A lawyer is representing a start-up company in a complex patent infringement case. The client's CEO sends an email to the lawyer's personal, unsecured email account, which the lawyer occasionally uses for client communications. The email contains highly sensitive trade secrets critical to the patent case. The lawyer's firm has a secure client portal, but the CEO found it cumbersome. What is the lawyer's ethical responsibility regarding the use of the unsecured email account?
- AThe lawyer has no ethical breach if the CEO chose to send it to the unsecured account.
- BThe lawyer must delete the email and request the client resend it to the secure portal.
- CThe lawyer potentially violated the duty of confidentiality by not ensuring reasonable security for client communications.
- DThe lawyer must immediately notify the bar association of the potential data breach.
Show answer & explanationAnswer & explanation
Correct answer: C. The lawyer potentially violated the duty of confidentiality by not ensuring reasonable security for client communications.
Lawyers have an affirmative duty to make reasonable efforts to protect client information, including ensuring the security of communication methods. While the client sent it to the unsecured account, the lawyer's failure to prevent or adequately address that use (e.g., by directing the client to the secure portal or setting up proper security for the personal account) constitutes a potential breach of their duty to safeguard confidential information.
Why the other options are wrong
- A. The lawyer still has a duty to ensure reasonable security for client communications, regardless of client's choice.
- B. Deleting the email and requesting resending is a good practical step but doesn't negate the prior potential ethical breach of allowing/using an unsecured channel.
- D. Not every potential breach requires immediate notification to the bar, especially if no actual breach occurred or harm is evident yet.
Technology & Confidentiality
Lawyers must use reasonable care when transmitting or storing client information electronically, ensuring adequate security measures to protect confidentiality.
- Reasonable efforts are required to prevent unauthorized access.
- Unsecured communication channels can be an ethical risk.
- Lawyers must be competent in technology use.
Memory trick: Secure Your Client Data, Always.