ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Securing Client Communications: Opinion 477R in Everyday Practice

ABA Formal Opinion 477R discusses reasonable efforts to protect client communications. See how to apply its factors to email, portals and messaging.

3 min readBy Counsel Cyber Team

Lawyers have communicated with clients by unencrypted email for decades, and the ABA historically treated that as generally acceptable in many circumstances. In 2017, Formal Opinion 477R, "Securing Communication of Protected Client Information," updated that view for an age of persistent cyber threats. It does not mandate a particular tool. It asks lawyers to make reasonable efforts based on the circumstances.

This post translates the opinion's themes into practical choices for a firm. It is not legal advice, and state guidance varies, so confirm with your state bar.

What the opinion says, in general terms

Opinion 477R builds on Model Rule 1.6(c), which requires reasonable efforts to prevent unauthorized disclosure of or access to client information. It describes a fact-specific analysis in which lawyers consider factors such as:

  • The sensitivity of the information
  • The likelihood of disclosure without additional precautions
  • The cost of employing additional safeguards
  • The difficulty of implementing them
  • The extent to which safeguards adversely affect the lawyer's ability to represent clients

It also describes steps lawyers should consider, such as understanding the nature of threats, understanding how client information is transmitted and stored, using reasonable electronic security measures, determining how electronic communications should be protected, labeling confidential communications, training lawyers and staff, and conducting due diligence on vendors. In special circumstances, such as highly sensitive matters or a known threat, more protection, including encryption, may be appropriate. Clients may also request particular methods.

Turning the factors into firm practice

Classify by sensitivity

Not every message needs the same protection. Consider tiers such as:

  1. Routine: scheduling, general updates
  2. Confidential: legal advice, case strategy, financial details
  3. Highly sensitive: trade secrets, personal identifiers, health information, matters involving a likely target

Assign a default method for each tier, so attorneys are not deciding from scratch each time.

Choose the right channels

  • Standard email with enforced transport encryption may be appropriate for routine matters, with MFA protecting the accounts.
  • Secure client portals suit documents and confidential exchanges, because the files stay in a controlled place rather than traveling as attachments.
  • Encrypted email or secure file transfer can be used for highly sensitive material.
  • Messaging apps should be firm-approved and not consumer tools on personal devices, and text messaging should follow a policy.
  • Video conferencing should use waiting rooms, passcodes and appropriate settings.

Protect the accounts behind the channels

Encryption matters less if an attacker simply logs in as the lawyer. MFA, strong passwords, device encryption and monitoring protect the mailbox itself. Many incidents involve account takeover rather than interception.

Take care with devices and networks

  • Encrypt laptops and phones
  • Avoid sending confidential material over public Wi-Fi without protection
  • Keep software patched
  • Use screen locks and remote wipe capability

Be careful where clients are the risk

Clients may use an employer's email, a shared family account or a device someone else can access. Ask at the outset where it is safe to send messages, and note it in the file. If a client's communications may be monitored, discuss alternatives.

Label and verify

Add a confidentiality notice, and use clear subject lines without sensitive details. Confirm recipient addresses before sending, especially with auto-complete, since misdirected email is among the most common disclosures.

Document the arrangement

Use the engagement letter to explain how you will communicate, what channels are available, and the client's role in protecting their own information. If a client requests a specific method, record it.

Train and review

Opinion 477R points to training lawyers and nonlawyer staff. Cover recipient checks, portals, phishing and approved channels. Review the approach whenever threats or tools change.

Vendor diligence

Evaluate the vendors that carry or store communications, such as your email provider, portal, and conferencing services, under Rules 5.3 and 1.6(c).

A simple starting policy

  • Default to a secure portal for documents and confidential exchanges
  • Enforce MFA and transport encryption for email
  • Use encrypted options on request or when circumstances warrant
  • Prohibit unapproved apps for client communications
  • Record the client's preferences at intake

Support from Counsel Cyber

We help firms deploy portals, email encryption and secure file sharing, and configure the protections that keep those channels safe. If you want to review your client communication practices, we are glad to help.