ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Locking Down Your Practice Management Platform: An Admin Checklist

A firm administrator checklist for securing practice management software such as Clio: accounts, roles, sharing, integrations and audit logs, step by step.

3 min readBy Counsel Cyber Team

Practice management software holds nearly everything about a matter: contacts, notes, billing, calendars, documents, and often trust accounting. That makes it one of the most valuable systems in the firm, and one of the least reviewed. It tends to be configured on day one, then left alone as staff come and go and integrations pile up.

This checklist is written for the firm administrator or office manager who owns the system day to day. It applies to cloud platforms such as Clio and to similar products. Exact menu names differ by vendor, so treat the items as questions to answer inside your own settings.

Accounts and sign-in

Require multi-factor authentication for every user

Turn it on at the account level if the platform supports it, and confirm that no user has been left out. If your firm uses single sign-on through Microsoft 365, enforce MFA there as well so the control follows the user across applications.

Remove accounts that should not exist

Compare your user list against your current staff roster. Look for former employees, interns from past summers, temporary contract attorneys, and generic accounts like "frontdesk" shared by several people. Each of those is an unmonitored door.

Limit administrator rights

Most firms need only one or two administrators. Everyone else should have a role that matches their work. A billing clerk does not need rights to delete matters or export all contacts.

Roles, permissions and matter access

  1. Define roles on paper first. Attorney, paralegal, billing, front desk, and read-only are common starting points.
  2. Check who can export data. Bulk export of contacts, matters, or documents is exactly what an intruder or a departing employee would want. Restrict it.
  3. Review confidential matter settings. If you need to wall off a matter for a conflict or a sensitive client, confirm that the platform's restrictions actually hide it from the people who should not see it, including in search and reports.
  4. Review trust accounting permissions separately. Fewer people should be able to record, edit, or reconcile trust transactions than can view them.

Integrations and connected apps

Over time, firms connect email, calendars, document storage, e-signature, payment tools, and marketing software. Each integration has permission to read or write data on your behalf.

  • List every connected app and who authorized it.
  • Remove anything no longer used.
  • For each remaining integration, ask what data it can access and whether the vendor can tell you how it is secured.
  • Establish a rule that new integrations require administrator approval.

Client portal and sharing

Client portals are safer than email attachments, but only if used consistently. Check whether portal access requires MFA or a strong sign-in. Confirm who can invite a client, and make sure invitations go to verified addresses. A mistyped email address on a portal invite is a quiet but real breach path.

Also review any public or shareable links to documents. Set expiration dates where the platform allows it.

Logs and alerts

Most platforms keep an activity or audit log. Find yours and learn what it records. Ask who reviews it and how often. A monthly review of unusual logins, bulk exports, permission changes, and deleted records is a reasonable starting cadence for a small firm.

If the platform offers login alerts or notifications for new devices, enable them for administrators at minimum.

Offboarding and onboarding

Add practice management to your standard checklist for both events. On an employee's last day, disable the account, reassign their matters and tasks, and revoke any API tokens or app authorizations they created. On a new hire's first day, assign the role template rather than copying another user's permissions, since copied permissions tend to carry old exceptions along with them.

Backups and data ownership

Cloud vendors protect their infrastructure, but your agreement may not promise you can recover a record you or an employee deleted by mistake. Ask the vendor what recovery options exist and for how long. Consider whether a periodic export of key data to a secure location belongs in your disaster recovery plan, and who is allowed to perform it.

A simple quarterly routine

  1. Reconcile users against the staff roster.
  2. Review administrator list and roles.
  3. Review connected apps.
  4. Skim the audit log for the quarter.
  5. Confirm MFA coverage is still complete.

This takes an hour or two and catches most of the drift that leads to problems.

If your firm would like help with a practice management review, Counsel Cyber does these regularly alongside Microsoft 365 and document management configuration. We can sit down with your administrator and go through the settings together.