Prospective clients now expect to fill out a form on their phone, sign an engagement letter electronically and pay online. Automating intake can reduce phone tag and speed up conflict checks. It also creates a new place where sensitive information gathers: website forms, scheduling tools, email inboxes and the practice management system.
A thoughtful design lets the firm capture what it needs while limiting what it holds and who can see it. This post walks through the decisions to make before you turn on automation.
Decide what you really need at first contact
Collect only what you need for conflict checking and an initial assessment: name, contact information, adverse parties and a brief description. Ask for detailed facts, identification documents and medical or financial details after you have decided to proceed, and use a secure channel for them. The less sensitive information in an early form, the less exposure if something goes wrong.
Warn people about the form
Prospective clients are owed some protection under Model Rule 1.18, which addresses duties to prospective clients. Add a short notice that submitting a form does not create an attorney-client relationship and that people should not include confidential details until an engagement is in place. Have an attorney review the wording and consult your state rules.
Choose tools with a security review
Intake commonly involves several tools: a website form builder, a scheduling app, a chat widget, an e-signature service, a payment processor and your practice management system. For each:
- Where is submitted data stored, and for how long?
- Is data encrypted in transit and at rest?
- Who at the vendor can access it?
- Does it support MFA and role-based access for your staff?
- What integrations does it have, and what do they receive?
Treat these vendors the same way you would treat any other provider handling client information, consistent with the supervision duties in Rule 5.3.
Secure the form itself
- Serve the form over HTTPS and keep the website platform patched.
- Use spam and bot protection that does not require sending data to unknown third parties.
- Avoid emailing form submissions in plain text. Send a notification with a link to view the entry in a protected system instead.
- Do not store submissions indefinitely in the website administration area, where many people may have access.
- Limit website administrator accounts and require MFA.
Control where submissions land
Route intake data directly into your practice management system or a restricted intake mailbox with a short list of authorized users. Avoid forwarding to personal inboxes or to a shared mailbox everyone can read. Set permissions so that only people working on intake and conflict checks see new entries.
Handle conflict checks carefully
Conflict checking uses information about adverse parties and other individuals who have not agreed to anything. Keep that data in the matter system with proper access controls. Do not paste it into a public chatbot or an unapproved tool.
E-signatures and engagement letters
Choose an e-signature service with audit trails and secure document storage. Send signing links to the client's verified address, and consider additional verification for high-value matters. Store signed copies in your document system, and decide when to remove copies from the vendor's platform after completion.
Payments
Do not accept card numbers by email or text. Use a processor that handles card data on its own secure pages so the firm does not store it, and keep trust and operating account rules in mind when configuring payment flows. Check your bar's rules on accepting funds, since requirements vary.
Automated follow-up messages
Automated texts and emails should be generic. Avoid including matter details, case outcomes or sensitive terms in subject lines or message previews, which can show on lock screens and in notifications. Confirm that clients have agreed to the channels you use.
Retention for people who do not become clients
Decide how long you keep intake data for those who never hire you, and follow it consistently. Holding old submissions forever increases risk, while deleting too soon may complicate conflict checking. Write a retention rule and document it.
Test the process like an attacker
Submit a test form and follow the data everywhere it goes. Where is it copied? Who gets a notification? What would a stranger see if they guessed a link? Fix any surprise.
Train staff
Teach intake staff to recognize that fraudulent prospects exist, including people who send fake checks or request unusual payments, and to escalate odd requests.
Working with Counsel Cyber
Counsel Cyber configures and secures intake workflows for law firms, from website forms to practice management integrations. We can map where your intake data travels and tighten what needs it.