Category: Confidentiality

  • Massachusetts Bar Association Publishes Cloud Computing Ethics Opinion

    The Massachusetts Bar Association published Ethics Opinion 12-03 regarding the use of cloud computing in law practice, specifically referring to lawyers’ use of Google docs. The scenario posed in the opinion is this: “A lawyer wishes to store and synchronize the electronic work files that he creates in the course of his law practice across multiple computers and devices (e.g., smartphones, iPads, etc.) so that he can access them remotely.”

    The question posed is “whether it [the use of cloud computing] would violate Lawyer’s obligations under the Massachusetts Rules of Professional Conduct to store confidential client information using Google docs or some other Internet based storage solution, and to synchronize his computers and other devices that contain or access such information over the Internet.”

    This opinion mirrors several that we have seen in the past year that focus on compliance with Rule 1.6 and protection of the client’s confidentiality. (more…)

  • Factors Determining “Reasonableness”

    The ABA Commission on Ethics 20/20 published its revised draft resolutions for comment regarding Technology and Confidentiality at the end of last month. Under Comment [16] to Rule 1.6 “Confidentiality of Information”, the revised draft contains a list of factors that determine whether the lawyer has made reasonable efforts to prevent “unauthorized access to, or the inadvertent or unauthorized disclosure of, confidential information.” Comment [16] states:

    Factors to be considered in determining the reasonableness of the lawyer’s efforts include the sensitivity of the information, the
    likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely  affect the lawyer’s ability to represent clients (e.g., by making a device or important piece of software excessively difficult to use). (more…)

  • NC Cloud Computing Opinion Published

     

    At its meeting on January 27, the NC State Bar Council adopted and published the last version of 2011 Formal Ethics 6 “Subscribing to Software as a Service While Fulfilling the Duties of Confidentiality and Preservation of Client Property”.  The last version of this opinion was sent to subcommittee in July 2011, but the discussion over the structure of the opinion has been almost a year and a half-long process. At one point, a draft of the opinion contained a list of minimum requirements for the use of SaaS which raised some concern with NC lawyers as well as others nationwide who are interested in the development of legal technology.

    The final conclusion of the published Opinion:

    a law firm may contract with a vendor of software as a service provided the lawyer uses reasonable care to safeguard confidential client information.

    The ethics subcommittee that reviewed this issue should be commended for the amount of research and thought that they put into this process. They pulled in experts on both sides on the fence on the issue of using SaaS in law practice and really made an effort to understand the broad impact that the opinion would make on NC practitioners in a variety of practices. At one point, experts in online banking, which also relies on strict security standards for the use of SaaS, were called in to provide their perspective.

    Here are some key items to notice in this opinion: (more…)

  • Private Cloud for Lawyers? Slides from Presentation on Future of Legal Service Delivery

     

    Last week I was honored to give a keynote at the annual Canadian Discipline Administrators Conference in Toronto hosted by the Law Society of Upper Canada. The attendees were the discipline authorities of the different Canadian Bar jurisdictions. After speaking with several of them and based on the Q & A session, I can report that our neighbors to the north are grappling with some of the same issues as our State Bar ethics regulators regarding the use of SaaS in law practice management.

    An interesting idea was raised by a member of the group that the Canadian Bar might create a private cloud just for Canadian lawyers. I believe there was some mention of this as well in the cloud computing report published by the Law Society of British Columbia this summer.

    Would this address some of the concerns surrounding lawyers placing their data into the hands of third-party providers and hosting it in a public cloud?  It’s certainly something to think about. My initial reaction was that it would limit competition and because of the expense of creating and maintaining a private cloud, might take away many of the cost-savings associated with a public cloud as well as cause problems when a law firm wants to use another SaaS product that does not collaborate with the Canadian Bar to host a copy of the data on the private cloud. But there would be benefits, especially for Canadian lawyers who are subject to a more rigorous auditing process that requires immediate access by regulators to a law firm’s data.

    I still think the best approach to take would be to create guidelines for lawyers rather than restricting use of web-based technology to a private cloud or restricting technology use to a specific list of approved vendors, especially if that list of vendors might not be updated regularly.

    What do you think about the creation of a private cloud? What if your state bar proposed to create a private cloud just for its members? What about cross-border and multijurisdictional practices?

    The slides from the presentation are below. I’ve integrated several ethics slides that are specific to the Canadian Bar. For those of you familiar with my presentations, the first few slides may be familiar background information on cloud computing and virtual practice, so skip ahead to the interesting case studies and resources.

  • Proposed NC Ethics Opinion on Cloud Computing Returned to Subcommittee

    The Ethics Committee at the North Carolina State Bar voted to send the proposed formal ethics opinion 6 (FEO 6), entitled “Subscribing to Software as a Service While Fulfilling the Duties of Confidentiality and Preservation of Client Property” back to the subcommittee to reconsider responses they received to inquiries #1 and #2.

    Both of these inquiries contained worrisome minimum requirements for the use of cloud computing that many of the technology providers and attorneys using cloud computing are not certain can be practically implemented without resulting in severe restrictions on the use of a wide number of cloud-based applications.

    The Ethics Committee received responses from groups such as ILTSO and the LCCA as well as from individual attorneys both licensed in NC and across the country.  You may read the LCCA’s detailed response on their website. Some of the responses from individuals included:

    – Nicole Black, author of the soon-to-be published by the ABA/LPM Cloud Computing for Lawyers, provided this response;

    – Erik Mazzone, Director of the Center for Practice Management at the North Carolina Bar Association, wrote about the opinion on his Law Practice Matters blog;

    – Richard Granat, co-chair of the ABA eLawyering Task Force, wrote critically of the proposed opinion on his elawyering blog; and

    – I posted the comments that I submitted to the Committee on this blog a few months ago.

    We should have some idea by the end of October about the revisions, if any, that will be made to the proposed opinion by the subcommittee.

     

  • Top Ten Basic Security Practices for a Virtual Law Office

    I love SaaS.  I depend on SaaS to operate my virtual law office.  I support an attorney’s right to choose their own practice management tools and make their own business decisions whether it’s in the cloud or in a filing cabinet.  But there are responsibilities that come along with choosing any practice management system and that means sticking to your own security policies and best practices.

    I’m a solo virtual lawyer, so the burden is on me alone.  Larger practices can designate an associate or hire an IT consultant to keep them up to date and to make any necessary security policies and safeguards.  Regardless of where you are engaging in virtual law practice, it’s always good be reminded of some basic security practices for delivering legal services online.  Here is my list of the top ten basic security practices for a virtual law office:

    1) Keep up to date on the security issues. Read Lifehacker, Slashdot, TechCrunch, etc.

    2)  If you use wireless networking, ensure that all wireless traffic is encrypted with WPA2.

    3)  Keep antivirus software and all software patches updated and turn on the software firewall for the computer.

    4) Use a safer browser, such as Mozilla with the NoScript add-on installed.  Or use another pop-up blocker. Do not use free Wi-Fi hotspots when using any cloud computing application remotely.  Use a cellular phone modem adapter instead.  I just got the 4G wireless hotspot which I highly recommend.  This also serves as backup internet access in my home office as well.

    5)  Never write down usernames and passwords.  Create strong passwords and change them regularly.  Use Keepass or other password management tool and generator.

    6) Go straight to privacy/account settings in any cloud-based application immediately after you register for and change the defaults for better protection.  Then check back occasionally to make sure they haven’t changed their privacy setting options again.

    7) Watch your back when you work in a public place to make sure the person behind you isn’t able to watch your screen as you enter your username and password or your client’s social security number.

    8) Encrypt your hard drive with Truecrypt, free open source encryption software.  Easy to use, free, protects you if your laptop is stolen.  Backup daily with an external hard drive with Truecrypt on it in addition to regular cloud-based backups.

    9) Make sure that the applications you are using to store and transmit confidential law office data are encrypted.  Look for HTTPS in the URL before proceeding.  Don’t enter data unless you know it will be encrypted.

    10) This isn’t going to be a popular one, but be wary of doing a lot of confidential work on your iPad with just any app.  With my virtual law office, I can open the browser and work in https, but other apps, especially iPad and other mobile device apps, do not have this level of security.  Unencrypted email is permitted by the state bars as exercising reasonable care, but most of us know better.  Text messaging your client is not a wise idea for a lot of reasons.

     

  • Revised Proposed Ethics Opinion on SaaS

    UPDATE: CHECK OUT THIS POST by Erik Mazzone, Director of the Center of Practice Management at the NC Bar Association, on his Law Practice Matters blog.  Erik is concerned that the proposed opinion will limit the cloud-based vendors that attorneys in NC can use based on the location of their servers.  While most legal SaaS vendors will probably be in compliance by housing the data on servers located in the States, other non-legal SaaS companies, such as Dropbox, Google, etc., may not be in compliance with the proposed opinion because their servers are located overseas.  Will this proposed ethics opinion have a broader reach than expected? Are these other services really safe to be using with law office data in the first place?  See this post by Information Law Group discussing a recent Ponemon Study about cloud providers and security.

    The North Carolina State Bar published the revised version of its proposed ethics opinion on the use of SaaS in law practice management on April 21st, entitled, “Formal Ethics Opinion 6: Subscribing to Software as a Service While Fulfilling the Duties of Confidentiality and Preservation of Client Property”.

    The direction that this opinion takes provides guidance to the practitioner, rather than attempting to write technology standards into an ethics opinion, which is not the safest place for it.  Instead, the opinion requires that the attorney do a thorough job investigating the technology provider and any agreements with that providers to ensure confidentiality of the client data.  They also include a reference the ILTSO standards in the footnotes of the opinion (www.iltso.org) along with links to other resources for attorneys to accomplish this process. (more…)

  • Why I Read Hacker Mags

    If you are using technology to deliver legal services online then it’s part of your responsibility to keep up to date on the technology that you are using. Different security risks pop up every day and if you aren’t aware of the them then you can’t protect your law practice and your clients.

    For example, just this week the WSJ reported that Apple and Google collect location information from their users’ mobile devices.  How many virtual lawyers are transmitting confidential client information via mobile devices without any idea of what information is being collected?  Maybe location isn’t a major problem but what about sending photos taken by you or your client on mobile devices across unencypted email and those photos store the locations of where they were taken.  There are situations where this information could put your client (or their children, friends or family members) at risk.

    There are so many benefits to using cloud based technology to deliver legal services online, but we also have a responsibility to protect the confidentiality of our client’s data.  This means understanding how the technology works and how to use it responsibly on a daily basis.

    Several times at the ABA TECHSHOW in Chicago last week after giving presentations I was asked how I keep up with technology.  There are a lot of great law and tech bloggers, but frankly, if you really want to keep up to date on technology and security risks then you need to step outside of the legal profession.  Go into the world that programmers live in or look at the way that the banking or medical industries are handling the transfer of sensitive information using cloud-based systems.

    Yes, I enjoy reading hacker magazines. I understand about 3/4 of what’s in them because I don’t know how to read a lot of code, but it gives me good insight into the risks that are out there and how hackers are able to get ahold of data and manipulate it. I don’t condone the actions of the authors because a lot of it is illegal.  But why not learn from the pros and turn it around to protect my own practice and my clients by making sure my own system is not vulnerable to attack?

    For example, this last spring issue of 2600 had a great article about passwords from a hacker who had downloaded several databases of usernames and passwords and then compiled statistics that showed what is most popular and the vulnerabilities.  That teaches me what I need to do to be more secure online and how to educate my clients when they create usernames and passwords for themselves.

    Here are my two favorite hacker mags:

    2600 (a classic, written by anonymous and well-respected hackers who break systems mostly for the purpose of revealing vulnerabilities; starting to put some issues online)

    phrack (sometimes a little hard to plow through to find gems, but worth the time; posts issues online)

    If you don’t enjoy keeping up with the technology, which includes understanding the security risks, or don’t find this at all interesting, then you should find someone in your firm who does and can keep you updated.  Or you could always retain an IT consultant who will charge you for that education. Or maybe operating a virtual law firm is not something you should be jumping into at all.  You might decide to trust your legal SaaS provider to keep your system updated and maintained to protect your data from vulnerabilities, but they can’t be responsible for your own use of the hardware. Keeping up has to be part of your daily regime because of how quickly it moves.

     

  • Virginia & the Ethics of Cloud Computing in Law Practice

    James M. McCauley, ethics counsel for the Virginia State Bar, has written an article for the February issue of the Virginia Lawyer Magazine, entitled “Cloud Computing — A Silver Lining or Ethical Thunderstorm for Lawyers?”

    Even if you aren’t licensed to practice in Virginia, I would recommend reading this well-balanced article on cloud computing.  

    McCauley summarizes the benefits of the technology for practice management, but spends the majority of the article answering the questions I’m sure he and other ethics counsel hear all the time from attorneys trying to figure out how to implement cloud computing in their practices.  He starts out by stating that “there is no basis in the Virginia Rules of Professional Conduct for an unqualified prohibition of lawyers managing their office software applications and client data using cloud computing.”   And then explains how Rule 1.6(a) gives attorneys an ethical duty to protect our clients’ confidential information.  From there the discussion moves to concerns about security and reliability of cloud computing.  (more…)

  • Outsourcing and the Virtual Law Office

    A virtual law office relies on a third-party provider to operate.  A legal SaaS provider maintains my virtual law office and the data is hosted on a server that is maintained by another third-party company that has leased its servers to my SaaS provider.  

    By using this form of technology to practice law online, am I “outsourcing” as governed by ABA Formal Ethics Opinion 08-451?  Does my use of a third-party technology provider fall under supervision of “non-lawyers” in Model Rule 5.3? 

    *open can of worms*

    The ABA Ethics Commission 20/20 has raised the question of whether cloud computing should be classified as a form of outsourcing.  This can be found in the issues paper entitled “Client Confidentiality and Lawyers’ Use of Technology.”  ABA Formal Ethics Opinion 08-451 describes a lawyer’s obligations when outsourcing work to lawyers and non-lawyers.  One comment to Rule 5.3 states that the duty to supervise non-lawyers extends to those who serve as independent contractors.

    My position:  Selecting a cloud-based technology solution for practice managment is not outsourcing.  It is a business method, a form of delivery.  Rules 1.6 (duty of confidentiality) and 1.15 (safe-guarding client property) require that attorneys use reasonable care in protecting the confidentiality of their client’s property.  To comply, attorneys must do their due diligence in researching and selecting their SaaS provider and any other third-party services.  This requirement provides adequate regulation for the use of a cloud-based technology in law practice management. State bars may provide their members with guidelines and education about how to handle the selection of technology providers or larger firms may decide to hire IT consultants to help them with these decisions.  (more…)

MENU