Arizona Ethics Bar approves online access to client records…
Lawyers providing an online file storage and retrieval system for client access of documents must take reasonable precautions to protect the security and confidentiality of client documents and information. Lawyers should be aware of limitations in their competence regarding online security measures and take appropriate actions to ensure that a competent review of the proposed security measures is conducted. As technology advances over time, a periodic review of the reasonability of security precautions may be necessary.
FACTS
The inquiring lawyer wants to offer a service to clients that would allow clients online access to view and retrieve client files. The lawyer designed a multi-level security system in an effort to maintain the confidentiality and security of the files. First, the client files would be accessible only through a Secure Socket Layer (SSL) server, which encodes documents, making it difficult for third parties to intercept or read them. Second, the lawyer would assign unique randomly generated alpha-numeric names and passwords to each online client folder. The folder names contain no information that could identify the client to which it belongs. The password would not be the same as the client folder name. Third, all online client files would be converted to Adobe PDF (Portable Document Format) files and protected with another randomly generated unique alpha-numeric password.
QUESTION PRESENTED
May the inquiring lawyer maintain an encrypted online file storage and retrieval system for clients in which all documents are converted to password-protected PDF format and stored in online folders with unique, randomly-generated alpha-numeric names and passwords?
For more information: http://centricecm.wordpress.com/2010/01/07/arizona-ethics-bar-approves-online-access-to-client-records/
Compliments of FileMan Research
Cary McGovern-Fileman
