ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Formal Opinion 477R: Securing Client Email and Communications

ABA Formal Opinion 477R asks lawyers to make reasonable efforts to secure client communications. Here is a plain-English guide for firm leaders.

3 min readBy Counsel Cyber Team

Email remains the default way lawyers talk to clients, and it is also the default way attackers reach law firms. ABA Formal Opinion 477R, "Securing Communication of Protected Client Information," addresses what lawyers should consider when transmitting client information electronically. The opinion was issued in 2017 and revised in 2018, which is why it carries the "R."

This post summarizes the opinion in plain English. It describes what the ABA has said, not what your state requires, so confirm local guidance with your bar. It is not legal advice.

The core idea

Model Rule 1.6(c) says a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or access to, information relating to the representation of a client. Opinion 477R builds on that. It describes a fact-based analysis rather than a fixed list of required tools, and it notes that what is reasonable can change as technology and threats change.

Factors the opinion highlights

The ABA lists several considerations in judging reasonable efforts:

  1. The sensitivity of the information
  2. The likelihood of disclosure if additional safeguards are not employed
  3. The cost of employing additional safeguards
  4. The difficulty of implementing the safeguards
  5. The extent to which the safeguards adversely affect the lawyer's ability to represent clients

In practice, this means a routine scheduling email and a memo discussing a client's trade secrets may deserve different handling.

Seven steps the opinion discusses

The ABA describes a general approach that firms can translate into policy:

  • Understand the nature of the threat. Know which clients and matters are likely targets.
  • Understand how client confidential information is transmitted and where it is stored. Map your flows, including phones, home devices and cloud tools.
  • Understand and use reasonable electronic security measures. This includes encryption and authentication appropriate to the situation.
  • Determine how electronic communications about clients should be protected. Consider different levels for different kinds of information.
  • Label client confidential information.
  • Train lawyers and nonlawyer assistants in technology and information security.
  • Conduct due diligence on vendors providing communication technology.

Special circumstances

The opinion states that in some situations, a lawyer may need to take special security precautions, or may need to obtain informed consent from the client to use certain methods. Examples include a client who requests particular handling, a matter involving unusually sensitive information, or a situation where a client's email account is known to be shared or monitored, such as a work account in a dispute with the employer.

Turning guidance into practice

Use a client portal or encrypted transfer for sensitive material

When documents are highly sensitive, a secure portal reduces the risk of misdirected email and interception.

Turn on the basics

Multi-factor authentication, encryption in transit, mobile device management and automatic screen locks are common baseline measures.

Watch for misdirected email

Autocomplete errors send messages to the wrong recipient. Consider a short delay on outgoing mail, or warnings on external recipients.

Set expectations with clients

Add language to engagement letters about how you will communicate and any limits. Ask clients about their own risks, such as shared devices.

Train and remind

Short, regular training reinforces habits such as checking recipients and avoiding public Wi-Fi without protection.

Beyond email

The opinion's reasoning applies to text messages, file-sharing links, video calls and messaging apps. A policy that governs only email will miss many real communications.

Documenting your approach

Keep a short written policy describing how the firm communicates securely, the tools it uses and when special handling applies. A dated policy, with training records, shows deliberate effort.

A short policy outline

A one-page secure communications policy can cover these points: which channels are approved for client information, when a portal or encryption is required, how to confirm recipient addresses, how to handle clients who insist on less secure methods, and who to call when a message goes to the wrong person. Review it annually and whenever the firm adopts a new tool. Written guidance gives staff a clear answer when a client asks for something convenient but risky.

How we can help

Counsel Cyber works with firms to set up encrypted email options, client portals, mobile device protections and staff training that match the practical spirit of Opinion 477R. If you would like to compare your current communication practices to the factors above, we can walk through them with you.