Client Confidentiality and Your Law Firm's Technology: What Washington Rules of Professional Conduct Require

By Raj Sidhu, Founder & CEO of inTech Consulting, author of "Beyond the Prompt: A Business Owner's Guide to Understanding AI." Published September 15, 2026.

Washington RPC 1.6 requires attorneys to make reasonable efforts to prevent unauthorized access to client information, and that duty applies to electronic data exactly the way it applies to a paper file. RPC 1.1 Comment 8 goes further and requires lawyers to understand the risks and benefits of the technology they actually use. Together, they mean your firm's IT setup is not a back-office decision. It's a professional conduct obligation.

What Does RPC 1.6 Require for Electronic Client Data?

RPC 1.6(a) protects information relating to the representation of a client. RPC 1.6 also requires reasonable efforts to prevent inadvertent or unauthorized disclosure, and that standard doesn't distinguish between a locked file cabinet and an encrypted server. If your firm stores client files, email, or case management data electronically, that data falls under the same duty of confidentiality as anything in a paper file.

"Reasonable efforts" is deliberately not a fixed checklist. It scales with the sensitivity of the information, the likelihood of disclosure without safeguards, the cost and difficulty of implementing safeguards, and how the safeguards affect your ability to represent the client. A solo estate planning practice and an 18-attorney litigation firm handling trade secret disputes don't have the same bar.

What Is the Duty of Technology Competence Under RPC 1.1?

RPC 1.1 Comment 8 requires a lawyer to keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. This isn't a suggestion to attend a CLE eventually. It's an ongoing competence requirement tied directly to the tools your firm uses to communicate with and store data about clients.

In practice, this comment is what turns "I didn't know our file-sharing tool wasn't encrypted" from a technical oversight into a professional conduct problem.

What Do the ABA Ethics Opinions Actually Require?

Two ABA Formal Opinions shape how "reasonable efforts" gets interpreted, and both are referenced by state bars including Washington's.

  • ABA Formal Opinion 477R addresses securing communication of protected client information. It doesn't mandate encryption for every email, but it requires a fact-specific risk assessment: the sensitivity of the information, the likely means of transmission, and whether the client has instructed a particular method of communication. Highly sensitive matters (a merger, a criminal case, a family law dispute involving a public figure) push firms toward encrypted transmission as the reasonable standard.
  • ABA Formal Opinion 483 covers what happens after a breach. It requires lawyers to stop the breach and restore systems, determine what occurred, and notify current clients whose confidential information was likely accessed or disclosed. Notification isn't optional once likely disclosure is established, even if you're still investigating scope.

What Does "Reasonable Efforts" Mean in Practice?

Four things consistently show up when firms are evaluated against this standard, whether by a bar complaint, a malpractice carrier, or opposing counsel in discovery.

  1. Encryption at rest and in transit for anything containing client data, including email attachments and backups, not just the primary case management system.
  2. Access controls tied to individual users, not shared logins, with multi-factor authentication on email and any system holding client files.
  3. Vendor diligence on every third-party tool that touches client data: practice management software, e-discovery platforms, cloud storage, even a transcription service.
  4. A documented incident response plan that spells out who investigates, who decides on notification, and how fast that decision gets made.

None of these require a firm to build its own infrastructure. They require the firm to know, specifically, what its vendors and its internal setup actually do.

Not sure your current setup would hold up under an RPC 1.6 review? Get a straight assessment of where your firm's technology stands against the reasonable efforts standard.

Get the Assessment Book a 30-Minute Call

Cloud Storage and Third-Party Vendors: What Does Due Diligence Look Like?

Most confidentiality failures in firms we work with don't come from a hacked email account. They come from a vendor contract nobody read closely. Before a firm adopts any cloud storage or SaaS tool that will touch client files, the diligence should cover:

  • Where the data is physically stored, and whether it leaves the country
  • Who at the vendor can access client data, and under what circumstances
  • Whether the vendor will sign a confidentiality or data processing agreement, not just a standard terms of service
  • The vendor's own breach notification commitments, and how fast they're required to tell you
  • What happens to the data if the firm terminates the contract

A vendor that won't answer these directly is telling you something. Vendor risk review should be part of onboarding any new platform, not an afterthought after a client asks about it.

Secure Client Portals vs Email: Which Should Your Firm Use?

Standard email is not inherently non-compliant under RPC 1.6, but ABA 477R's fact-specific standard means the sensitivity of what you're sending should drive the method. A routine scheduling email doesn't need the same protection as a settlement offer or medical records in a personal injury matter.

Secure client portals solve this at the source: encrypted by default, access-logged, and outside the reach of a compromised personal email account on the client's end, which is a common breach vector firms don't control. Firms handling regularly sensitive matters (family law, criminal defense, high-value litigation) increasingly treat a portal as the default, with email reserved for routine, low-sensitivity communication.

Illustrative example, not a specific client engagement: an 18-attorney litigation firm in Bellevue handling trade secret and employment disputes adopted a secure client portal for all document exchange after a client's compromised personal email exposed a draft settlement demand. The firm's own systems were never breached. The exposure came entirely from the client's side, which is exactly the scenario RPC 1.6's reasonable efforts standard is meant to anticipate.

Does This Apply the Same Way in Oregon and Idaho?

The underlying obligation is consistent. Oregon's RPC 1.6 and RPC 1.1 track the ABA Model Rules closely, and the Oregon State Bar has issued its own guidance reinforcing the technology competence duty. Idaho's rules follow the same structure through the Idaho State Bar. Firms operating across the Washington, Oregon, and Idaho footprint should treat the reasonable efforts standard as the floor everywhere, rather than assuming the strictest state's requirements are unique to that state.

What does vary is enforcement posture and any state-specific guidance opinions, so a firm with offices in more than one state should confirm current bar guidance in each jurisdiction rather than assuming full uniformity.

What Should a Firm Ask a Prospective IT Provider to Prove?

Before signing with any IT provider serving law firms, ask for specifics, not assurances:

  • Documented encryption standards for data at rest and in transit
  • How access controls and MFA are enforced across the firm, not just recommended
  • A written backup and disaster recovery plan with tested recovery times, not just "we do backups"
  • Their own vendor diligence process for any subcontracted tools
  • A named point of contact for incident response, with response time commitments

A provider that can't produce these in writing isn't equipped to help you meet RPC 1.6, regardless of how the sales conversation goes.

Frequently Asked Questions

Does RPC 1.6 require law firms to encrypt all client communications?

Not automatically. RPC 1.6 and ABA Formal Opinion 477R require a fact-specific risk assessment based on the sensitivity of the information and the likely means of transmission, rather than a blanket encryption mandate. Highly sensitive matters typically require encrypted transmission as the reasonable standard.

What is the duty of technology competence under RPC 1.1?

RPC 1.1 Comment 8 requires lawyers to keep abreast of the benefits and risks associated with relevant technology as part of the general duty of competence. It applies directly to the tools firms use to store and transmit client information.

What must a law firm do after a data breach under ABA Formal Opinion 483?

The firm must stop the breach and restore system integrity, determine what occurred to the extent reasonably possible, and notify current clients whose confidential information was likely accessed or disclosed, without waiting for a complete investigation to conclude first.

Does client confidentiality apply to cloud storage and SaaS vendors?

Yes. Any third-party vendor that touches client data is subject to the same reasonable efforts standard, which means firms need to vet where data is stored, who can access it, and what breach notification commitments the vendor makes before adopting the tool.

Should a law firm use a secure client portal instead of email?

For sensitive matters, a secure portal is increasingly treated as the reasonable standard because it's encrypted by default and not exposed to breaches on the client's personal email account. Routine, low-sensitivity communication can generally still use standard email.

Do Oregon and Idaho have the same confidentiality technology requirements as Washington?

The underlying obligation is consistent, since Oregon and Idaho's professional conduct rules track the same ABA Model Rules structure as Washington's. Firms operating across state lines should confirm current guidance in each jurisdiction rather than assume full uniformity.

Bring your firm's technology in line with RPC 1.6 and RPC 1.1. We work with law firms across Washington, Oregon, Idaho, and Montana on encryption, access controls, vendor vetting, and incident response built around the reasonable efforts standard.

Get the Assessment Book a 30-Minute Call