idea: reasonable efforts

Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Opinion 477R explains that determining what is reasonable involves a risk-based analysis. In broad terms, it points to factors such as:

  • The sensitivity of the information.
  • The likelihood of disclosure if additional safeguards are not employed.
  • The cost of employing additional safeguards.
  • The difficulty of implementing the safeguards.
  • The extent to which the safeguards adversely affect the lawyer's ability to represent clients.

The opinion also discusses understanding the nature of the threat, understanding how client confidential information is transmitted and stored, using reasonable electronic security measures, determining how electronic communications about client matters should be protected, labeling confidential communications, training lawyers and nonlawyer assistants, and conducting due diligence on vendors.

"Standard" email is not one thing

When people say email, they may mean very different setups. A message sent from a well-configured, MFA-protected, filtered Microsoft 365 account to a client using a modern provider is quite different from a message sent from a personal webmail account over hotel Wi-Fi, to a recipient whose mailbox is shared with an employer's IT staff.

Because risks differ, the opinion suggests that a one-size-fits-all rule is not adequate.

When more may be called for

Opinion 477R notes circumstances in which a lawyer may need to take special security precautions, such as when the client requests it, when the information is unusually sensitive, or when there is a heightened risk, for example, a client whose email may be accessible to others. Practical examples a firm might consider include:

  • Highly sensitive deal or litigation strategy documents.
  • Medical, financial or immigration records.
  • Matters involving high-profile or hostile opponents.
  • Clients using employer-owned accounts or shared devices, for example in some employment or family law matters.
  • Documents containing government identification numbers or bank account details.

For these, consider a secure client portal, encrypted email or password-protected attachments with the password given by phone.

Controls that make ordinary email more defensible

  1. Enforce MFA on every mailbox.
  2. Use transport encryption so messages are encrypted between mail servers whenever the receiving system supports it. Most major providers do.
  3. Filter inbound and outbound mail for phishing and malware.
  4. Use confidentiality labels in subject lines or footers where appropriate.
  5. Check recipients carefully. Misdirected email is a common cause of disclosure. Enable warnings for external recipients and consider delaying send by a few seconds.
  6. Limit auto-complete risks by cleaning stale contacts.
  7. Control mobile access with passcodes and the ability to wipe.

Discuss it with clients

The opinion's approach fits naturally with Model Rule 1.4's emphasis on communication. At intake, explain how the firm communicates, what tools are used and invite clients to say if they have special needs or risks. Capture preferences in the engagement letter, for instance a request not to email a work address.

Train the people

Opinion 477R recognizes training as part of reasonable efforts. Short, regular training on addressing, attachments, phishing and secure sharing is generally more effective than a single long session.

Document your approach

Write a short email and communications policy: when standard email is acceptable, when to use the portal, how to handle attachments, how to deal with client requests for less secure channels and who to ask. A one-page policy applied consistently shows thoughtfulness.

Reassess as threats change

The opinion stresses that reasonable efforts change as technology and threats do. Review the policy annually and after any incident.

How Counsel Cyber can help

Counsel Cyber helps law firms configure secure email, client portals and encryption options that attorneys will actually use. If you would like to review your current communications practices, we are glad to start with a conversation.