The operational reality

What Makes Legal Services Different

Your duty runs to the client, and it is enforceable by the Bar. The Florida Bar publishes ethics opinions on exactly the technology questions firms ask - cloud storage of client files, the data on a leased copier before it goes back, and generative AI (Florida Bar ethics opinions). Those opinions ask for due diligence you can describe, not a product you bought.

Trust accounts make you a payments target. Real estate closings, settlements, and escrow disbursements move on emailed instructions. Business email compromise against an IOLTA disbursement is the highest-severity incident type for a small firm, and it is a verification process failure rather than a missing security tool.

Your practice management platform decides your controls. Clio, MyCase, PracticePanther at the small end; Aderant or Elite 3E at the large end; NetDocuments or iManage for documents - or, in many firms under ten attorneys, a shared drive. The vendor configuration you never opened is your access control policy.

There is no natural owner. One to fifteen attorneys, no IT staff, and the de facto administrator is a paralegal or the managing partner. Any requirement to designate a responsible person lands on someone with a full caseload.

Your clients now audit you. Corporate clients push their own vendor requirements down to outside counsel as questionnaires - multi-factor, encryption, retention, breach notification terms. Firms lose engagements over the answers, not the rates.

Failure patterns

What Usually Goes Wrong

  • A closing wire is redirected. The instructions look right, the thread looks real, and the funds are gone within hours. Call-back verification to a number from the file - not from the email - is the control that stops it.
  • "The cloud vendor handles security." The Bar's due-diligence expectation is about where the data lives, who can compel access to it, and whether you can get it back. That is a vendor review, and it produces a document.
  • Departed access lingers. Paralegals, contract attorneys, and temps keep credentials to the document system months after the last matter closed.
  • The leased copier goes back with the drive in it. Court filings, discovery, and probate documents live on that device.
  • An associate pastes client facts into a public AI tool. Almost no small firm has a written policy on this, which makes it a personnel question with no rule behind it.
  • The cyber insurance renewal comes back conditional on multi-factor everywhere, endpoint detection, and immutable backups. Firms find out at renewal, or worse, at claim.
  • A client sends a security questionnaire and the firm has nothing to send back.
  • Everything is privileged, so everything feels protected. Privilege is a rule of evidence. It does not encrypt anything.

Questions people ask

Frequently Asked Questions

Do law firms have to comply with HIPAA?
Only where the firm acts as a business associate - that is, receives protected health information while performing services for a covered entity. It is matter-driven rather than firm-wide. HHS publishes the business associate definition and the required contract terms at hhs.gov/hipaa.
Do I have to tell my clients if the firm was hacked?
Two obligations run in parallel. Professional responsibility governs what you owe the affected client, and the Florida Bar publishes guidance in its ethics opinions. Separately, Fla. Stat. §501.171 requires notice to affected Florida residents within 30 days of determining a breach of personal information. Consult ethics counsel on the first; the statute text is on flsenate.gov for the second.
Can lawyers use Dropbox or Google Drive for client files?
Cloud storage is not prohibited. What is expected is due diligence you can describe: where the data resides, who else can access or compel it, how it is protected, and whether you can retrieve it if the relationship ends. The Florida Bar has addressed cloud computing in its ethics opinions - read them at floridabar.org/etopinions.
Is it acceptable to email clients unencrypted?
It depends on the sensitivity of the content and the client's informed expectations. The higher-risk case is not the routine status email - it is anything containing account numbers or payment instructions, which should not be transmitted or acted on by email alone.
What do I do before returning a leased office copier?
Treat it as a storage device, because it is one. The Florida Bar has issued an ethics opinion on the confidentiality obligations attached to devices with retained data. Practically: a documented sanitization step in the lease-return process, with a certificate you keep.
Can I use ChatGPT to draft legal documents?
The Florida Bar has published an ethics opinion addressing generative AI and lawyers' duties around confidentiality, supervision, and competence. The firm-level answer is a written policy naming approved tools and what may never be entered into them - most firms this size do not have one yet.
Does my malpractice insurance cover a cyberattack?
Professional liability and cyber liability are different policies covering different losses, and social engineering or funds transfer fraud is frequently a separate, sub-limited coverage. Read the funds transfer endorsement specifically, before you need it.
Do solo attorneys get targeted?
Wire fraud attempts are opportunistic and driven by transaction visibility, not firm size. A solo practitioner handling residential closings is a more attractive target than a large firm doing appellate work, because the money moves and the approval chain is short.
A client sent us a security questionnaire. What do we send back?
They typically ask about multi-factor authentication, encryption at rest and in transit, access reviews, backup and recovery, incident response and notification timelines, subcontractor lists, and cyber insurance limits. The answers should come from documents that already exist. Building the answers and the documents at the same time is what makes this painful.
Is my firm required to have multi-factor authentication?
No general rule imposes it on all firms. In practice it is imposed by your cyber insurer at renewal, by corporate clients in engagement terms, and by the reasonable-safeguards expectation behind your confidentiality duty. Treat it as required and you will be right in every case that matters.