ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Securing Your Practice Management Platform: A Settings Checklist

Cloud practice management systems hold your most sensitive data. Use this settings checklist to harden user access, sharing, integrations and recovery.

3 min readBy Counsel Cyber Team

Cloud practice management software holds contacts, matter notes, billing details, trust accounting records and often documents. Most firms spend significant time choosing and implementing the platform and far less on locking it down. Vendors secure their infrastructure, but how the firm configures accounts and permissions is the firm's responsibility.

This checklist applies to any cloud practice management or document platform. Names of settings vary by product, so use it as a guide for conversations with your administrator or IT provider.

Identity and Access

Require multi-factor authentication

Turn MFA on for every user, not just administrators. If the platform supports single sign-on through Microsoft 365 or another identity provider, consider using it so MFA and conditional access rules apply consistently.

Use named accounts

Each person should have their own login. Shared logins make it impossible to know who did what, and they tend to persist after staff leave.

Limit administrator rights

Keep the number of administrators small, ideally two or three. Administrators should use separate accounts for admin work if the platform allows it.

Apply role-based permissions

Give users access based on what their role needs. A receptionist usually does not need access to trust account reports. Review permissions when roles change.

Offboard promptly

Add practice management accounts to your departure checklist. Disable the account the same day, and reassign matters and tasks.

Data Sharing and Client Access

  • Review client portal settings. Confirm who can invite clients, what documents are visible and whether links expire.
  • Control external sharing links. Prefer links that require authentication and expire, over anonymous links that last forever.
  • Check email-to-matter integrations so confidential messages do not land in the wrong matter.
  • Restrict exports. Bulk export of contacts or documents should be limited to people who need it, and logged.

Integrations and Connected Apps

Practice management platforms connect to email, calendars, accounting, e-signature, payment and automation tools. Every connection is a door.

  1. List every connected application and who authorized it
  2. Remove anything no longer used
  3. Review what data each integration can read or write
  4. Restrict who may add new integrations
  5. Re-review after any vendor announces a change

Trust Accounting Controls

Trust accounting is one of the most sensitive functions in a law firm. Use the software's controls to support your reconciliation process: limit who can post and edit entries, require review of reconciliations, and enable audit logs. Combine these with a firm policy requiring verification of any payment instruction. Your state bar's trust accounting rules govern; confirm your obligations there.

Logging and Alerts

  • Turn on audit logging if it is not on by default
  • Decide who reviews unusual activity, such as large exports, failed logins and permission changes
  • Set up alerts for new administrator creation and changes to security settings
  • Know how long the platform retains logs and whether you can export them

Backup and Recovery

Even reputable vendors usually describe a shared responsibility model: they keep the service running, while you are responsible for your data's content. Ask:

  • What recovery options exist if a user deletes matters or documents?
  • How long are deleted items retained?
  • Can you restore a single matter, or only the entire account?
  • Is a separate third-party backup available or appropriate?

Document the answers and test a recovery if possible. This fits into your broader disaster recovery plan.

Vendor Due Diligence

Ask the vendor for security documentation: independent assessment reports, encryption practices, data location, incident notification terms and exit options. ABA Model Rule 5.3 and Formal Opinion 477R both relate to a lawyer's obligations when using outside technology providers, and written answers help you meet client questionnaire and cyber insurance requests.

Staff Habits

  • Do not store passwords in the platform's notes fields
  • Report any suspicious activity such as unexpected login notices
  • Use firm-managed devices when possible
  • Lock screens and log out of shared computers

A Quarterly Routine

Once a quarter, have the administrator review:

  1. The list of users and their roles
  2. Active integrations
  3. Sharing and portal settings
  4. Audit log highlights
  5. Any vendor security notices

Document the review and date.

Getting It Done

Counsel Cyber configures and reviews practice management and document platforms for law firms, including MFA, permissions, integrations and recovery. If it has been a while since anyone looked at your settings, we can run a short configuration review and give you a prioritized list.