ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Virtual Practice and Opinion 498: A Remote Work Compliance Checklist

ABA Formal Opinion 498 addresses virtual law practice. Use this checklist to align remote work technology, confidentiality and supervision at your firm.

3 min readBy Counsel Cyber Team

Remote and hybrid work is now a normal part of legal practice. The ABA recognized this in Formal Opinion 498, issued in 2021, which discusses how the Model Rules apply to virtual practice. It does not create new rules, but it applies existing duties of competence, confidentiality, communication and supervision to lawyers working outside a traditional office.

This post turns those themes into a practical checklist for firm leaders. It is not legal advice, and your state bar may have its own guidance, so confirm local requirements.

Themes in the opinion

In general terms, Opinion 498 highlights:

  • Competence (Rule 1.1): Lawyers working virtually should understand the technology they use, including video platforms, cloud storage and security features.
  • Confidentiality (Rule 1.6): Reasonable efforts to prevent unauthorized access, including in home environments and with devices, networks and smart speakers.
  • Communication (Rule 1.4): Clients should be able to reach lawyers, and lawyers should communicate effectively using appropriate technology.
  • Supervision (Rules 5.1 and 5.3): Firms need policies and systems to supervise lawyers and staff working remotely, including vendors.
  • Practical questions: protecting client files, secure communications, managing mail and paper at home, and the firm's virtual presence.

A remote work checklist

Devices

  • Firm-managed laptops with full-disk encryption, endpoint protection and automatic updates
  • Screen locks and short inactivity timeouts
  • Rules for personal devices, including enrollment in management with the ability to remove firm data
  • Prohibition on storing client files on unmanaged local drives or USB sticks

Network and access

  • MFA on all remote access, email and cloud applications
  • VPN or secure access service for firm resources that are not cloud-based
  • Guidance on securing home Wi-Fi: strong passwords, updated router firmware, and changing default credentials
  • A rule against using public Wi-Fi for client work without a secure connection

Home environment

Opinion 498 mentions the home setting. Consider guidance such as:

  1. Work in a space where client conversations cannot be overheard
  2. Position screens away from windows and family members
  3. Lock the screen whenever stepping away
  4. Be aware of smart speakers and voice assistants that may listen during calls
  5. Store any paper files in a locked cabinet or drawer, and shred them properly

Communication tools

  • Use firm-approved video conferencing with waiting rooms, passcodes and appropriate recording settings
  • Use firm-approved messaging, not personal text or consumer apps, for client matters
  • Establish rules for sharing documents, such as secure links instead of unencrypted attachments
  • Consider client preferences and the sensitivity of information when choosing channels

Supervision

  • Maintain regular check-ins between supervising attorneys and junior lawyers and staff
  • Make sure remote staff know who to call with questions or incidents
  • Document remote work policies and require acknowledgment
  • Include vendors in the review, such as cloud providers and remote support tools

Mail, phones and paper

  • Decide how mail is received and scanned
  • Use a firm number or softphone rather than personal numbers for client calls
  • Handle physical originals and signed documents with a defined procedure

Incident response

  • Make sure everyone knows how to report a lost device or suspicious email, from anywhere
  • Maintain the ability to lock or wipe devices remotely
  • Keep contact numbers for IT and the incident lead available offline

Policy contents

A written remote work policy should cover approved devices and tools, security requirements, confidentiality at home, reporting duties and consequences. Keep it short enough that people will read it, and review it annually.

Training

Offer a brief orientation on remote security, including phishing, secure document sharing, home network basics and a quick walkthrough of reporting. Refresh it periodically.

Monitor and review

Technology and work patterns change. Review remote access logs, device compliance and policy exceptions quarterly. Ask staff what is hard, since friction leads to workarounds.

Where Counsel Cyber fits

We help firms secure remote and hybrid work, from device management and MFA to policies and training. Ask us for a remote work readiness review.