The American Bar Association’s 2023 Legal Technology Survey found that 29% of attorneys said their firm had experienced a security breach, while another 19% did not know either way. That second figure is the harder one for client data security for Lancaster PA law firms.
The Duty Never Changed. The Filing Cabinet Did.
Pennsylvania Rule of Professional Conduct 1.6(d) asks a lawyer to make reasonable efforts to prevent two things. One is the inadvertent or unauthorized disclosure of information relating to the representation of a client. The other is unauthorized access to that information.
The comment to the rule sharpens the point. A lawyer must act competently to safeguard client information against unauthorized access by third parties.
Nothing in that language mentions servers, permissions, or software. It does not need to. When client files live on a shared drive and travel by email, reasonable efforts is a description of how your technology is configured.
The rule also builds in a defense worth noticing. Unauthorized access does not violate the rule if the lawyer made reasonable efforts to prevent it. That defense rests on evidence you can produce afterward, which means policies, settings, and records rather than good intentions.
Where Privileged Material Actually Ends Up
Ask a firm where client files are stored and you will hear the name of a document management system. Ask where a specific set of deposition exhibits from two springs ago lives, and the answer gets longer and less certain.
Privileged material spreads because the work spreads. Attorneys draft at night, review on the road, and share files across firms, and sending a copy is always faster than arranging access to the original.
Common resting places for confidential client material in small and midsize firms:
- Mailboxes holding years of attachments nobody has ever archived
- Personal laptops and home desktops used for after-hours drafting
- Consumer cloud accounts a staff member set up for one project
- Flash drives from a closing or hearing that never came back
- Shared drives where every employee can open every folder
- Text threads between attorneys and clients on personal phones
None of this is misconduct, and none of it means anyone did anything careless. It is what modern practice looks like. Each location is simply another copy of confidential information sitting outside whatever protection the firm believes it has in place.
The exposure is rarely dramatic. A laptop is stolen from a car in a Lancaster parking garage. A departing associate keeps a sync folder running for six weeks. A shared login gets reused on a personal account that later shows up in a credential dump.
The Channel Nobody Reexamines
Most confidential material still leaves a firm the same way it did fifteen years ago, as an attachment on ordinary email. Encryption would help, but the ABA survey found only 42% of respondents had email encryption available to them at all.
Misdirected mail is the quiet version of this problem. Address autocomplete puts opposing counsel one keystroke away from a privileged draft, and there is no recall button that reliably works outside the firm.
A client portal takes that risk off the table for document exchange, and most practice management platforms already include one. Firms often own the capability and never switch it on, because email is what clients expect and nobody wants to add friction.
Access Control Is Most of the Job
The most common security gap in a small firm is not a missing product. It is that everyone can see everything.
A twelve-person firm often runs one shared drive with one permission level. The paralegal who supports family law matters can open the folder for a contested estate. Nobody decided that. It is what happens when a drive grows for a decade and no one revisits who should reach what.
Matter-level access control fixes that quietly, and it does something else besides. It creates a defensible record of who could see which file, which is exactly what a client, a carrier, or a disciplinary inquiry will want to see.
Worth answering this quarter:
- Can every employee open every client folder right now?
- When someone resigns, how many minutes pass before access actually ends?
- Do contract attorneys and temp staff get scoped access or full access?
- Does anyone review permissions on a schedule, or only after a problem?
- Could you produce a log showing who opened a given matter last month?
That is what client data security for Lancaster PA law firms comes down to in daily practice. Not a purchase. A configuration, maintained on purpose.
Your Vendors Sit Inside the Privilege
Verizon’s 2026 Data Breach Investigations Report found that breaches involving a third party now account for 48% of all breaches, a 60% jump over the prior year. Supply chain exposure is no longer an enterprise concern.
Law firms have more outside parties touching confidential material than most businesses their size. Co-counsel, e-discovery platforms, court reporters, translators, expert witnesses, cloud practice management vendors, and the firm’s own IT provider all have some path to privileged information.
The professional duty does not travel with the file. If a vendor mishandles client material, the obligation to have made reasonable efforts still belongs to the lawyer who sent it.
Vetting vendors does not require a security background. It requires a short, consistent set of questions asked before the engagement rather than during an incident.
Ask any vendor handling client material:
- Who on your staff can read our data, and under what circumstances?
- Is our material encrypted while stored and while moving between us?
- What happens to every copy of it when we end the relationship?
- How fast will you notify us of a security incident affecting our files?
Answers in writing are worth more than answers on a call. They also form part of the record that shows reasonable efforts were made, which is the same record that protects the firm later.
What Clients Have Started Asking For
Something has shifted in how clients evaluate outside counsel. The ABA survey found 27% of respondents had been asked by a client or prospective client for the firm’s security requirements documentation, and 22% had been asked to complete a security questionnaire.
Those percentages drop sharply at smaller firms. Only 15% of firms with two to nine attorneys reported a request for security documentation, compared with 41% at firms of ten to forty-nine attorneys.
Read that as a leading indicator, not a reprieve. Requirements of this kind tend to move down the chain over time, from corporate clients to their regional counsel to the local firms handling a piece of the matter.
Client data security for Lancaster PA law firms is turning into a business development question, not only an ethics one. A firm that can answer a security questionnaire in a week has an advantage over a firm that needs a month and an outside consultant to get started.
Pennsylvania Puts a Clock on the Bad Day
Pennsylvania’s Breach of Personal Information Notification Act requires notice to affected residents without unreasonable delay once a breach is determined. The 2022 amendments, effective in May 2023, widened what counts as personal information.
The statute now counts medical information, health insurance information, and a username or email address paired with a password or security question answer. Those elements trigger the law when they are linked to a person’s name and left unencrypted. Look at what sits in a typical matter file. Personal injury records, employment files, estate documents, and client portal credentials all land inside that definition.
The encryption carve-out is the part worth underlining. Data that is encrypted or redacted falls outside the notification trigger, which turns a technical control into the difference between a quiet cleanup and a public one.
The trouble is that notification obligations arrive on the worst day of the year, and most firms meet them cold. The ABA survey found only 34% of respondents had an incident response plan at all. Among firms of two to nine attorneys, the figure was 19%, matching solo practitioners.
An incident response plan is not a binder nobody reads. It is a short document naming who gets called first, which vendor performs forensics, who talks to clients, and where the backups are. Deciding all of that while the phones are ringing is how a manageable incident becomes a reportable one.
Where a Firm Actually Starts
None of this requires rebuilding the practice. The ABA data suggests most of the gap sits in controls that are already available and simply not turned on or not enforced.
Reasonable first moves for a small or midsize firm:
- Enable multifactor authentication on email, the document system, and remote access, since only 54% of survey respondents reported having it available at all
- Turn on file and email encryption, available to 48% and 42% of respondents respectively
- Rebuild shared drive permissions around matters and roles instead of one flat level
- Put written policies in place for remote access, email use, and acceptable use
- Test a full restore from backup rather than trusting the nightly success report
- Commission a third-party security assessment, which 29% of firms overall and 21% of solos have done
Work down that list and most of the realistic exposure closes. What remains is upkeep, which is the part firms tend to underestimate. Permissions drift, staff turn over, vendors change hands, and a configuration that was sound two years ago quietly stops matching how the firm works.
Client data security for Lancaster PA law firms is not a purchase with a completion date. The standard is reasonable efforts, and reasonable efforts are demonstrated by what a firm does routinely, documents as it goes, and can show to someone who asks.
Sources:
- American Bar Association, 2023 Cybersecurity TechReport (2023 Legal Technology Survey Report, Technology Basics and Security volume)
- Pennsylvania Rule of Professional Conduct 1.6, 204 Pa. Code Chapter 81, including the comment to paragraph (d)
- Breach of Personal Information Notification Act, Act 94 of 2005 as amended by Act 151 of 2022, full statute text, Pennsylvania General Assembly
- Verizon, 2026 Data Breach Investigations Report, Verizon news release