Cloud practice-management platforms hold nearly everything about a matter: contacts, notes, billing, calendars and documents. That concentration makes them convenient, and it also makes them a target. Most platforms offer a range of security settings, but defaults are not always the strictest, and many firms never revisit them after setup. This checklist applies to Clio and similar tools, though the exact menu names differ by product. Check your vendor's documentation for specifics.
Start with identity
Require multi-factor authentication
If your platform allows MFA, enforce it for every user, not just administrators. If it supports single sign-on through Microsoft 365 or another identity provider, consider using it so access is controlled in one place and disabling one account cuts off everything.
Review who is an administrator
Administrator roles can usually change billing, export data and add users. Keep the number small. Many firms discover that a former employee or an assistant who changed roles still holds broad permissions.
Use role-based access
Give each person access to what their job requires. A receptionist rarely needs billing reports or access to every matter. Where the software supports matter-level permissions, use them for sensitive files and conflicts situations, such as when an ethical wall is needed.
Control how data leaves the system
Sharing links and client portals
Check how documents are shared externally. Prefer a secure client portal over email attachments. If the tool allows public or anonymous links, determine whether they expire, whether they require a password, and who can create them.
Exports and reports
Large exports of contacts or matters are a classic way for departing staff or compromised accounts to take data. Ask whether exports are restricted to administrators and whether they are logged.
Email and document sync
If the platform syncs with Outlook, a document system or cloud storage, review what permissions those connections hold and where copies of data end up.
Review third-party integrations
Practice-management tools connect to accounting software, e-signature tools, calendars, payment processors and many apps. Each integration is an authorized path into your data.
- List every connected app and who authorized it.
- Remove anything no one recognizes or uses.
- Check what scope of access each app was granted.
- Establish a rule that new integrations need approval before anyone connects them.
Turn on and read the logs
Audit logs record sign-ins, changes and exports. Find out what your plan includes and how long history is retained. Assign someone to review them periodically, or have your IT provider alert on unusual activity such as sign-ins from unexpected locations or large downloads.
Protect trust accounting data
Billing and trust-accounting features are sensitive. Limit who can edit trust transactions, require review of changes, and keep reconciliation duties separate from payment authorization where staffing allows. Your state's trust account rules govern the details, so confirm with your bar.
Plan for onboarding and offboarding
- Create accounts through a standard checklist with approved roles.
- On departure, disable the account the same day, transfer matters, and revoke tokens and connected apps.
- Review dormant accounts quarterly and remove those no longer needed.
Know your vendor's side of the arrangement
Ask the vendor about their security documentation, data location, encryption, backup and recovery commitments, and how they notify customers of incidents. Cloud vendors operate under a shared-responsibility model. They secure the platform, and you remain responsible for configuring access and protecting accounts. Also ask how you can obtain a periodic export of your data in a usable format.
A quick quarterly review
Put a recurring reminder on the calendar to run through these items:
- Active users and their roles
- MFA enforcement status
- Connected apps
- External sharing settings
- Recent unusual log entries
- Departed staff whose access should be removed
Where to get help
A configuration review takes only a few hours, and it often reveals old accounts and unused integrations. Counsel Cyber supports firms that run Clio, NetDocuments, iManage and Microsoft 365, and we can review your settings with your administrator and provide a short list of recommended changes.