{"id":3255,"date":"2016-05-18T17:40:25","date_gmt":"2016-05-18T17:40:25","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=3255"},"modified":"2019-03-08T19:52:17","modified_gmt":"2019-03-09T00:52:17","slug":"digital-direction-for-the-analog-attorney-data-protection-e-discovery-and-the-ethics-of-technological-competence","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2016\/05\/18\/digital-direction-for-the-analog-attorney-data-protection-e-discovery-and-the-ethics-of-technological-competence\/","title":{"rendered":"Digital Direction for the Analog Attorney &#8211; Data Protection, E-Discovery, and the Ethics of Technological Competence"},"content":{"rendered":"<p style=\"text-align: left\">\n<p style=\"text-align: left\"><a href=\"http:\/\/jolt.richmond.edu\/files\/2016\/05\/BMS-Publication-Version-PDF.pdf\" rel=\"\">BMS Publication Version PDF<\/a><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-128 alignleft\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/><\/p>\n<p style=\"text-align: center\">Cite as: Stacey Blaustein et al.,\u00a0<em>Digital Direction for the Analog Attorney<\/em><strong>\u2014<\/strong><em>Data Protection, E-Discovery, and the Ethics of Technological Competence in Today\u2019s World of Tomorrow<\/em>, 22 Rich. J.L. &amp; Tech. 10 (2016), http:\/\/jolt.richmond.edu\/v22i4\/article10.pdf.<\/p>\n<p style=\"text-align: center\"><strong>\u00a0<\/strong>Stacey Blaustein,<a href=\"#_ftn1\" name=\"_ftnref1\">*<\/a> Melinda L. McLellan,<a href=\"#_ftn2\" name=\"_ftnref2\">**<\/a> and James A. Sherer<sup>***<\/sup><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center\"><strong>I. \u00a0Introduction<\/strong><\/p>\n<p><strong>\u00a0<\/strong>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Over the past twenty years, the near-constant use of sophisticated technological tools has become an essential and indispensable aspect of the practice of law. The time and cost efficiencies generated by these resources are obvious, and have been for years.<a href=\"#_ftn3\" name=\"_ftnref3\">[1]<\/a> And because clients expect their counsel to take full advantage,<a href=\"#_ftn4\" name=\"_ftnref4\">[2]<\/a> savvy attorneys understand that they must keep up with ever-evolving legal technologies to stay competitive in a crowded marketplace.<a href=\"#_ftn5\" name=\"_ftnref5\">[3]<\/a><\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 With increased globalization and exponential growth in the creation, collection, use, and retention of electronic data, the challenges to all lawyers\u2014especially those who may not have tech backgrounds or a natural aptitude for the mechanics of these innovations\u2014are multiplying with breathtaking speed.<a href=\"#_ftn6\" name=\"_ftnref6\">[4]<\/a> Nevertheless, many attorneys are either blissfully unaware of the power and potential danger associated with the tools they now find themselves using on a daily basis, or they are willfully avoiding a confrontation with reality. For lawyers, technological know-how is no longer a \u201cnice to have\u201d bonus; it now poses an ethical obligation. Where competent client representation demands a minimum level of tech proficiency, however, many lawyers come up short with respect to this fundamental component of their professional responsibilities.<a href=\"#_ftn7\" name=\"_ftnref7\"><sup><sup>[5]<\/sup><\/sup><\/a><\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 What types of privacy and data security threats do various technologies pose to attorneys, their firms, their clients, and the legal profession in general? What rules and regulations govern how attorneys may make use of technology in their practice, and how might clients seek to impose restrictions around such use when it comes to their corporate data? Must attorneys gain mastery over the intricate mechanics of the technological resources they employ, or is basic knowledge sufficient? How can we weigh the potential risks and rewards of cutting-edge, emerging digital products and electronic resources about which clients\u2014and indeed, even the lawyers themselves\u2014may understand very little? These are just a few of the questions that arise when we consider the issue of technological competence in the legal profession and corresponding ethical requirements.<\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 To begin to answer these questions, we look to the applicable Model Rules issued by the American Bar Association (\u201cABA\u201d), various state-level professional ethics rules that incorporate the Model Rules, associated ethics opinions and guidance issued by the states, state and federal court decisions, and guidelines issued by sector-specific agencies and organizations.<a href=\"#_ftn8\" name=\"_ftnref8\"><sup><sup>[6]<\/sup><\/sup><\/a> Our focus in this investigation concerning lawyerly \u201ctechnological competence\u201d will be on privacy and data security risks and safeguards, e-Discovery-related challenges, and the potential perils of various uses of social media in the legal sphere.<\/p>\n<p style=\"text-align: center\"><strong>\u00a0II. \u00a0<\/strong><strong>The Threat Landscape: Law Firms as Prime Targets<\/strong><\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In recent years, the volume and severity of attacks on electronically-stored data, and the information systems and networks that house that data, have increased exponentially. The modern-day \u201cthreat environment\u201d is \u201chighly sophisticated,\u201d and \u201cmassive data breaches are occurring with alarming frequency.\u201d<a href=\"#_ftn9\" name=\"_ftnref9\">[7]<\/a> For attorneys, such perils implicate multiple ethical and professional responsibilities with respect to how they handle data, including the duty to protect the confidentiality of client information and the obligation to provide \u201ccompetent\u201d representation.<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Unfortunately, law firms can provide a proverbial back door for hackers seeking access to a company\u2019s data, as attorneys often are custodians of a veritable \u201ctreasure trove\u201d of valuable client information \u201cthat is extremely attractive to criminals, foreign governments, adversaries and intelligence entities.\u201d<a href=\"#_ftn10\" name=\"_ftnref10\">[8]<\/a> Some hackers even focus their efforts primarily on law firms, especially those firms collecting vast amounts of data from corporate clients in the course of E-Discovery or corporate due diligence.<a href=\"#_ftn11\" name=\"_ftnref11\">[9]<\/a> Corporate secrets, business strategies, and intellectual property all may be found in a law firm\u2019s collection of its clients\u2019 data.<a href=\"#_ftn12\" name=\"_ftnref12\">[10]<\/a> In some cases, the interceptors may be looking for competitive information relevant to merger negotiations, or trying to suss out evidence of as-yet unannounced deals for insider trading purposes.<a href=\"#_ftn13\" name=\"_ftnref13\">[11]<\/a><\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 A 2015 report estimated that 80% of the biggest 100 law firms have experienced some sort of data security incident.<a href=\"#_ftn14\" name=\"_ftnref14\">[12]<\/a> And as is the case with so many companies that suffer a breach, law firms that <em>have<\/em> been hacked may not know about it for a considerable period of time. Moreover, unlike other industry sectors subject to various reporting requirements, law firms generally do not have a statutory obligation to publicly report cybercrimes that do not involve personally identifiable information.<a href=\"#_ftn15\" name=\"_ftnref15\">[13]<\/a> Lack of obligations notwithstanding, a recent report indicated that \u201c[t]he legal industry reported more \u201ccyber threats\u201d threats in January [2016] than nearly any other sector,\u201d topped only by the retail industry and financial services.<a href=\"#_ftn16\" name=\"_ftnref16\">[14]<\/a><\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Although these reported \u201cthreats\u201d might not necessarily result in data compromises, the fact that the legal industry frequently is among the most targeted for data theft should concern attorneys.<a href=\"#_ftn17\" name=\"_ftnref17\">[15]<\/a> Anecdotal evidence of actual and attempted interference with law firms\u2019 data security systems abounds as well. In 2014, a report indicated that communications between lawyers from the law firm of Mayer Brown and officials with the Indonesian government were intercepted by an Australian intelligence agency that had ties with the U.S. National Security Agency (\u201cNSA\u201d).<a href=\"#_ftn18\" name=\"_ftnref18\">[16]<\/a> And the managing partner of the Washington-area offices of Hogan Lovells LLP recently noted that her firm \u201cconstantly intercept[s] attacks.\u201d<a href=\"#_ftn19\" name=\"_ftnref19\">[17]<\/a><\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The message to law firms seems clear: first, if \u201cyou\u2019re a major law firm, it\u2019s safe to say that you\u2019ve either already been a victim, currently are a victim, or will be a victim.\u201d<a href=\"#_ftn20\" name=\"_ftnref20\">[18]<\/a> Second, \u201c[f]irms have to make sure they are not a weak link\u2026which at its most basic level means their standards for protecting data need to be at least equivalent to those of the companies they represent.\u201d<a href=\"#_ftn21\" name=\"_ftnref21\">[19]<\/a><\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 It seems inevitable that client expectations and demands with regard to their legal service providers\u2019 security will continue to evolve and expand. One commentator recently predicted that in the future \u201cclients across the board will demand firms demonstrate they\u2019re prepared for all shapes and sizes of cybersecurity breaches,\u201d<a href=\"#_ftn22\" name=\"_ftnref22\"><sup><sup>[20]<\/sup><\/sup><\/a> while another prophesized that \u201cin the name of risk management and data leakage prevention, a large financial industry corporation will challenge their outside counsel\u2019s [Bring Your Own Device] program.\u201d<a href=\"#_ftn23\" name=\"_ftnref23\">[21]<\/a> Indeed, according to a 2014 report in the New York Times:<\/p>\n<p style=\"padding-left: 30px\">Banks are pressing outside law firms to demonstrate that their computer systems are employing top-tier technologies to detect and deter attacks from hackers bent on getting their hands on corporate secrets for their own use of sale to others\u2026.Some financial institutions are asking law firms to fill out lengthy 60 page questionnaires detailing the [law firm\u2019s] cybersecurity measures, while others are demanding on-site inspections\u2026.Other companies are asking law firms to stop putting files on portable thumb drives, to stop emailing non-secure iPad or working on computers linked to a share network in countries like China and Russia.<a href=\"#_ftn24\" name=\"_ftnref24\"><sup><sup>[22]<\/sup><\/sup><\/a><\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 In short, lawyers, law firms, and other legal services providers cannot afford to be complacent when it comes to cybersecurity.<\/p>\n<p style=\"padding-left: 60px\"><strong>A. \u00a0Lawyering in the Cloud <\/strong><\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 Firm adoption of cloud services is on the rise, especially among boutiques and solo practitioners that previously lacked the resources to compete effectively with larger law firms when it came to technology and data storage.<a href=\"#_ftn25\" name=\"_ftnref25\">[23]<\/a> At first, the added value of cloud services created a perception that \u201cnirvana had arrived\u201d in terms of leveling the playing field for smaller firms.<a href=\"#_ftn26\" name=\"_ftnref26\">[24]<\/a> Notwithstanding the apparent advantages of the cloud, attorneys were quick to identify concerns associated with the technology and its supporting practices, including \u201cincreased sensitivity to cyber-threats and data security.\u201d<a href=\"#_ftn27\" name=\"_ftnref27\">[25]<\/a> Some commentators opted for a cautious and conservative approach, noting that the \u201clegal profession has developed many safeguards to protect client confidences,\u201d and that the use of cloud hosting, among other practices, fell on a continuum where, as \u201can individual attorney gives up direct control of his or her client\u2019s information, he or she takes calculated risks with the security of that information.\u201d<a href=\"#_ftn28\" name=\"_ftnref28\">[26]<\/a><\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 There is hope for attorneys drawn to the advantages of cloud services, but vigilance and diligence is required. As noted in tech law guidance from March 2014, \u201c[u]sing the cloud to hold data is fine, so long as you understand the security precautions.\u201d<a href=\"#_ftn29\" name=\"_ftnref29\">[27]<\/a> Security concerns have put a damper on adoption rates and the development of attorney-specific cloud services lags behind other industries. This reluctance is unsurprising given the slow rate of technological advancements within the profession generally,<a href=\"#_ftn30\" name=\"_ftnref30\">[28]<\/a> and a deserved reputation that the tendency of firms is \u201cto be technology followers, not leaders.\u201d<a href=\"#_ftn31\" name=\"_ftnref31\">[29]<\/a> That said, lawyers do seem to be embracing the cloud to some extent,<a href=\"#_ftn32\" name=\"_ftnref32\">[30]<\/a> with the majority utilizing cloud solutions in some capacity,<a href=\"#_ftn33\" name=\"_ftnref33\">[31]<\/a> even if implementation is mostly through \u201csporadic action and adoption among firms and law departments.\u201d<a href=\"#_ftn34\" name=\"_ftnref34\">[32]<\/a><\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 With respect to professional obligations, this type of implementation may not require specific technological expertise on the part of the attorneys. New York State Bar Association Opinion 1020, which addressed ethical implications of the \u201cuse of cloud storage for purposes of a transaction,\u201d determined that compliant usage \u201cdepends on whether the particular technology employed provides reasonable protection to confidential client information and, if not, whether the lawyer obtains informed consent from the client after advising the client of the relevant risks.\u201d<a href=\"#_ftn35\" name=\"_ftnref35\">[33]<\/a><\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Further, New Jersey Opinion 701 addresses the reality that it is<\/p>\n<p style=\"padding-left: 30px\">[N]ot necessarily the case that safeguards against unauthorized disclosure are inherently stronger when a law firm uses its own staff to maintain a server. Providing security on the Internet against hacking and other forms of unauthorized use has become a specialized and complex facet of the industry, and it is certainly possible that an independent [Internet Service Provider] may more efficiently and effectively implement such security precautions.<a href=\"#_ftn36\" name=\"_ftnref36\">[34]<\/a><\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 Opinion 701 does include an additional caveat, that<\/p>\n<p style=\"padding-left: 30px\">[W]hen client confidential information is entrusted in unprotected form, even temporarily, to someone outside the firm, it must be under a circumstance in which the outside party is aware of the lawyer\u2019s obligation of confidentiality, and is itself obligated, whether by contract, professional standards, or otherwise, to assist in preserving it.<a href=\"#_ftn37\" name=\"_ftnref37\">[35]<\/a><\/p>\n<p style=\"padding-left: 60px\"><strong>\u00a0B. \u00a0<\/strong><strong>E-Discovery Tools<\/strong><\/p>\n<p><strong>\u00a0<\/strong>[17]\u00a0\u00a0\u00a0\u00a0 To begin with, federal judges are unconvinced that many of the attorneys appearing before them understand how to make proper use of the technologies and related strategies associated with E-Discovery. A recent report, \u201cFederal Judges Survey on E-Discovery Best Practices &amp; Trends,\u201d<a href=\"#_ftn38\" name=\"_ftnref38\">[36]<\/a> compiled some of the judges\u2019 concerns, noting first \u201cthe typical attorney\u2026does not have the legal and technical expertise to offer effective advice to clients on e-discovery.\u201d<a href=\"#_ftn39\" name=\"_ftnref39\">[37]<\/a> Some of the judges\u2019 comments were quite blunt, with one noting that \u201c[s]ome attorneys are highly competent; but most appear to have significant gaps in their understanding of e-discovery principles.\u201d<a href=\"#_ftn40\" name=\"_ftnref40\">[38]<\/a><\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 Legal ethical rules and related opinions and scholarship provide guidance for what attorney E-Discovery competence should look like. At least one author has made the connection between professional responsibility and technological savoir-faire, noting that:<\/p>\n<p style=\"padding-left: 30px\">There is growing recognition across the country that the practice of law requires some degree of competence in technology. In the forum of litigation, competence in technology necessarily equates with competence in e-discovery. It is only a matter of time before ethics bodies across the nation call for competence in e-discovery.<a href=\"#_ftn41\" name=\"_ftnref41\">[39]<\/a><\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 The opinions of courts and bar associations may carry the most weight, but a number of influential professional and industry groups also have offered useful commentary on technological competence. For example, competence is<\/p>\n<p style=\"padding-left: 30px\">\u2026highlighted in the very first rule of legal ethics, according to the American Bar Association[\u2019s] Rule 1.1 of the ABA Model Rules of Professional Conduct,\u201d which \u201cspecifically recognized the need for technological competence through a significant change in August 2012 that formally notified all lawyers (and specifically those in jurisdictions following the Model Rules) that competency includes current knowledge of the impact of e-Discovery and technology on litigation.<a href=\"#_ftn42\" name=\"_ftnref42\">[40]<\/a><\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 This guidance predated and perhaps presaged a number of state and federal reactions to technology and the impact of these developments on the practice of law, especially within the realm of E-Discovery. Delaware amended its Lawyers\u2019 Rules of Professional Conduct as they related to technology in 2013;<a href=\"#_ftn43\" name=\"_ftnref43\">[41]<\/a> North Carolina<a href=\"#_ftn44\" name=\"_ftnref44\">[42]<\/a> and Pennsylvania<a href=\"#_ftn45\" name=\"_ftnref45\">[43]<\/a> did the same shortly thereafter.<\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 California\u2019s relatively recent Formal Opinion No. 2015-193 (the \u201cCalifornia Opinion\u201d) addresses a number of issues associated with attorney ethical duties vis-\u00e0-vis E-Discovery. Although advisory in nature, the California Opinion states \u201cattorneys have a duty to maintain the skills necessary to integrate legal rules and procedures with \u2018ever-changing technology.\u2019\u201d<a href=\"#_ftn46\" name=\"_ftnref46\">[44]<\/a> That reads broadly, but the California Opinion has been interpreted to indicate that, because E-Discovery arises \u201cin almost every litigation matter, attorneys should have at least a baseline understanding of it.\u201d<a href=\"#_ftn47\" name=\"_ftnref47\">[45]<\/a> Specifically, the California Opinion begins with the premise that E-Discovery requires an initial assessment of its inclusion at the beginning of a matter.<a href=\"#_ftn48\" name=\"_ftnref48\">[46]<\/a> If E-Discovery will be a component of a matter,<\/p>\n<p style=\"padding-left: 30px\">[T]he duty of competence requires an attorney to assess his or her own e-discovery skills and resources as part of the attorney\u2019s duty to provide the client with competent representation. If an attorney lacks such skills and\/or resources, the attorney must try to acquire sufficient learning and skill, or associate or consult with someone with expertise to assist.<a href=\"#_ftn49\" name=\"_ftnref49\">[47]<\/a><\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 Other commentators have noted that the California Opinion focuses on \u201cnine (9) core competency issues\u201d which would offer \u201csolid guidelines for attorneys\u2026to maintain competency and protect client confidentiality in the era of eDiscovery.\u201d<a href=\"#_ftn50\" name=\"_ftnref50\">[48]<\/a> One author notes that one of these core competency issues and its related directive, that of performing data searches, stretches across the entirety of the E-Discovery process \u201coccurring at each of these steps, from preservation and collection to review and redaction.\u201d<a href=\"#_ftn51\" name=\"_ftnref51\">[49]<\/a><\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 Soon after the California Opinion was decided, Magistrate Judge Mitchell Dembin issued a Southern District of California decision that addressed \u201ccounsels\u2019 ethical obligations and expected competency\u201d in <em>HM Electronics, Inc. v. R.F. Technologies, Inc<\/em>.<a href=\"#_ftn52\" name=\"_ftnref52\">[50]<\/a> The <em>HM Electronics<\/em> case focused both on specific steps the attorneys <em>should have<\/em> <em>taken<\/em> (such as implementing a legal hold and doing the legwork necessary to certify discovery responses as true) as well as behavior actively detrimental to the case (instructing client personnel to destroy relevant documents).<a href=\"#_ftn53\" name=\"_ftnref53\">[51]<\/a> Of note in Judge Dembin\u2019s excoriation of the misbehaving attorneys is his statement that \u201ca judge must impose sanctions for a violation of the Rule that was without substantial justification.\u201d<a href=\"#_ftn54\" name=\"_ftnref54\">[52]<\/a> One article suggests that part of the problem may be simply that \u201ccounsel and clients alike\u2026fail to take seriously judges\u2019 expectations for how they conduct themselves throughout the discovery process.\u201d<a href=\"#_ftn55\" name=\"_ftnref55\">[53]<\/a><\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 New York attorneys followed the California Opinion with interest, first noting that it merely presented \u201cthe standard tasks one should engage in and competently execute to properly collect and produce responsive ESI [Electronically Stored Information] to the opposing party.\u201d<a href=\"#_ftn56\" name=\"_ftnref56\">[54]<\/a> A 2009 S.D.N.Y. opinion had chastised attorneys who would otherwise disclaim experience, warning that it was \u201ctime that the Bar\u2014even those lawyers who did not come of age in the computer era\u201d understood E-Discovery technologies and their application.<a href=\"#_ftn57\" name=\"_ftnref57\">[55]<\/a> A recent article indicated that there is \u201can ample basis to discern a framework for ethical obligations, derived from ethics rules, court rules, and sanctions decisions in the e-discovery context\u201d based in part on the history of New York courts as \u201cleaders in the advancement of e-discovery law.\u201d<a href=\"#_ftn58\" name=\"_ftnref58\">[56]<\/a><\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0 But such a \u201cframework for ethical obligations\u201d might not even be necessary where competence is the ethical rule at issue. Competence \u201crequires that lawyers have the legal knowledge, skill, thoroughness, and preparation to conduct the representation, or associate with a lawyer who has such skills\u201d<a href=\"#_ftn59\" name=\"_ftnref59\">[57]<\/a> and that supervision is appropriate to ensure that the work of others \u201cis completed in a competent manner.\u201d<a href=\"#_ftn60\" name=\"_ftnref60\">[58]<\/a> The issue of supervision came up in another advisory opinion, Ethics Opinion 362 of the District of Columbia Bar, which indicated that retaining an e-Discovery vendor that provided all of the E-Discovery services was both impermissible (as the unauthorized practice of law on the part of the vendor) as well as a circumstance where the attorney engaging such a vendor was not absolved from understanding and supervising the work performed, no matter how technical.<a href=\"#_ftn61\" name=\"_ftnref61\">[59]<\/a><\/p>\n<p style=\"padding-left: 90px\"><strong>\u00a0<\/strong><strong>1. Metadata in Electronic Files<\/strong><\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 A very basic threat to client confidentiality (as well as the secrecy of counsel\u2019s strategy) is the existence of metadata embedded in electronic files exchanged between the parties or produced as evidence. Most frequently this threat exists in the form of automatically created information about a file, including changes made to the file, that can be recovered and viewed by a third party if not removed (or \u201cscrubbed\u201d) prior to disclosing the file. This \u201capplication metadata\u201d can include information about the document itself, the author, comments and prior edits, and may also detail when the document was created, viewed, modified, saved or printed.<a href=\"#_ftn62\" name=\"_ftnref62\">[60]<\/a> In addition to the fact that access to metadata can provide opposing parties with everything from revealing insights to damning evidence, there\u2019s also a \u201creal danger\u201d that \u201capplication metadata may be inaccurate.\u201d<a href=\"#_ftn63\" name=\"_ftnref63\">[61]<\/a><\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 Further, disputes related to metadata regularly arise in the E-Discovery context. Indeed, one of the \u201cbiggest challenges in electronic discovery\u201d concerns \u201c[u]nderstanding when metadata is relevant and needs to be preserved and produced.\u201d<a href=\"#_ftn64\" name=\"_ftnref64\">[62]<\/a> To cite just one example, the concurring opinion in <em>State v. Ratcliff<\/em> noted that judges must determine whether submitted evidence contained more than the information visible on the face of the document, or whether metadata was included as well, where the distinction \u201cis critical, both on an ethical and adjudicative basis.\u201d<a href=\"#_ftn65\" name=\"_ftnref65\">[63]<\/a><\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0 Accordingly, understanding and managing metadata has become a baseline requirement for technological competence when dealing with client data and attorney work product. Numerous products exist to help save lawyers from themselves when it comes to accidental disclosure of metadata, including software applications that may be integrated into email programs to prevent documents from being sent outside the network without first passing through a scrubbing filter. And the e-filing portal in many jurisdictions \u201ccontains a warning reminder that it is the responsibility of the e-filer to strip metadata from the electronic file before submitting it through the portal.\u201d<a href=\"#_ftn66\" name=\"_ftnref66\">[64]<\/a> Reliance on these tools, however, may not suffice for long as the sophistication and complexity of issues related to the creation and manipulation of metadata continue to evolve.<\/p>\n<p style=\"text-align: center\"><strong>III. Overview of U.S. Data Privacy and<br \/>\nInformation Security Law<\/strong><\/p>\n<p><strong>\u00a0<\/strong>[29]\u00a0\u00a0\u00a0\u00a0 The sectoral approach to privacy and data security law in the United States often is described as \u201ca patchwork quilt\u201d comprised of numerous state and federal laws and regulations that apply variously to certain types of data, certain industries, the application of particular technologies, or some combination of those elements. These laws may be enforced by a variety of regulators, with state Attorneys General and the Federal Trade Commission often leading the way.<a href=\"#_ftn67\" name=\"_ftnref67\">[65]<\/a> Plaintiffs\u2019 lawyers also are prominent actors in this space, bringing an ever-increasing number of class action and other civil suits alleging violations of privacy rights, data protection laws, and information security standards.<\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0 Although there are no federal or state privacy statutes specifically applicable solely to lawyers, numerous data protection laws and regulations may apply to attorneys in their role as service provider to their clients or in other contexts. The obligations associated with these laws often implicitly or explicitly demand that lawyers handling client data (1)\u00a0have a thorough understanding of the potential privacy and security risks to that data; (2)\u00a0assess and determine how best to secure the data and prevent unauthorized access to the data; and (3)\u00a0supervise anyone acting on their behalf with respect to the data to ensure the data is appropriately protected at all times.<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0 Below we describe a few of the privacy and data security laws that tend to come up frequently for lawyers and impose requirements on their handling of client data that may involve technological competence. This discussion is by no means exhaustive, as technology touches upon virtually every aspect of data protection regulation and information security counseling by attorneys in the field. To provide just a few examples, advising companies on restrictions applicable to cross-border data transfers, data localization requirements, cybersecurity standards and information sharing obligations, and regulatory action around the use of biometrics and geolocation technologies are just a few examples of areas where a lawyer must have an understanding of the underlying technology to effectively assist clients.<\/p>\n<p style=\"padding-left: 30px\"><strong>\u00a0<\/strong><strong>A. \u00a0HIPAA \u2013 Business Associate Agreements<\/strong><\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0 The Health Insurance Portability and Accountability Act of 1996 (\u201cHIPAA\u201d), is the most significant health privacy law in the United States, imposing numerous obligations on \u201ccovered entities\u201d and \u201cbusiness associates\u201d of those \u201ccovered entities\u201d to protect the privacy and security of \u201cprotected health information\u201d (\u201cPHI\u201d).<a href=\"#_ftn68\" name=\"_ftnref68\">[66]<\/a> As required by HIPAA, the Department of Health and Human Services (\u201cHHS\u201d) issued two key sets of regulations to implement the statute: the Privacy Rule<a href=\"#_ftn69\" name=\"_ftnref69\">[67]<\/a> and the Security Rule.<a href=\"#_ftn70\" name=\"_ftnref70\">[68]<\/a><\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0 Although attorneys and law firms are not themselves considered covered entities directly subject to HIPAA\u2019s requirements,<a href=\"#_ftn71\" name=\"_ftnref71\">[69]<\/a> when attorneys obtain PHI from covered entity clients in the course of a representation, the law firm may be subject to certain HIPAA Privacy Rule requirements<a href=\"#_ftn72\" name=\"_ftnref72\">[70]<\/a> in its role as a business associate.<a href=\"#_ftn73\" name=\"_ftnref73\">[71]<\/a> The Privacy Rule and the Security Rule apply to a covered entity\u2019s interactions with third parties (e.g., service providers) that handle PHI on the covered entity\u2019s behalf.<a href=\"#_ftn74\" name=\"_ftnref74\">[72]<\/a> The covered entity\u2019s relationships with these \u201cbusiness associates\u201d are governed by obligatory contracts known as business associate agreements (\u201cBAAs\u201d) that must contain specific terms.<a href=\"#_ftn75\" name=\"_ftnref75\">[73]<\/a> With respect to technological competence specifically, for example, the BAA requires the business associate to implement appropriate safeguards to prevent use or disclosure of PHI other than as provided for by the BAA, and states that the business associate must ensure that any agents\/subcontractors that receive PHI from the business associate also protect the PHI in the same manner. And attorneys who \u201chold HIPAA data or [other PII] may be governed by state or federal law beyond the scope of the proposed rules, which is noted in the new comments\u201d<a href=\"#_ftn76\" name=\"_ftnref76\">[74]<\/a> to ABA Rule 1.6, discussed further below.<\/p>\n<p style=\"padding-left: 30px\"><strong>B. \u00a0GLBA Safeguards Rule Requirements<\/strong><\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0 Pursuant to the Gramm-Leach-Bliley Act (\u201cGLBA\u201d), the primary federal financial privacy law in the United States, various federal agencies promulgated rules and regulations addressing privacy and data security issues.<a href=\"#_ftn77\" name=\"_ftnref77\">[75]<\/a> For example, the Safeguards Rule requires financial institutions to protect security of personally identifiable financial information by maintaining reasonable administrative, technical, and physical safeguards for customer information.<a href=\"#_ftn78\" name=\"_ftnref78\">[76]<\/a> To comply with the Safeguards Rule, a financial institution must develop, implement, and maintain a comprehensive information security program, and that program must address the financial institution\u2019s oversight of service providers that have access to customers\u2019 nonpublic personal information (\u201cNPI\u201d).<a href=\"#_ftn79\" name=\"_ftnref79\">[77]<\/a><\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0 Again, although a law firm is not a financial institution directly subject to the GLBA, when it acts as counsel to a financial institution, GLBA requirements may apply to its handling of NPI received from that client. To the extent a financial institution\u2019s law firm will have access to such NPI in the course of the representation, the financial institution-client must take reasonable steps to ensure the law firm has the ability to safeguard such data prior to disclosing it to the firm, and require the firm to contractually agree (in writing) to safeguard the NPI. Assuming such data will be stored electronically (a safe assumption in virtually all cases), it is incumbent on the law firm to understand the potential data security risks and how to prevent unauthorized access, use, transfer, or other processing of their clients\u2019 NPI.<\/p>\n<p style=\"padding-left: 30px\"><strong>\u00a0<\/strong><strong>C. \u00a0State Data Security Laws<\/strong><\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0 At the state level, there are numerous laws and regulations regarding the protection of personal information (and other types of data) that apply to all entities that maintain such data, including lawyers, law firms, and other legal service providers.<\/p>\n<p>[37]\u00a0\u00a0\u00a0\u00a0 A number of states, such as California, Connecticut, Maryland, Nevada, Oregon, and Texas, have enacted laws that require companies to implement information security measures to protect personal information of residents of the state that the business collects and maintains.<a href=\"#_ftn80\" name=\"_ftnref80\">[78]<\/a> These laws of general application are relevant to attorneys and law firms with respect to the personal information they maintain\u2014both client data and data relating to their employees. Typically, these laws are not overly prescriptive and include obligations to implement and maintain reasonable security policies and procedures to safeguard personal information from unauthorized access, use, modification, disclosure, or destruction (though most do not offer a definition or description of what is meant by \u201creasonable\u201d security). Some laws, such as California\u2019s, impose a requirement to contractually obligate non-affiliated third parties that receive personal information from the business to maintain reasonable security procedures with respect to that data.<a href=\"#_ftn81\" name=\"_ftnref81\">[79]<\/a><\/p>\n<p>[38]\u00a0\u00a0\u00a0\u00a0 Massachusetts was the first state to enact regulations that directed businesses to develop and implement comprehensive, written information security programs (\u201cWISPs\u201d) to protect the personal information of Massachusetts residents.<a href=\"#_ftn82\" name=\"_ftnref82\">[80]<\/a> These regulations apply to all private entities (including law firms) that maintain personal information of Massachusetts residents, including those that do not operate in Massachusetts; they also list a number of minimum standards for the information security program.<a href=\"#_ftn83\" name=\"_ftnref83\">[81]<\/a> The Massachusetts regulations are relatively prescriptive as compared to other similar state laws of this nature, and they include numerous specific technical requirements.<\/p>\n<p>[39]\u00a0\u00a0\u00a0\u00a0 These requirements apply to law firms directly, but they also apply to law firms as service providers to businesses that maintain personal information of Massachusetts residents. A compliant WISP must address the vetting of service providers, and the contract must include provisions obligating the service provider to protect the data.<a href=\"#_ftn84\" name=\"_ftnref84\">[82]<\/a><\/p>\n<p style=\"text-align: center\"><strong>IV. \u00a0Applicable Ethical Rules and Guidance<\/strong><\/p>\n<p>[40]\u00a0\u00a0\u00a0\u00a0 The myth of the Luddite<a href=\"#_ftn85\" name=\"_ftnref85\">[83]<\/a> or caveman<a href=\"#_ftn86\" name=\"_ftnref86\">[84]<\/a> lawyer persists, even if this type of anachronism is, in fact, an ethical violation waiting to happen.<a href=\"#_ftn87\" name=\"_ftnref87\">[85]<\/a> But even attorneys who \u201conly touch a computer under duress, and take comfort in paper files and legal research from actual books\u201d<a href=\"#_ftn88\" name=\"_ftnref88\">[86]<\/a> must deal with technology.<a href=\"#_ftn89\" name=\"_ftnref89\">[87]<\/a> The adequate practice\u2014or perhaps simply \u201cthe practice\u201d of law does not exist without technology, and there is no longer a place for lawyers who simply \u201chope to get to retirement before they need to fully incorporate technology into their lives.\u201d<a href=\"#_ftn90\" name=\"_ftnref90\">[88]<\/a><\/p>\n<p>[41]\u00a0\u00a0\u00a0\u00a0 \u201cReally?\u201d goes the refrain. \u201cWhy can\u2019t I just practice the way I always have, without [insert mangled, vaguely-recognizable technology portmanteau] getting in the way?\u201d<\/p>\n<p>[42]\u00a0\u00a0\u00a0\u00a0 Well, for one thing, to the extent attorneys rely on the protections of privilege to serve their clients, said attorneys must understand how the confidentiality of their communications and work product may be compromised by the technology they use. Technologies introduce complexity that, in turn, may affect privilege\u2014especially when \u201cmany lawyers don\u2019t understand electronic information or have failed to take necessary precautions to protect it.\u201d<a href=\"#_ftn91\" name=\"_ftnref91\">[89]<\/a> But how much understanding, exactly, may be required to competently represent clients in matters concerning E-Discovery, or data security, or even privacy? At many organizations, \u201c[p]rivacy issues get handled by anyone who wants to do them\u201d because the subject matter area is understaffed or ignored.<a href=\"#_ftn92\" name=\"_ftnref92\">[90]<\/a> The key technological issues relevant to E-Discovery versus data privacy may be somewhat different, but the \u201csolutions\u201d companies find are eerily similar: the practitioners that are actually doing the work are often those who have been delegated the work, whose \u201cexpertise\u201d is somewhat home-grown and may, in fact, not really represent true technological competence at all.<a href=\"#_ftn93\" name=\"_ftnref93\">[91]<\/a><\/p>\n<p>[43]\u00a0\u00a0\u00a0\u00a0 What, then, are the requirements for expertise? Perhaps a pragmatic approach is best. Certainly, practitioners who use technology\u2014again, likely all of them\u2014must take some well-defined, initial steps toward acquiring the appropriate skill set. This might be as straightforward as the lawyer familiarizing herself with the relevant technologies at issue. Although it may sound a bit <em>too<\/em> easy, \u201cjust being well-versed enough to understand the issues is a big plus.\u201d<a href=\"#_ftn94\" name=\"_ftnref94\">[92]<\/a> That being said, \u201cthose considering a career in cybersecurity or privacy will need to spend time developing some level of technical expertise.\u201d<a href=\"#_ftn95\" name=\"_ftnref95\">[93]<\/a> In short, the answer is \u201cit depends\u201d and \u201cno one really knows \u2013 yet.\u201d In this relatively new space, actual decisions and definitive standards for \u201ctechnological competence\u201d are thin on the ground. Below we will examine some of the relevant rules and guidelines to consider.<\/p>\n<p style=\"padding-left: 30px\"><strong>\u00a0<\/strong><strong>A. \u00a0Recent Guidelines in the Ethics Rules<\/strong><\/p>\n<p>[44]\u00a0\u00a0\u00a0\u00a0 Most attorneys do not have specialized training focused on a particular technological field. Certainly the vast majority do not hold themselves out as experts in cybersecurity, cloud-based storage, social media, biometrics, or any of a variety of related disciplines. However, even in the absence of expertise, there are some basic ethical rules that provide a framework for determining a practitioner\u2019s professional duties and obligations with regard to technology\u2014specifically, rules pertaining to competent client representation, adequate supervision, confidentiality, and communications.<a href=\"#_ftn96\" name=\"_ftnref96\">[94]<\/a><\/p>\n<p style=\"padding-left: 60px\"><strong>1. \u00a0Competent Client Representation (Model Rule 1.1)<\/strong><\/p>\n<p>[45]\u00a0\u00a0\u00a0\u00a0 As discussed briefly above, almost four years ago, the America Bar Association formally approved a change to the Model Rules of Professional Conduct to establish a clear understanding that lawyers have a duty to be competent not only in the law and its practice, but also with respect to technology. Detailed below, the passage of this rule contemplated changes in technology and eschewed specifics. Rather than a paint-by-numbers approach, ABA Model Rule 1.1 puts the responsibility on attorneys to understand their own\u2014and their clients\u2019\u2014needs, and how new technologies impact their particular practice.<\/p>\n<p>[46]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 1.1 states that:<\/p>\n<p style=\"padding-left: 60px\">A lawyer shall provide competent representation to a client. Competent representation requires legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.<a href=\"#_ftn97\" name=\"_ftnref97\">[95]<\/a><\/p>\n<p>[47]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 1.1 was amended in 2012 by Codified Comment 8 as follows:<\/p>\n<p style=\"padding-left: 60px\">To maintain the requisite knowledge and skills, a lawyer should keep abreast of changes in the law and its practice, <em>including the benefits and risks associated with relevant technology<\/em>, engage in continuing study and education and comply with all continuing legal education requirements to which the lawyer is subject.<a href=\"#_ftn98\" name=\"_ftnref98\">[96]<\/a><\/p>\n<p>[48]\u00a0\u00a0\u00a0\u00a0 Some note that Rule 1.1 \u201cdoes not actually impose any new obligations on lawyers;\u201d<a href=\"#_ftn99\" name=\"_ftnref99\">[97]<\/a> neither does it require perfection.<a href=\"#_ftn100\" name=\"_ftnref100\">[98]<\/a> Instead it \u201csimply reiterates the obvious, particularly for seasoned eDiscovery lawyers, that in order for lawyers to adequately practice, they need to understand the means by which they zealously advocate for their clients.\u201d<a href=\"#_ftn101\" name=\"_ftnref101\">[99]<\/a> One article noted, in fact, that Comment 8 was evidence of \u201cthe ABA\u2019s desire to nudge lawyers into the 21<sup>st<\/sup> century when it comes to technology.\u201d<a href=\"#_ftn102\" name=\"_ftnref102\">[100]<\/a> It did, however, caution that it was \u201ca very gentle nudge.\u201d<a href=\"#_ftn103\" name=\"_ftnref103\">[101]<\/a><\/p>\n<p><strong>\u00a0<\/strong>[49]\u00a0\u00a0\u00a0\u00a0 Nudge or not, that message has resonated across the United States. In the four years since that amendment was approved and adopted by the ABA, twenty-one states since have adopted the ethical duty of technological competence for lawyers.<a href=\"#_ftn104\" name=\"_ftnref104\">[102]<\/a> As for many of the states that have not formally adopted the change to their Model Rules of Professional Conduct, those may still explicitly or implicitly acknowledge this emerging duty to be competent in technology, having a basic understanding of technologies their clients use, and a duty to keep abreast of such changes including a required awareness of regulatory requirements and privacy laws.<a href=\"#_ftn105\" name=\"_ftnref105\">[103]<\/a><\/p>\n<p style=\"padding-left: 60px\"><strong>2. \u00a0Supervision (Model Rules 5.1 and 5.3)<\/strong><\/p>\n<p>[50]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 5.1 also bears on a lawyer\u2019s duties regarding technology insofar as duties aided or supported by technology are performed by someone other than the attorney. This responsibility extends to immediate as well as remote support staff, with ABA Model Rule 5.1 requiring that \u201c[l]awyers must also supervise the work of others to ensure it is completed in a competent manner.\u201d<a href=\"#_ftn106\" name=\"_ftnref106\">[104]<\/a> This attempt at establishing \u201cthe principle of supervisory responsibility without introducing a vicarious liability concept\u201d<a href=\"#_ftn107\" name=\"_ftnref107\">[105]<\/a> has led to considerations regarding inexperience generally,<a href=\"#_ftn108\" name=\"_ftnref108\">[106]<\/a> but the implications for technological applications should be clear\u2014an associate or other paralegal professional is much more likely to use technology to support legal work<a href=\"#_ftn109\" name=\"_ftnref109\">[107]<\/a> than she is to make a representation before a court or like body.<\/p>\n<p>[51]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 5.3 also sets forth responsibilities of partners and supervising attorneys to non-lawyer assistants. This set of ethical considerations further reinforces the responsibilities attorneys have to apply sufficient care in their practice when outsourcing supporting legal work to inexperienced non-professionals, and to ensure that confidentiality is maintained with outsourcing staff.<a href=\"#_ftn110\" name=\"_ftnref110\">[108]<\/a> This is not just a matter of supervising specific tasks. It also contemplates knowing which tasks are appropriate for delegation, both within the firm and to third-party vendors. For example, if a delegate of the attorney uses technology to begin an engagement, it\u2019s possible that such an arrangement could be viewed as \u201cestablish[ing] the attorney-client relationship,\u201d which may be prohibited under ABA Model Rule 5.5.<a href=\"#_ftn111\" name=\"_ftnref111\">[109]<\/a><\/p>\n<p style=\"padding-left: 60px\"><strong>3. \u00a0Duty of Confidentiality (Model Rule 1.6)<\/strong><\/p>\n<p>[52]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 1.6 states that it is critical that lawyers do not reveal confidential or privileged client information.<a href=\"#_ftn112\" name=\"_ftnref112\">[110]<\/a> When information was kept in an attorney\u2019s head, or perhaps committed to a sheet of paper, historical precedent on how to comply with this duty may have been helpful. In the \u201cworld of tomorrow,\u201d<a href=\"#_ftn113\" name=\"_ftnref113\">[111]<\/a> looking to the past for answers makes little sense, especially in those instances where the attorney is unclear as to how information is stored, accessed, maintained, or utilized.<\/p>\n<p>[53]\u00a0\u00a0\u00a0\u00a0 Model Rule 1.6 also considers a duty of confidentiality that resides at the core of every attorney\u2019s role and serves as one of the attorney\u2019s most important ethical responsibilities. Model Rule 1.6 generally defines the duty of confidentiality as follows: \u201cA lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized in order to carry out the representation or the disclosure is permitted [elsewhere].\u201d<a href=\"#_ftn114\" name=\"_ftnref114\">[112]<\/a><\/p>\n<p>[54]\u00a0\u00a0\u00a0\u00a0 This rule is broad. It encompasses any client information, confidential or privileged, shared or accessible to the attorney and is not limited to just confidential communications. Further, it may only be relinquished under the most onerous of circumstances.<a href=\"#_ftn115\" name=\"_ftnref115\"><sup><sup>[113]<\/sup><\/sup><\/a> A lawyer shall not, therefore, reveal information relating to the representation of a client unless the client gives informed consent, the disclosure is impliedly authorized in order to carry out the representation, or the disclosure is permitted elsewhere in the rules.<\/p>\n<p>[55]\u00a0\u00a0\u00a0\u00a0 In 2000, the Advisory Committee looked into its crystal ball and considered ESI on various platforms, in different repositories, in various forms. It then added Comment 18 to Rule 1.6, requiring reasonable precautions to safeguard and preserve confidential information. Comment 18 states that, \u201c[A] lawyer [must] act competently to safeguard information relating to the representation of a client against \u2026 inadvertent or unauthorized disclosure by the lawyer or other persons who are participating in the representation of the client or who are subject to the lawyer\u2019s supervision.\u201d<a href=\"#_ftn116\" name=\"_ftnref116\">[114]<\/a> Indeed, \u201c[p]artners and supervising attorneys are required to take reasonable actions to ensure that those under their supervision comply with these requirements.\u201d<a href=\"#_ftn117\" name=\"_ftnref117\">[115]<\/a><\/p>\n<p>[56]\u00a0\u00a0\u00a0\u00a0 In addition to the ABA\u2019s commentary, state and local professional organizations have issued guidance as well. In establishing a specific roadmap for lawyers to attain the skills necessary to meet their ethical obligations with respect to relevant technology in the practice of law, and returning to the California Bar\u2019s Formal Opinion 2015-193, there is a sort of checklist that may assist lawyers in meeting their ethical obligations to develop and maintain core E-Discovery competence in the following areas:<a href=\"#_ftn118\" name=\"_ftnref118\">[116]<\/a><\/p>\n<ul>\n<li>Initially assessing E-Discovery needs and issues, if any;<\/li>\n<li>Implementing or causing (the client) to implement appropriate ESI preservation procedures, (\u201csuch as circulating litigation holds or suspending auto-delete programs\u201d);<a href=\"#_ftn119\" name=\"_ftnref119\">[117]<\/a><\/li>\n<li>Analyzing and understanding the client\u2019s ESI systems and storage;<\/li>\n<li>Advising the client on available options for collection and preservation of ESI;<\/li>\n<li>Identifying custodians of potentially relevant ESI;<\/li>\n<li>Engaging in competent and meaningful meet and confers with opposing counsel concerning an E-Discovery plan;<\/li>\n<li>Performing data searches;<\/li>\n<li>Collecting responsive ESI in a manner that preserves the integrity of the ESI; and<\/li>\n<li>Producing responsive, non-privileged ESI in a recognized and appropriate manner.<\/li>\n<\/ul>\n<p>[57]\u00a0\u00a0\u00a0\u00a0 But this technological competence inherent in the Duty of Competence represents only one third of the ethical duties that govern an attorney\u2019s interaction with technology. This ESI and litigation skills checklist does <em>not<\/em> address \u201cthe scope of an attorney\u2019s duty of competence relating to obtaining an opposing party\u2019s ESI;\u201d<a href=\"#_ftn120\" name=\"_ftnref120\">[118]<\/a> nor does it consider the skills required of non-litigation attorneys, which must be inferred from the rule.<\/p>\n<p>[58]\u00a0\u00a0\u00a0\u00a0 In addition, the State Bar of California\u2019s Standing Committee on Professional Responsibility and Conduct, Formal Opinion 2010-179 states that \u201c[a]n attorney\u2019s duties of confidentiality and competence require the attorney to take appropriate steps to ensure that his or her use of technology in conjunction with a client\u2019s representations does not subject confidential client information to an undue risk of unauthorized disclosure.\u201d<a href=\"#_ftn121\" name=\"_ftnref121\"><sup><sup>[119]<\/sup><\/sup><\/a><\/p>\n<p>[59]\u00a0\u00a0\u00a0\u00a0 In reference to the duty of confidentiality, the New York County Lawyer\u2019s Association\u2019s Committee on Professional Ethics examined shared computer services amongst practitioners in Opinion 733, noting that an \u201cattorney must diligently preserve the client\u2019s confidences, whether reduced to digital format, paper, or otherwise. The same considerations would also apply to electronic mail and websites to the extent they would be used as vehicles for communications with the attorney\u2019s clients.\u201d<a href=\"#_ftn122\" name=\"_ftnref122\"><sup><sup>[120]<\/sup><\/sup><\/a> The New York State Bar\u2019s Committee on Professional Ethics Opinion 842 further stated that, when \u201ca lawyer is on notice that the [client\u2019s] information\u2026is of \u2018an extraordinarily sensitive nature that it is reasonable to use only a means of communication that is completely under the lawyer\u2019s control,\u2026the lawyer must select a more secure means of communication than unencrypted Internet e-mail.\u2019\u201d<a href=\"#_ftn123\" name=\"_ftnref123\"><sup><sup>[121]<\/sup><\/sup><\/a><strong>\u00a0<\/strong><\/p>\n<p style=\"padding-left: 60px\"><strong>4. \u00a0Communications (Model Rule 1.4)<\/strong><\/p>\n<p>[60]\u00a0\u00a0\u00a0\u00a0 ABA Model Rule 1.4 on Communications also applies to the attorney\u2019s use of technology and requires appropriate communications with clients \u201cabout the means by which the client\u2019s objectives are to be accomplished,\u201d including the use of technology.<a href=\"#_ftn124\" name=\"_ftnref124\">[122]<\/a><\/p>\n<p>[61]\u00a0\u00a0\u00a0\u00a0 In construing all of these Model Rules and comments, it is clear that attorneys who are not tech-must (1) understand their limitations; (2)\u00a0obtain appropriate assistance; (3)\u00a0be aware of the areas in which technology knowledge is essential; and (4)\u00a0evolve to competently handle those challenges; or (5)\u00a0retain the requisite expert assistance. This list applies equally to data security issues, such as being aware of the risks associated with cloud storage, cybersecurity threats, and other sources of potential harm to client data, and can easily be extended to include awareness and understanding with respect to domestic and foreign data privacy issues.<\/p>\n<p>[62]\u00a0\u00a0\u00a0\u00a0 The ethical obligations to safeguard information require reasonable security, not absolute security. Accordingly, under such rules and related guidance from the Proposal from the ABA Commission on Ethics 20\/20,<a href=\"#_ftn125\" name=\"_ftnref125\">[123]<\/a> the factors to be considered in determining the reasonableness of the lawyers\u2019 efforts with respect to security include:<\/p>\n<p style=\"padding-left: 30px\">(1) The sensitivity of the information;<\/p>\n<p style=\"padding-left: 30px\">(2) The likelihood of disclosure if additional safeguards are not employed;<\/p>\n<p style=\"padding-left: 30px\">(3) The cost of employing additional safeguards;<\/p>\n<p style=\"padding-left: 30px\">(4) The difficulty of implementing the safeguards; and<\/p>\n<p style=\"padding-left: 30px\">(5) The extent to which the safeguards adversely affect the lawyer\u2019s ability to represent the client.<a href=\"#_ftn126\" name=\"_ftnref126\">[124]<\/a><\/p>\n<p>As New Jersey Ethics Opinion 701 states, \u201c[r]easonable care however does not mean that the lawyer absolutely and strictly guarantees that the information will be utterly invulnerable against all unauthorized access. Such a guarantee is impossible.\u201d<a href=\"#_ftn127\" name=\"_ftnref127\">[125]<\/a><\/p>\n<p style=\"padding-left: 30px\"><strong>B. \u00a0Ethics and Social Media<\/strong><\/p>\n<p>[63]\u00a0\u00a0\u00a0\u00a0 When considering their ethical duties with respect to technology, lawyers today must confront a host of challenges that would have been almost unimaginable even ten years ago. The rise and proliferation of social media as a daily part of most people\u2019s personal and professional lives has created one such challenge.<a href=\"#_ftn128\" name=\"_ftnref128\"><sup><sup>[126]<\/sup><\/sup><\/a> Numerous courts have addressed\u2014and continue to address\u2014attorney duties with respect to social media in the context of spoliation motions when social media evidence has been lost, destroyed, or obfuscated due to negligence, or in accordance with attorney advice.<a href=\"#_ftn129\" name=\"_ftnref129\">[127]<\/a> In addition, given the novelty and complexity of the issues, and in the interest of consistency, state bar associations have begun to address issues associated with attorney use of, counseling on, and preservation of social media.<\/p>\n<p>[64]\u00a0\u00a0\u00a0\u00a0 The Association of the Bar of the City of New York\u2019s Committee on Professional and Judicial Ethics, in Formal Opinion 2010-2, provided some helpful guidelines on attorney access to social media, stating that \u201c[a] lawyer may not use deception to access information from a social networking webpage,\u201d either directly or through an agent.<a href=\"#_ftn130\" name=\"_ftnref130\">[128]<\/a> While focused on behaviors that attorneys and their agents should not undertake when developing a case, the opinion does note that the \u201cpotential availability of helpful evidence on these internet-based sources makes them an attractive new weapon in a lawyer\u2019s arsenal of formal and informal discovery devices,\u201d and also offers up \u201cthe Court of Appeals\u2019 oft-cited policy in favor of informal discovery.\u201d<a href=\"#_ftn131\" name=\"_ftnref131\">[129]<\/a> Simply put, the duty is twofold: an attorney must both be aware of social media and know how to use social media to provide effective representation.<\/p>\n<p style=\"padding-left: 60px\"><strong>\u00a02. \u00a0<\/strong><strong>State Bar Association Guidance<\/strong><\/p>\n<p>[65]\u00a0\u00a0\u00a0\u00a0 State bar associations are becoming increasingly involved in providing guidance on social media and its implications for the practice of law. For example, in 2014, the New York and Pennsylvania State Bar Associations and the Florida Professional Ethics Committee issued guidance on social media usage by attorneys and addressed the obligations of attorneys to understand how various platforms work, what information will be available to whom, the ethical implications of advising clients to alter or change social media accounts, and the value of ensuring adequate preservation of social media evidence.<\/p>\n<p style=\"padding-left: 120px\"><strong>i. \u00a0New York<\/strong><\/p>\n<p>[66]\u00a0\u00a0\u00a0\u00a0 The Social Media Ethics Guidelines of the Commercial and Federal Litigation Section of the New York State Bar Association provide specific guidance for the use of social media by attorneys.<a href=\"#_ftn132\" name=\"_ftnref132\">[130]<\/a> Guideline 4, relating to the review and use of evidence from social media, is divided into four subparts, all of which provide specific and pertinent guidance to attorneys:<\/p>\n<ul>\n<li>Guideline No. 4.A: Viewing a Public Portion of a Social Media Website, provides that \u201c[a] lawyer may view the public portion of a person\u2019s social media profile or public posts even if such person is represented by another lawyer. However, the lawyer must be aware that certain social media networks may send an automatic message to the person whose account is being viewed which identifies the person viewing the account as well as other information about such person.\u201d<a href=\"#_ftn133\" name=\"_ftnref133\">[131]<\/a><\/li>\n<\/ul>\n<ul>\n<li>Guideline No. 4.B: Contacting an Unrepresented Party to View a Restricted Portion of a Social Media Website, provides that \u201c[a] lawyer may request permission to view the restricted portion of an unrepresented person\u2019s social media website or profile. However, the lawyer must use her full name and an accurate profile, and she may not create a different or false profile to mask her identity. If the person asks for additional information from the lawyer in response to the request that seeks permission to view her social media profile, the lawyer must accurately provide the information requested by the person or withdraw her request.\u201d<a href=\"#_ftn134\" name=\"_ftnref134\">[132]<\/a><\/li>\n<\/ul>\n<ul>\n<li>Guideline No. C: Viewing A Represented Party\u2019s Restricted Social Media Website, provides that \u201c[a] lawyer shall not contact a represented person to seek to review the restricted portion of the person\u2019s social media profile unless an express authorization has been furnished by such person.\u201d<sup><sup><a href=\"#_ftn135\" name=\"_ftnref135\">[133]<\/a><\/sup><\/sup><\/li>\n<\/ul>\n<ul>\n<li>Guideline No. 4.D: Lawyer\u2019s Use of Agents to Contact a Represented Party, \u201cas it relates to viewing a person\u2019s social media account,\u201d provides that \u201c[a] lawyer shall not order or direct an agent to engage in specific conduct, or with knowledge of the specific conduct by such person, ratify it, where such conduct if engaged in by the lawyer would violate any ethics rules.\u201d<a href=\"#_ftn136\" name=\"_ftnref136\">[134]<\/a><\/li>\n<\/ul>\n<p style=\"padding-left: 120px\"><strong>ii. \u00a0Florida<\/strong><\/p>\n<p>[67]\u00a0\u00a0\u00a0\u00a0 In Advisory Opinion 14-1, the Florida Bar Association\u2019s Professional Ethics Committee confirmed that an attorney could advise a client to increase privacy settings (as so to conceal from public eye) and remove information relevant to the foreseeable proceedings from social media as long as an appropriate record was maintained\u2014the data preserved\u2014and no rules or substantive laws regarding preservation and\/or spoliation of evidence were broken.<a href=\"#_ftn137\" name=\"_ftnref137\"><sup><sup>[135]<\/sup><\/sup><\/a><\/p>\n<p style=\"padding-left: 120px\"><strong>iii. Pennsylvania<\/strong><\/p>\n<p>[68]\u00a0\u00a0\u00a0\u00a0 In 2014, the Pennsylvania Bar Association issued a Formal Opinion that included detailed guidance regarding an attorney\u2019s ethical obligations with respect to the use of social media. Among other guidelines, the Opinion specifically stated that:<\/p>\n<ul>\n<li>Attorneys may advise clients about the content of their Social networking websites, including the removal or addition of information;<\/li>\n<li>Attorneys may connect with clients and former clients;<\/li>\n<li>Attorneys may not contact a represented person through social networking websites;<\/li>\n<li>Although attorneys may contact an unrepresented person through social networking websites, they may not use a pretextual basis for viewing otherwise private information on social networking websites; and<\/li>\n<li>Attorneys may use information on social networking websites in a dispute.<a href=\"#_ftn138\" name=\"_ftnref138\">[136]<\/a><\/li>\n<\/ul>\n<p style=\"padding-left: 90px\"><strong>3. \u00a0ABA Model Rule 3.4<\/strong><\/p>\n<p>[69]\u00a0\u00a0\u00a0\u00a0 Finally, although ABA Model Rule 3.4 on Fairness to Opposing Party and Counsel does not directly address social media, the principles behind the rule apply in the social media context. The Rule provides that an attorney shall not \u201cunlawfully obstruct another party\u2019s access to evidence or unlawfully alter, destroy or conceal a document or other material having potential evidentiary value\u201d nor shall the attorney \u201ccounsel or assist another person\u201d to undertake such actions.<a href=\"#_ftn139\" name=\"_ftnref139\">[137]<\/a><\/p>\n<p style=\"padding-left: 30px\"><strong>C. \u00a0Guidance on Duties Related to<\/strong><strong> Cybersecurity <\/strong><\/p>\n<p>[70]\u00a0\u00a0\u00a0\u00a0 As we discussed above in Section II, attorneys face a complex threat landscape when it comes to security concerns related to the protection of their clients\u2019 data.<a href=\"#_ftn140\" name=\"_ftnref140\">[138]<\/a> Although the scope of an attorney\u2019s ethical obligations in this regard remains somewhat unclear, there are several sources of guidance relevant to how lawyers are expected to manage cybersecurity risks.<\/p>\n<p>[71]\u00a0\u00a0\u00a0\u00a0 One such source that squarely addresses the issue is the Resolution issued by the ABA\u2019s Cybersecurity Legal Task Force. The Resolution contains a detailed Report explaining the ABA\u2019s position regarding the growing problem of intrusions into computer networks utilized by lawyers and law firms, and urges lawyers and law firms to review and comply with the provisions relating to the safeguarding of confidential client information.<a href=\"#_ftn141\" name=\"_ftnref141\"><sup><sup>[139]<\/sup><\/sup><\/a> As the ABA noted in its Report, defending the confidentiality of the lawyer-client relationship and preservation of privilege in communications and attorney work product are fundamental to public confidence in the legal system.<a href=\"#_ftn142\" name=\"_ftnref142\">[140]<\/a> Attorneys are directed to (1)\u00a0keep clients reasonably informed as set forth in the Model Rules of Professional Conduct, as amended in August 2012 and adopted in the jurisdictions applicable to their practice; and (2)\u00a0comply with other applicable state, federal, and court rules pertaining to data privacy and cybersecurity.<a href=\"#_ftn143\" name=\"_ftnref143\">[141]<\/a> The ABA further urges the respect and preservation of the attorney client relationship during the pendency of any actions in which a government entity aims to deter, prevent, or punish unauthorized, illegal intrusions into computer systems and networks used by lawyers and law firms.<\/p>\n<p>[72]\u00a0\u00a0\u00a0\u00a0 The comment to ABA Model Rule 5.7 states, perhaps somewhat axiomatically, that when \u201c[a] lawyer performs law-related services or controls an organization that does so, there exists the potential for ethical problems.\u201d<a href=\"#_ftn144\" name=\"_ftnref144\">[142]<\/a> This, combined with Model Rule 1.6\u2019s requirement for attorneys to safeguard and protect client information, suggests further potential duties associated with cybersecurity.<a href=\"#_ftn145\" name=\"_ftnref145\">[143]<\/a> As one author notes<\/p>\n<p style=\"padding-left: 30px\">Fulfillment of a law firm\u2019s duty to maintain client confidences in today\u2019s world of cyberattacks requires much more than legal knowledge and legal skills. It requires sophisticated computer knowledge and skills far beyond legal practice. That is why cybersecurity experts should be used to assist in any law firm\u2019s client\u2019s data protection efforts.<a href=\"#_ftn146\" name=\"_ftnref146\"><sup><sup>[144]<\/sup><\/sup><\/a><\/p>\n<p>Indeed, \u201c[t]raining in security, including cybersecurity should be a part of every lawyer\u2019s education. It is especially important for lawyers who do electronic discovery\u201d.<a href=\"#_ftn147\" name=\"_ftnref147\"><sup><sup>[145]<\/sup><\/sup><\/a><\/p>\n<p>[73]\u00a0\u00a0\u00a0\u00a0 On a related subject, in Formal Opinion 2015-3, the New York City Bar Association issued guidance indicating that lawyers do <em>not <\/em>violate their ethical duties by reporting suspected cybercrime to law enforcement.<a href=\"#_ftn148\" name=\"_ftnref148\">[146]<\/a> If an attorney has performed \u201creasonable diligence\u201d to determine whether a prospective client is actually attempting fraud, the opinion says, then the attorney is free to report.<a href=\"#_ftn149\" name=\"_ftnref149\">[147]<\/a> The Opinion continued, highlighting the lack of duty associated with individuals who are not actually clients, stating that an<\/p>\n<p style=\"padding-left: 30px\">attorney who discovers that is he the target of an Internet-based trust account scam does <em>not<\/em> have a duty of confidentiality to the individual attempting to defraud him, and is free to report the individual to law enforcement authorities, because that person does not qualify as a prospective or actual client of the attorney.<a href=\"#_ftn150\" name=\"_ftnref150\">[148]<\/a><\/p>\n<p style=\"padding-left: 30px;text-align: center\"><strong>V. \u00a0Conclusion<\/strong><\/p>\n<p>[74]\u00a0\u00a0\u00a0\u00a0 It goes without saying that we live (and work) in interesting times. Cloud technology offers convenience, flexibility, cost savings\u2014and a host of potential security issues that existing \u201chard-copy world\u201d rules aren\u2019t fit to address. The details of top-secret corporate transactions are now hashed out on collaborative virtual platforms that may be vulnerable to damage, destruction, or unauthorized access. And the increasing ubiquity of social media makes it ever more likely that lawyers and clients alike may post information without appreciating the potential legal ramifications. New technologies have the capacity to enrich our personal lives and enhance our professional lives, but they also create complex and novel challenges for lawyers already subject to a web of ethical duties concerning competence and confidentiality.<\/p>\n<p>[75]\u00a0\u00a0\u00a0\u00a0 Given the speed with which this dynamic area is changing, the issues raised in this piece may well feel dated within months of publication as the next new product or service revolutionizes another fundamental aspect of human interaction and connectivity. Nevertheless, in this article we have outlined some of the many challenges facing attorneys operating in a threat-laden high-tech landscape, taken a look at the ways in which existing and emerging ethical rules and guidelines may apply to the practice of law in the digital age, and opened a door to further conversation about all of these issues as they continue to evolve.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">*<\/a> Stacey Blaustein is a Senior Attorney &#8211; Corporate Litigation with the IBM Corporation.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">**<\/a> Melinda L. McLellan is Counsel in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p><sup>***<\/sup> James Sherer is Counsel in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[1]<\/a> <em>See <\/em>Roger V. Skalbeck, <em>Computing Efficiencies, Computing Proficiencies and Advanced Legal Technologies<\/em>, Virginia State Bar \u2013 Research Recourses (Oct. 2001), http:\/\/www.vsb.org\/docs\/valawyermagazine\/oct01skalbeck.pdf, <em>archived at <\/em>https:\/\/perma.cc\/8YWX-YAHF.<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[2]<\/a> <em>See <\/em>Ed Finkel, <em>Technology No Longer a \u2018Nice to Learn\u2019 for Attorneys<\/em>, Legal Management, Association of Legal Administrators (Oct. 2014), http:\/\/encoretech.com\/wp-content\/uploads\/2014\/10\/Technology-No-Longer-a-Nice-to-Learn-for-Attorneys_ALA-Legal-Management_Oct2014.pdf, <em>archived at <\/em>https:\/\/perma.cc\/HUT3-672F.<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[3]<\/a> <em>See, e.g.<\/em>, Evan Weinberger, <em>Fintech Boom Prompts Lawyers to Add Tech Know-How<\/em>, Law360 (Sep. 4, 2015, 6:05 PM), http:\/\/www.law360.com\/articles\/692081\/fintech-boom-prompts-lawyers-to-add-tech-know-how, <em>archived at <\/em>https:\/\/perma.cc\/WVE8-UPGP; <em>see also <\/em>Allison O. Van Laningham, <em>Navigating in the Brave New World of E-Discovery: Ethics, Sanctions and Spoliation<\/em>, FDCC Q. 327(Summer 2007), http:\/\/www.thefederation.org\/documents\/V57N4-VanLaningham.pdf, <em>archived at <\/em>https:\/\/perma.cc\/9L48-MPLU.<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[4]<\/a> <em>See <\/em>Frank Strong, <em>Beautiful Minds: 41 Legal Industry Predictions for 2016<\/em>, LexisNexis LawBlog (Dec. 17, 2015), http:\/\/businessoflawblog.com\/2015\/12\/legal-industry-predictions-2016\/, <em>archived at <\/em>http:\/\/perma.cc\/BG5W-R4DB.<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[5]<\/a> To further complicate matters, for attorneys and law firms practicing in the financial technology area such as payment, online lending, bitcoin and other virtual currencies, these lawyers need to be competent in \u201cfintech\u201d, financial technology, another outgrowth of the expertise in technology requirement. <em>See<\/em> Evan Weinberger, <em>Fintech Boom Prompts Lawyers to Add Tech Know-How<\/em>, Law360 (Sep. 4, 2015, 6:05 PM), http:\/\/www.law360.com\/articles\/692081\/fintech-boom-prompts-lawyers-to-add-tech-know-how, <em>archived at <\/em>https:\/\/perma.cc\/L76C-FZRL.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[6]<\/a> <em>See infra <\/em>Part III (explaining that agencies such as the FDA have issued guidance in their arena- Postmarket Management of Cybersecurity in Medical Devices).<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[7]<\/a> Report to the House of Delegates, ABA Cybersecurity Legal Task Force Section of Sci. &amp; Tech. Law 1, http:\/\/www.americanbar.org\/content\/dam\/aba\/administrative\/house_of_delegates\/resolutions\/2014_hod_annual_meeting_109.authcheckdam.pdf, <em>archived at<\/em> https:\/\/perma.cc\/KQT3-AFAJ.<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[8]<\/a> Ellen Rosen, <em>Most Big Firms Have Had Some Hacking: Business of Law<\/em>, Bloomberg (Mar. 11, 2015, 12:01 AM), http:\/\/www.bloomberg.com\/news\/articles\/2015-03-11\/most-big-firms-have-had-some-form-of-hacking-business-of-law, <em>archived at<\/em> https:\/\/perma.cc\/YDR6-ZUV8.<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[9]<\/a> <em>See <\/em>Melissa Maleske, <em>A Soft Target for Hacks, Law Firms Must Step Up Data Security<\/em>, Law360 (Sep. 23, 2015, 10:09 PM), http:\/\/www.law360.com\/articles\/706312\/a-soft-target-for-hacks-law-firms-must-step-up-data-security, <em>archived at<\/em> https:\/\/perma.cc\/6V7K-2WB4.<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[10]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[11]<\/a> <em>See <\/em>Susan Hansen, <em>Cyber Attacks Upend Attorney-Client Privilege<\/em>, Bloomberg Businessweek (Mar. 19, 2015, 2:56 PM), http:\/\/www.bloomberg.com\/news\/articles\/2015-03-19\/cyber-attacks-force-law-firms-to-improve-data-security, <em>archived at<\/em> https:\/\/perma.cc\/29A5-MUNG.<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[12]<\/a> <em>See<\/em> Rosen, <em>supra<\/em> note 8.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[13]<\/a> <em>Id.<\/em><\/p>\n<p>[14] Mark Wolski, <em>Report: Legal Industry Was Heavily Targeted with Cyber Threats in January<\/em>, Bloomberg BNA (Mar. 9, 2016), https:\/\/bol.bna.com\/report-legal-industry-was-heavily-targeted-with-cyber-threats-in-january, <em>archived at<\/em> https:\/\/perma.cc\/ZCR9-2WRX.<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[15]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[16]<\/a> James Risen &amp; Laura Poitras, <em>Spying by N.S.A. Ally Entangled U.S. Law Firm<\/em>, N.Y. Times, Feb. 15, 2014, http:\/\/www.nytimes.com\/2014\/02\/16\/us\/eavesdropping-ensnared-american-law-firm.html, <em>archived at<\/em> https:\/\/perma.cc\/F8M4-TEQ7.<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[17]<\/a> <em>See<\/em> Rosen, <em>supra<\/em> note 8.<\/p>\n<p>[18] <em>See <\/em>Hansen, <em>supra<\/em> note 11.<\/p>\n<p>[19] Blake Edwards, <em>Verizon GC: Law Firms Prime Targets for Hackers<\/em>, Bloomberg BNA (Feb. 4, 2016), https:\/\/bol.bna.com\/verizon-gc-law-firms-are-prime-targets-for-hackers\/, <em>archived at <\/em>https:\/\/perma.cc\/F6WU-N6FW.<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[20]<\/a> Strong, <em>supra<\/em> note 4.<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[21]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[22]<\/a> Matthew Goldstein, <em>Law Firms Are Pressed on Security for Data<\/em>, N.Y. Times (Mar. 26, 2014), http:\/\/dealbook.nytimes.com\/2014\/03\/26\/law-firms-scrutinized-as-hacking-increases\/, <em>archived at <\/em>https:\/\/perma.cc\/Q77A-8BN3.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[23]<\/a> <em>See <\/em>N.Y. City Bar Comm. on Small Law Firms, The Cloud and the Small Law Firm: Business, Ethics and Privilege Considerations 2 (Nov. 2013), http:\/\/www2.nycbar.org\/pdf\/report\/uploads\/20072378-TheCloudandtheSmallLawFirm.pdf, <em>archived at<\/em> https:\/\/perma.cc\/A8EG-AH7E.<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[24]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[25]<\/a> Strong, <em>supra<\/em> note 4.<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[26]<\/a> Patrick Mohan &amp; Steve Krause, <em>Up in the Cloud: Ethical Issues that Arise in the Age of Cloud Computing<\/em>, 8 ABI Ethics Comm. News L. 1 (Feb. 2011), http:\/\/www.davispolk.com\/sites\/default\/files\/files\/Publication\/a2e048ea-3b12-45fe-a639-9fc2881a4db8\/Preview\/PublicationAttachment\/0f8af440-1db0-4936-8d0d-a1937a0e6c8f\/skrause.ethics.clouds.feb11.pdf, <em>archived at<\/em> https:\/\/perma.cc\/SW3C-FYT5.<\/p>\n<p><a href=\"#_ftnref29\" name=\"_ftn29\">[27]<\/a> Sharon D. Nelson &amp; John W. Simek, <em>Why Do Lawyers Resist Ethical Rules Requiring Competence with Technology?<\/em>, Slaw (Mar. 27, 2015), http:\/\/www.slaw.ca\/2015\/03\/27\/why-do-lawyers-resist-ethical-rules-requiring-competence-with-technology\/, <em>archived at<\/em> https:\/\/perma.cc\/6HNN-UCDZ.<\/p>\n<p>[28] Ed Finkel, <em>Technology No Longer a \u2018Nice to Learn\u2019 for Attorneys<\/em>, Legal Management, Association of Legal Administrators (Oct. 2014) http:\/\/encoretech.com\/wp-content\/uploads\/2014\/10\/Technology-No-Longer-a-Nice-to-Learn-for-Attorneys_ALA-Legal-Management_Oct2014.pdf, <em>archived at<\/em> https:\/\/perma.cc\/TW7N-4WP5.<\/p>\n<p><a href=\"#_ftnref31\" name=\"_ftn31\">[29]<\/a> Leslie Pappas, <em>The Security Concerns Holding Up One Firm\u2019s Cloud Usage<\/em>, Bloomberg BNA (Jan. 22, 2016), https:\/\/bol.bna.com\/the-security-concerns-holding-up-one-firms-cloud-usage\/, <em>archived at<\/em> https:\/\/perma.cc\/Z4LJ-H83Q.<\/p>\n<p><a href=\"#_ftnref32\" name=\"_ftn32\">[30]<\/a> <em>See <\/em>Casey C. Sullivan, <em>Is It Time for a Law Firm Cloud Computing Security Standard?<\/em>, FindLaw (Feb. 18, 2016), http:\/\/blogs.findlaw.com\/technologist\/2016\/02\/is-it-time-for-a-law-firm-cloud-computing-security-standard.html, <em>archived at<\/em> https:\/\/perma.cc\/78HF-KKX4.<\/p>\n<p><a href=\"#_ftnref33\" name=\"_ftn33\">[31]<\/a> <em>See <\/em>Jonathan R. Tung, <em>Survey: Law Departments Are Warming Up to the Cloud<\/em>, FindLaw (Feb. 18, 2016), http:\/\/blogs.findlaw.com\/in_house\/2016\/02\/survey-law-depts-are-warming-up-to-the-cloud.html, <em>available at<\/em> https:\/\/perma.cc\/M89M-LC3M.<\/p>\n<p><a href=\"#_ftnref34\" name=\"_ftn34\">[32]<\/a> Strong, <em>supra<\/em> note 4.<\/p>\n<p><a href=\"#_ftnref35\" name=\"_ftn35\">[33]<\/a> N.Y. State Bar Ass\u2019n Comm. on Prof\u2019l Ethics, Op. 1020 (Sept. 12, 2014), http:\/\/www.nysba.org\/CustomTemplates\/Content.aspx?id=52001, <em>archived at<\/em> https:\/\/perma.cc\/8MPU-62BR.<\/p>\n<p><a href=\"#_ftnref36\" name=\"_ftn36\">[34]<\/a> N.J. Advisory Comm. on Prof\u2019l Ethics, Op. 701 (2006), https:\/\/www.judiciary.state.nj.us\/notices\/ethics\/ACPE_Opinion701_ElectronicStorage_12022005.pdf, <em>archived at<\/em> https:\/\/perma.cc\/2H5Y-UYWX.<\/p>\n<p><a href=\"#_ftnref37\" name=\"_ftn37\">[35]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref39\" name=\"_ftn39\">[37]<\/a> Aebra Coe, <em>Judges Lack Faith in Attys\u2019 E-Discovery Skills, Survey Says<\/em>, Law360 (Jan. 28, 2016), http:\/\/www.law360.com\/articles\/751961\/judges-lack-faith-in-attys-e-discovery-skills-survey-says, <em>archived at<\/em> https:\/\/perma.cc\/5UJB-D2YX.<\/p>\n<p><a href=\"#_ftnref40\" name=\"_ftn40\">[38]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref41\" name=\"_ftn41\">[39]<\/a> Bob Ambrogi, <em>California Considers Ethical Duty to Be Competent in E-Discovery<\/em>, Catalyst Blog (Feb. 27, 2015), http:\/\/www.catalystsecure.com\/blog\/2015\/02\/california-considers-ethical-duty-to-be-competent-in-e-discovery\/, <em>archived at<\/em> https:\/\/perma.cc\/2FXD-8KM4.<\/p>\n<p><a href=\"#_ftnref42\" name=\"_ftn42\">[40]<\/a> Karin S. Jenson, Coleman W. Watson &amp; James A. Sherer, <em>Ethics, Technology, and Attorney Competence<\/em>, The Advanced eDiscovery Inst. (Nov. 2014), http:\/\/www.law.georgetown.edu\/cle\/materials\/eDiscovery\/2014\/frimorndocs\/EthicsIneDiscoveryBakerHostetler.pdf, <em>archived at<\/em> https:\/\/perma.cc\/TFR6-VZNG.<\/p>\n<p><a href=\"#_ftnref43\" name=\"_ftn43\">[41]<\/a> <em>See<\/em> Order Amending Rules 1.0, 1.1, 1.4, 1.6, 1.17, 1.18, 4.4, 5.3, 5.5, 7.1, 7.2, and 7.3 of the Delaware Lawyers&#8217; Rules of Professional Conduct, Del. R. Prof&#8217;l Conduct (2013), http:\/\/courts.delaware.gov\/rules\/pdf\/dlrpc2013rulechange.pdf.<\/p>\n<p><a href=\"#_ftnref44\" name=\"_ftn44\">[42]<\/a> <em>See<\/em> N.C. State. Bar Rules of Prof&#8217;l Responsibility &amp; Conduct R. 1.1 (2014), http:\/\/www.ncbar.com\/rules\/rules.asp?page=4, <em>archived at <\/em>https:\/\/perma.cc\/7R44-4JAG.<\/p>\n<p><a href=\"#_ftnref45\" name=\"_ftn45\">[43]<\/a> <em>See<\/em> Notice of Proposed Rulemaking, 43 Pa. Bull. 1997 (Apr. 13, 2013), http:\/\/www.pa bulletin.com\/secure\/data\/vol43\/43-15\/652.html, <em>archived at<\/em> https:\/\/perma.cc\/WS5G-MHKQ.<\/p>\n<p><a href=\"#_ftnref46\" name=\"_ftn46\">[44]<\/a> Bob Ambrogi, <em>California Finalizes Ethics Opinion Requiring Competence in E-Discovery<\/em>, Catalyst Blog (Aug. 6, 2015), https:\/\/www.catalystsecure.com\/blog\/2015\/08\/california-finalizes-ethics-opinion-requiring-competence-in-e-discovery\/, <em>archived at <\/em>https:\/\/perma.cc\/V7NV-QCWW.<\/p>\n<p><a href=\"#_ftnref47\" name=\"_ftn47\">[45]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref48\" name=\"_ftn48\">[46]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref49\" name=\"_ftn49\">[47]<\/a> State Bar of Cal. Standing Comm. on Prof&#8217;l Responsibility &amp; Conduct, Formal Op. 2015-193 (2015), https:\/\/ethics.calbar.ca.gov\/Portals\/9\/documents\/Opinions\/CAL%202015-193%20%5B11-0004%5D%20(06-30-15)%20-%20FINAL.pdf, <em>archived at<\/em> https:\/\/perma.cc\/8GWJ-BVJ2.<\/p>\n<p><a href=\"#_ftnref50\" name=\"_ftn50\">[48]<\/a> Adam Kuhn, <em>The California eDiscovery Ethics Opinion: 9 Steps to Competency<\/em>, Recommind Blog (Aug. 11, 2015), http:\/\/www.recommind.com\/blog\/california-ediscovery-ethics-opinion-9-steps-to-competency, <em>archived at<\/em> https:\/\/perma.cc\/2X2K-FCRQ.<\/p>\n<p><a href=\"#_ftnref51\" name=\"_ftn51\">[49]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref52\" name=\"_ftn52\">[50]<\/a> H. Christopher Boehning &amp; Daniel J. Toal, <em>E-Discovery Competence of Counsel Criticized in Sanctions Decision<\/em>, New York Law Journal (Oct. 6, 2015), http:\/\/www.newyorklawjournal.com\/id=1202738840840\/EDiscovery-Competence-of-Counsel-Criticized-in-Sanctions-Decision#ixzz42wNK34Ms, <em>archived at<\/em> https:\/\/perma.cc\/4BMP-T76U.<\/p>\n<p><a href=\"#_ftnref53\" name=\"_ftn53\">[51]<\/a> <em>See generally<\/em> HM Elecs., Inc. v. R.F. Techs., Inc., 2015 U.S. Dist. LEXIS 104100 (S.D. Cal. Aug. 7, 2015) (arguing the invalidity of the steps that the defendants took in order to certify discovery as true).<\/p>\n<p><a href=\"#_ftnref54\" name=\"_ftn54\">[52]<\/a> Boehning &amp; Toal, <em>supra<\/em> n. 50.<\/p>\n<p><a href=\"#_ftnref55\" name=\"_ftn55\">[53]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref56\" name=\"_ftn56\">[54]<\/a> Samantha V. Ettari &amp; Noah Hertz-Bunzl, <em>Ethical E-Discovery: Core Competencies for New York Lawyers<\/em>, New York Law Journal (Nov. 2, 2015), http:\/\/www.kramerlevin.com\/files\/Publication\/60607051-f018-43b7-8a3c-7d43b4ff6e50\/Presentation\/PublicationAttachment\/1e570a52-e27d-425f-a75b-9e25811df796\/NYLJ%20Article-EDiscovery%2011.2.15.pdf, <em>archived at<\/em> https:\/\/perma.cc\/F3R8-UWM6.<\/p>\n<p><a href=\"#_ftnref57\" name=\"_ftn57\">[55]<\/a> William A. Gross Constr. Assocs., Inc. v. Am. Mfrs. Mut. Ins. Co., 256 F.R.D. 134, 136 (S.D.N.Y. 2009).<\/p>\n<p><a href=\"#_ftnref58\" name=\"_ftn58\">[56]<\/a> <em>See<\/em> Ettari &amp; Hertz-Bunzl, <em>supra<\/em> n. 54.<\/p>\n<p><a href=\"#_ftnref59\" name=\"_ftn59\">[57]<\/a> <em>See<\/em> Ettari &amp; Hertz-Bunzl, <em>supra<\/em> n. 54 (citing New York Rules of Professional Conduct (N.Y. Rule) 1.1.5).<\/p>\n<p><a href=\"#_ftnref60\" name=\"_ftn60\">[58]<\/a> <em>See<\/em> Ettari &amp; Hertz-Bunzl, <em>supra<\/em> n. 54 (citing N.Y. Rule 5.1(c)).<\/p>\n<p><a href=\"#_ftnref61\" name=\"_ftn61\">[59]<\/a> <em>See generally<\/em> D.C. Comm. on Legal Ethics, Formal Op. 362 (2012), https:\/\/www.dcbar.org\/bar-resources\/legal-ethics\/opinions\/opinion362.cfm, <em>archived at<\/em> https:\/\/perma.cc\/TXA5-26ZG (discussing the permissibility of non-lawyer ownership of discovery service vendors).<\/p>\n<p><a href=\"#_ftnref62\" name=\"_ftn62\">[60]<\/a> <em>See generally<\/em> The Sedona Conference Working Group, <em>Best Practices Recommendations &amp; Principles for Addressing Electronic Document Production<\/em>, The Sedona Principles: Second Edition, June 2007, at 60, 61 https:\/\/thesedonaconference.org\/publication\/The%20Sedona%20Principles, <em>archived at<\/em> https:\/\/perma.cc\/UU5K-V8KQ (explaining the composition and functionality of metadata).<\/p>\n<p><a href=\"#_ftnref63\" name=\"_ftn63\">[61]<\/a> <em>Id. <\/em>at 4.<\/p>\n<p><a href=\"#_ftnref64\" name=\"_ftn64\">[62]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref65\" name=\"_ftn65\">[63]<\/a> State v. Ratcliff, 849 N.W.2d 183, 196 (N.D. 2014).<\/p>\n<p><a href=\"#_ftnref66\" name=\"_ftn66\">[64]<\/a> <em>See <\/em>Christian Dodd, <em>Metadata 101 for Lawyers: A 2-Minute Primer<\/em>, Law360 (Oct. 15, 2015, 4:30 PM), http:\/\/www.law360.com\/articles\/712714\/metadata-101-for-lawyers-a-2-minute-primer, <em>archived at <\/em>https:\/\/perma.cc\/3VCT-TJRB.<\/p>\n<p><a href=\"#_ftnref67\" name=\"_ftn67\">[65]<\/a> <em>See <\/em>Daniel J. Solove &amp; Woodrow Hartzog, <em>The FTC and the New Common Law of Privacy<\/em>, 114 Colum. L. Rev. 583, 587 (2014).<\/p>\n<p><a href=\"#_ftnref68\" name=\"_ftn68\">[66]<\/a><em>See <\/em>Health Insurance Portability and Accountability Act of 1996 (HIPAA), 42 U.S.C. \u00a7\u00a71320d to 1320d-8 (2007) [hereinafter HIPAA].<\/p>\n<p>[67] <em>See <\/em>Standards for Privacy of Individually Identifiable Health Information, 65 Fed. Reg. 82,462 (Dec. 28, 2000) (codified at 45 C.F.R. pts. 160, 164).<\/p>\n<p><a href=\"#_ftnref70\" name=\"_ftn70\">[68]<\/a> <em>See <\/em>Security Standards, 68 Fed. Reg. 8333, 8334 (Feb. 20, 2003) (codified at 45 C.F.R. pts. 160, 162, 164).<\/p>\n<p><a href=\"#_ftnref71\" name=\"_ftn71\">[69]<\/a> The health plan within an organization, such as a law firm\u2019s employee health plan, may itself be a \u201ccovered entity\u201d for HIPAA compliance purposes, but a firm generally is not, itself, a covered entity. <em>See, e.g.<\/em>, HIPAA, <em>supra<\/em> note 66.<\/p>\n<p><a href=\"#_ftnref72\" name=\"_ftn72\">[70]<\/a> <em>See <\/em>John V. Arnold, <em>PRIVACY: What Lawyers Must Do to Comply with HIPAA<\/em>, 50 Tenn. B.J. 16, 17 (Mar. 2014).<\/p>\n<p><a href=\"#_ftnref73\" name=\"_ftn73\">[71]<\/a> <em>See <\/em>Lisa J. Acevedo et. al., <em>New HIPAA Liability for Lawyers<\/em>, 30 GPSolo, no. 4, 2013, http:\/\/www.americanbar.org\/publications\/gp_solo\/2013\/july_august\/new_hipaa_liability_lawyers.html, <em>archived at <\/em>https:\/\/perma.cc\/F88Y-U928.<\/p>\n<p><a href=\"#_ftnref74\" name=\"_ftn74\">[72]<\/a> <em>See <\/em>Standards for Privacy of Individually Identifiable Health Information, <em>supra <\/em>note 67; <em>see <\/em>Security Standards, <em>supra<\/em> note 68.<\/p>\n<p><a href=\"#_ftnref75\" name=\"_ftn75\">[73]<\/a> Both the Privacy Rule and the Security Rule dictate certain terms that must be included in a BAA.<\/p>\n<p><a href=\"#_ftnref76\" name=\"_ftn76\">[74]<\/a> <em>See<\/em> Nelson &amp; Simek, <em>supra<\/em> note 27.<\/p>\n<p><a href=\"#_ftnref77\" name=\"_ftn77\">[75]<\/a> <em>See<\/em> 15 U.S.C. \u00a7\u00a7 6801\u20136809 (2012).<\/p>\n<p><a href=\"#_ftnref78\" name=\"_ftn78\">[76]<\/a> <em>See<\/em> 16 C.F.R. \u00a7\u00a7 314.2, 314.3(b).<\/p>\n<p><a href=\"#_ftnref79\" name=\"_ftn79\">[77]<\/a> <em>See<\/em> 16 C.F.R. \u00a7 314.4(a-c).<\/p>\n<p><a href=\"#_ftnref80\" name=\"_ftn80\">[78]<\/a> <em>See, e.g.<\/em>, Cal. Civ. Code \u00a7 1798.81.5 (Deering 2009); Conn. Gen. Stat. \u00a7 42-471 (2010); Md. Code Ann., Com. Law \u00a7\u00a7 14-3501 to 14-3503 (LexisNexis 2009); Nev. Rev. Stat. \u00a7 603A.210 (2009); Or. Rev. Stat. \u00a7 646A.622 (2009); Tex. Bus. &amp; Com. Code Ann. \u00a7\u00a7 72.001\u201372.051 (West 2009).<\/p>\n<p><a href=\"#_ftnref81\" name=\"_ftn81\">[79]<\/a> <em>See <\/em>Cal. Civ. Code \u00a7 1798.81.5 (Deering 2009).<\/p>\n<p><a href=\"#_ftnref82\" name=\"_ftn82\">[80]<\/a> <em>See <\/em>201 Mass. Code Regs. 17.01\u201317.05 (2008).<\/p>\n<p><a href=\"#_ftnref83\" name=\"_ftn83\">[81]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref84\" name=\"_ftn84\">[82]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref85\" name=\"_ftn85\">[83]<\/a> <em>See<\/em> Debra Cassens Weiss, <em>Lawyers Have Duty to Stay Current on Technology\u2019s Risks and Benefits<\/em>, <em>New Model Ethics Comment Says<\/em>, ABA Journal Law News (Aug. 6, 2012, 7:46 PM)<\/p>\n<p>http:\/\/www.abajournal.com\/news\/article\/lawyers_have_duty_to_stay_current_on_technologys_risks_and_benefits\/, <em>archived at <\/em>https:\/\/perma.cc\/WPZ4-2DYH.<\/p>\n<p><a href=\"#_ftnref86\" name=\"_ftn86\">[84]<\/a> <em>See Unfrozen Caveman Lawyer<\/em>, Saturday Night Live Transcripts, http:\/\/snltranscripts.jt.org\/91\/91gcaveman.phtml, <em>archived at<\/em> https:\/\/perma.cc\/M7GB-DGJZ (\u201cSometimes when I get a message on my fax machine, I wonder: \u2018Did little demons get inside and type it?\u2019 I don\u2019t know! My primitive mind can\u2019t grasp these concepts.\u201d) (last visited Apr. 5, 2016).<\/p>\n<p><a href=\"#_ftnref87\" name=\"_ftn87\">[85]<\/a> <em>See <\/em>Megan Zavieh, <em>Luddite Lawyers Are Ethical Violations Waiting to Happen<\/em>, Lawyerist.com (last updated July 10, 2015), https:\/\/lawyerist.com\/71071\/luddite-lawyers-ethical-violations-waiting-happen\/, <em>archived at <\/em>https:\/\/perma.cc\/6V4W-94J7.<\/p>\n<p><a href=\"#_ftnref88\" name=\"_ftn88\">[86]<\/a> Lois D. Mermelstein, <em>Ethics Update: Lawyers Must Keep Up with Technology Too, American Bar Association \u2013 Business Law Today<\/em>, Business Law Today (Mar. 2013), http:\/\/www.americanbar.org\/publications\/blt\/2013\/03\/keeping_current.html, <em>archived at <\/em>https:\/\/perma.cc\/T8CF-ZWND.<\/p>\n<p><a href=\"#_ftnref89\" name=\"_ftn89\">[87]<\/a> <em>See <\/em>Blair Janis, <em>How Technology Is Changing the Practice Of Law<\/em>, GP Solo, http:\/\/www.americanbar.org\/publications\/gp_solo\/2014\/may_june\/how_technology_changing_practice_law.html, <em>archived at <\/em>https:\/\/perma.cc\/23P5-PGM7 (last visited Apr. 5, 2016).<\/p>\n<p><a href=\"#_ftnref90\" name=\"_ftn90\">[88]<\/a> Kevin O\u2019Keefe, <em>We Need Laws Requiring Lawyers to Stay Abreast of Technology? <\/em>LEXBLOG: Ethics &amp; Blogging Law (Mar. 28, 2015), http:\/\/kevin.lexblog.com\/2015\/03\/28\/we-need-laws-requiring-lawyers-to-stay-abreast-of-technology\/, <em>archived at <\/em>https:\/\/perma.cc\/8DR5-XK43.<\/p>\n<p><a href=\"#_ftnref91\" name=\"_ftn91\">[89]<\/a> <em>Attorney-client Privilege: Technological Changes Bring Changing Responsibilities for Attorneys and Legal Departments, <\/em>Corporate Law Advisory, http:\/\/www.lexisnexis.com\/communities\/corporatecounselnewsletter\/b\/newsletter\/archive\/2014\/01\/06\/attorney-client-privilege-technological-changes-bring-changing-responsibilities-for-attorneys-and-legal-departments.aspx, <em>archived at <\/em>https:\/\/perma.cc\/XQ53-P3MF (last visited Apr. 5, 2016).<\/p>\n<p>[90] Daniel Solove, <em>Starting a Privacy Law Career<\/em>, LinkedIn Pulse (Aug. 27, 2013), https:\/\/www.linkedin.com\/pulse\/20130827061558-2259773-starting-a-privacy-law-career?forceNoSplash=true, <em>archived at <\/em>https:\/\/perma.cc\/G78L-DM2X.<\/p>\n<p><a href=\"#_ftnref93\" name=\"_ftn93\">[91]<\/a> <em>See <\/em>Peter Geraghty &amp; Sue Michmerhuizen, <em>Think Twice Before You Call Yourself an Expert<\/em>, Your ABA (Mar. 2013), http:\/\/www.americanbar.org\/newsletter\/publications\/youraba\/201303article11.html, <em>archived at <\/em>https:\/\/perma.cc\/HJK7-RSLG .<\/p>\n<p><a href=\"#_ftnref94\" name=\"_ftn94\">[92]<\/a> Solove, <em>supra<\/em> note 90.<\/p>\n<p><a href=\"#_ftnref95\" name=\"_ftn95\">[93]<\/a> Alysa Pfeiffer-Austin, <em>Four Practical Tips to Succeed in the Cybersecurity and Privacy Law Market<\/em>, ABA Security Law (Dec. 9, 2015), http:\/\/abaforlawstudents.com\/2015\/12\/09\/four-practical-tips-to-succeed-in-the-cybersecurity-and-privacy-law-market\/, <em>archived at<\/em> https:\/\/perma.cc\/AH9A-JCTU.<\/p>\n<p><a href=\"#_ftnref96\" name=\"_ftn96\">[94]<\/a> <em>See <\/em>David G. Ries, <em>Cybersecurity for Attorneys: Understanding the Ethical Obligations<\/em>, Law Practice Today (Mar. 2012), http:\/\/www.americanbar.org\/publications\/law_practice_today_home\/law_practice_today_archive\/march12\/cyber-security-for-attorneys-understanding-the-ethical-obligations.html, <em>archived at <\/em>https:\/\/perma.cc\/N4VM-N4NG.<\/p>\n<p><a href=\"#_ftnref97\" name=\"_ftn97\">[95]<\/a> Model Rules of Prof\u2019l Conduct R. 1.1 (2014).<\/p>\n<p><a href=\"#_ftnref98\" name=\"_ftn98\">[96]<\/a> Model Rules of Prof\u2019l Conduct R. 1.1 cmt. 8 (2014) (emphasis added).<\/p>\n<p><a href=\"#_ftnref99\" name=\"_ftn99\">[97]<\/a> Jenson, Watson &amp; Sherer, <em>supra<\/em> note 40, at 2.<\/p>\n<p><a href=\"#_ftnref100\" name=\"_ftn100\">[98]<\/a> <em>See <\/em>James Podgers, <em>You Don\u2019t Need Perfect Tech Knowhow for Ethics\u2019 Sake\u2014But a Reasonable Grasp Is Essential<\/em>, ABA Journal (Aug. 9, 2014), http:\/\/www.abajournal.com\/news\/article\/you_dont_need_perfect_tech_knowhow_for_ethics_sake&#8211;but_a_reasonable_grasp, <em>archived at<\/em> https:\/\/perma.cc\/CB3P-R7YL.<\/p>\n<p><a href=\"#_ftnref101\" name=\"_ftn101\">[99]<\/a> Jenson, Watson &amp; Sherer, <em>supra<\/em> note 40, at 2.<\/p>\n<p><a href=\"#_ftnref102\" name=\"_ftn102\">[100]<\/a> Kelly H. Twigger, Symposium, <em>Ethics in Technology and eDiscovery \u2013 Stuff You Know, but Aren\u2019t Thinking About<\/em>, Ark. L. Rev. (Oct. 16, 2014), http:\/\/law.uark.edu\/documents\/2014\/10\/TWIGGER-Ethics-in-Technology-and-eDiscovery.pdf, <em>archived at<\/em> https:\/\/perma.cc\/LTG8-7AYU.<\/p>\n<p><a href=\"#_ftnref103\" name=\"_ftn103\">[101]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref104\" name=\"_ftn104\">[102]<\/a> These states are: Arizona, Arkansas, Connecticut, Delaware, Idaho, Illinois, Iowa, Kansas, Massachusetts, Minnesota, Nebraska, New Hampshire, New Mexico, New York, North Carolina, Ohio, Pennsylvania, Utah, Virginia, West Virginia, and Wyoming. <em>See <\/em>Robert Ambrogi, <em>20 States Have Adopted Ethical Duty of Technological Competence<\/em>, Law Sites (Mar. 16, 2015), http:\/\/www.lawsitesblog.com\/2015\/03\/11-states-have-adopted-ethical-duty-of-technology-competence.html, <em>archived at <\/em>https:\/\/perma.cc\/B5TF-D6NJ (last updated Dec. 23, 2015) (listing 20 states not including Nebraska); <em>see also Basic Technology Competence for Lawyers<\/em>, Event Details, Nebraska Bar Assoc. (Apr. 6, 2016), https:\/\/nebar.site-ym.com\/events\/EventDetails.aspx?id=788239&amp;group=, <em>archived at<\/em> https:\/\/perma.cc\/SMU6-58TU (\u201c[T]he need to be aware of and have a working knowledge of technology\u2026is ethically required of all lawyers.\u201d).<\/p>\n<p><a href=\"#_ftnref105\" name=\"_ftn105\">[103]<\/a> Ann M. Murphy, <em>Is It Safe? The Need for State Ethical Rules to Keep Pace with Technological Advances<\/em>, 81 Fordham L. Rev. 1651, 1659, 1665\u201366 (2013), http:\/\/ir.lawnet.fordham.edu\/cgi\/viewcontent.cgi?article=4876&amp;context=flr, <em>archived at <\/em>https:\/\/perma.cc\/V69A-EETR.<\/p>\n<p><a href=\"#_ftnref106\" name=\"_ftn106\">[104]<\/a> Samantha V. Ettari &amp; Noah Hertz-Bunzl, <em>Ethical E-Discovery: What Every Lawyer Needs to Know<\/em>, LegaltechNews (Nov. 10, 2015), http:\/\/www.kramerlevin.com\/files\/Publication\/d7dec721-693a-4810-a4b9-32dfe9c1864b\/Presentation\/PublicationAttachment\/018a444a-d7de-46b2-bc16-506cff88d346\/EDiscovery-Legaltech%20News11.10.15..pdf, <em>archived at <\/em>https:\/\/perma.cc\/4YMR-XL9U (referring to Model Rule of Prof\u2019l Conduct 5.1).<\/p>\n<p><a href=\"#_ftnref107\" name=\"_ftn107\">[105]<\/a> American Bar Association, A Legislative History: the Development of the ABA Model Rules of Professional Conduct, 1982-2005 560 (2006).<\/p>\n<p><a href=\"#_ftnref108\" name=\"_ftn108\">[106]<\/a> Jeffrey P. Reilly, <em>Rule 5.1 of the Rules of Professional Conduct: What Must Corporate General Counsel Do?<\/em> Association of Corporate Counsel, Baltimore Chapter FOCUS 2Q12 5\u20136 (2012), http:\/\/www.milesstockbridge.com\/pdf\/publications\/ReillyACCArticle.pdf, <em>archived at<\/em> https:\/\/perma.cc\/G26J-NTJE<em>.<\/em><\/p>\n<p><a href=\"#_ftnref109\" name=\"_ftn109\">[107]<\/a> <em>See<\/em> Jennifer Ellis, <em>What Technology Does a Modern US Lawyer Generally Use in Practice?<\/em>, Quora (Mar. 22, 2014), https:\/\/www.quora.com\/What-technology-does-a-modern-US-lawyer-generally-use-in-practice, <em>archived at <\/em>https:\/\/perma.cc\/4FX4-2UV7.<\/p>\n<p><a href=\"#_ftnref110\" name=\"_ftn110\">[108]<\/a> <em>See<\/em> Model Rules of Prof\u2019l Conduct R. 5.3.<\/p>\n<p><a href=\"#_ftnref111\" name=\"_ftn111\">[109]<\/a> Frances P. Kao, <em>No, a Paralegal Is Not a Lawyer<\/em>, ABA Bus. Law Today, (Jan.\/Feb. 2007), https:\/\/apps.americanbar.org\/buslaw\/blt\/2007-01-02\/kao.shtml, <em>archived at<\/em> https:\/\/perma.cc\/3J2N-ELPA.<\/p>\n<p><a href=\"#_ftnref112\" name=\"_ftn112\">[110]<\/a> <em>See <\/em>Model Rules of Prof\u2019l Conduct R. 1.6.<\/p>\n<p><a href=\"#_ftnref113\" name=\"_ftn113\">[111]<\/a> <em>See <\/em>Jon Snyder, <em>1939\u2019s \u2018World of Tomorrow\u2019 Shaped Our Today<\/em>, Wired (Apr. 29, 2010, 8:00 PM), http:\/\/www.wired.com\/2010\/04\/gallery-1939-worlds-fair\/, <em>archived at <\/em>https:\/\/perma.cc\/D5V4-36R5.<\/p>\n<p><a href=\"#_ftnref114\" name=\"_ftn114\">[112]<\/a> Model Rules of Prof\u2019l Conduct R. 1.6.<\/p>\n<p><a href=\"#_ftnref115\" name=\"_ftn115\">[113]<\/a> <em>See <\/em>Saul Jay Singer, <em>Speaking of Ethics: When Tarasoff Meets Rule 1.6<\/em>, Washington Lawyer (May 2011), https:\/\/www.dcbar.org\/bar-resources\/publications\/washington-lawyer\/articles\/may-2011-speaking-of-ethics.cfm, <em>archived at<\/em> https:\/\/perma.cc\/A7E4-DSH6.<\/p>\n<p><a href=\"#_ftnref116\" name=\"_ftn116\">[114]<\/a> Model Rules of Prof\u2019l Conduct R. 1.6 cmt. 18.<\/p>\n<p><a href=\"#_ftnref117\" name=\"_ftn117\">[115]<\/a> David G. Ries, <em>Cybersecurity for Attorneys: Understanding the Ethical Obligations<\/em>, Law Practice Today (Mar. 2012), http:\/\/www.americanbar.org\/publications\/law_practice_today_home\/law_practice_today_archive\/march12\/cyber-security-for-attorneys-understanding-the-ethical-obligations.html, <em>archived at<\/em> https:\/\/perma.cc\/59Q2-55Q4.<a href=\"#_ftnref118\" name=\"_ftn118\"><\/a><\/p>\n<p>[116] <em>See <\/em>State Bar of Cal. Standing Comm. on Prof\u2019l Responsibility and Conduct, Formal Op. 2015-193, 3\u20134 (2015) [hereinafter Cal. Ethics Op. 2015-193] (discussing what an attorney\u2019s ethical duties are in the handling of discovery of electronically stored information).<\/p>\n<p><a href=\"#_ftnref119\" name=\"_ftn119\">[117]<\/a> Ettari &amp; Hertz-Bunzl, <em>supra <\/em>note 104.<\/p>\n<p><a href=\"#_ftnref120\" name=\"_ftn120\">[118]<\/a> Cal. Ethics Op. 2015-193, <em>supra <\/em>note 116, at fn. 7.<\/p>\n<p><a href=\"#_ftnref121\" name=\"_ftn121\">[119]<\/a> State Bar of Cal. Standing Comm. on Prof\u2019l Responsibility and Conduct, Formal Op. 2010-179, 7 (2010) (discussing whether an attorney violates the duties of confidentiality and competence she owes to a client by using technology to transmit or store confidential client information when the technology may be susceptible to unauthorized access by third parties).<\/p>\n<p><a href=\"#_ftnref122\" name=\"_ftn122\">[120]<\/a> N.Y. Cnty. Lawyers\u2019 Ass\u2019n Comm. on Prof\u2019l Ethics, Formal Op. 733, 7 (2004) (discussing non-exclusive referrals and sharing of office space, computers, telephone lines, office expenses, and advertising with non-legal professionals).<\/p>\n<p><a href=\"#_ftnref123\" name=\"_ftn123\">[121]<\/a> N.Y. State Bar Ass\u2019n Comm. on Prof\u2019l Ethics, Formal Op. 842 (2010) (discussing using an outside online storage provider to store client\u2019s confidential information).<\/p>\n<p><a href=\"#_ftnref124\" name=\"_ftn124\">[122]<\/a> Model Rules of Prof\u2019l Conduct R. 1.4 (1983); <em>see also<\/em> 204 Pa. Code \u00a7 81.4 (1988), http:\/\/www.pacode.com\/secure\/data\/204\/chapter81\/chap81toc.html, <em>archived at<\/em> https:\/\/perma.cc\/6FG5-9VP3 (incorporating ABA Model Rule 1.4 into Pennsylvania\u2019s Model Rule 1.4).<\/p>\n<p><a href=\"#_ftnref125\" name=\"_ftn125\">[123]<\/a><em>See <\/em>ABA Comm. on Ethics 20\/20, <em>Introduction and Overview<\/em> (Feb. 2013), http:\/\/www.americanbar.org\/content\/dam\/aba\/administrative\/ethics_2020\/20121112_ethics_20_20_overarching_report_final_with_disclaimer.authcheckdam.pdf, <em>archived at<\/em> https:\/\/perma.cc\/D2ZY-NYEU.<\/p>\n<p><a href=\"#_ftnref126\" name=\"_ftn126\">[124]<\/a> Model Rules of Prof\u2019l Conduct R. 1.6(c) cmt. 18 (1983).<\/p>\n<p><a href=\"#_ftnref127\" name=\"_ftn127\">[125]<\/a> Opinion 701 also highlights, if inadvertently, the challenges attorneys face when trying to modify existing practices to fit new technologies. As part of the inquiry underpinning Opinion 701\u2019s guidance, the opinion notes that \u201cnothing in the RPCs prevents a lawyer from archiving a client\u2019s file through use of an electronic medium such as PDF files or similar formats.\u201d This note is nearly laughable when read in the context of current practice, as it suggests that attorneys were (or are?) concerned about whether PDF files are appropriate for retaining paper documents. N.J. Advisory Comm. on Prof\u2019l Ethics, Formal Op. 701 (2006), https:\/\/www.judiciary.state.nj.us\/notices\/ethics\/ACPE_Opinion701_ElectronicStorage_12022005.pdf, <em>archived at <\/em>https:\/\/perma.cc\/EV9H-BN3T.<\/p>\n<p><a href=\"#_ftnref128\" name=\"_ftn128\">[126]<\/a> <em>See <\/em>Brian M. Karpf, <em>Florida\u2019s Take on Telling Clients to Scrub Social Media Pages<\/em>, Law 360 (Sept. 15, 2015, 4:33 PM), http:\/\/www.law360.com\/articles\/702288\/florida-s-take-on-telling-clients-to-scrub-social-media-pages, <em>archived at <\/em>https:\/\/perma.cc\/NZ3W-FHPS.<\/p>\n<p><a href=\"#_ftnref129\" name=\"_ftn129\">[127]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref130\" name=\"_ftn130\">[128]<\/a> N.Y.C. Bar Ass\u2019n Comm. on Prof\u2019l. Ethics, Formal Op. 2010-2 (2010), http:\/\/www.nycbar.org\/ethics\/ethics-opinions-local\/2010-opinions\/786-obtaining-evidence-from-social-networking-websites, <em>archived at<\/em> https:\/\/perma.cc\/JT9K-2EGV (discussing lawyers\u2019 obtainment of information from social networking websites).<\/p>\n<p><a href=\"#_ftnref131\" name=\"_ftn131\">[129]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref132\" name=\"_ftn132\">[130]<\/a> Mark A. Berman, Ignatius A. Grande &amp; James M. Wicks, <em>Social Media Ethics Guidelines of the Commercial and Federal Litigation Section of the New York State Bar Association<\/em>, The New York State Bar Association (June 9, 2015), http:\/\/www.nysba.org\/socialmediaguidelines\/, <em>archived at<\/em> https:\/\/perma.cc\/4ZSN-BXT4.<\/p>\n<p><a href=\"#_ftnref133\" name=\"_ftn133\">[131]<\/a> <em>Id.<\/em><\/p>\n<p>[132] <em>Id.<\/em><\/p>\n<p>[133] <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref136\" name=\"_ftn136\">[134]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref137\" name=\"_ftn137\">[135]<\/a> <em>See <\/em>Fla. State Bar Comm. on Prof&#8217;l Ethics, Proposed Op. 14-1 (2015), http:\/\/www.floridabar.org\/TFB\/TFBResources.nsf\/Attachments\/B806500C941083C785257E730071222B\/$FILE\/14-01%20PAO.pdf?OpenElement, <em>archived at <\/em>https:\/\/perma.cc\/DK9W-A44Z.<\/p>\n<p><a href=\"#_ftnref138\" name=\"_ftn138\">[136]<\/a> Pa. Bar Ass\u2019n. Comm. on Ethics, Formal Op. 2014-300, 2 (2014), http:\/\/www.americanbar.org\/content\/dam\/aba\/events\/professional_responsibility\/2015\/May\/Conference\/Materials\/pa_formal_op_2014_300.authcheckdam.pdf, <em>archived at<\/em> https:\/\/perma.cc\/G6EY-PBFF.<\/p>\n<p><a href=\"#_ftnref139\" name=\"_ftn139\">[137]<\/a> Model Rules of Prof&#8217;l Conduct R. 3.4 (1983).<\/p>\n<p><a href=\"#_ftnref140\" name=\"_ftn140\">[138]<\/a> <em>See<\/em> <em>supra<\/em> Part II.<\/p>\n<p><a href=\"#_ftnref141\" name=\"_ftn141\">[139]<\/a> <em>See<\/em> ABA Cybersecurity Legal Task Force, Resolution 118, 2 (August 2013), http:\/\/www.americanbar.org\/content\/dam\/aba\/administrative\/law_national_security\/resolution_118.authcheckdam.pdf, <em>archived at<\/em> https:\/\/perma.cc\/UQ44-3Q2C.<\/p>\n<p><a href=\"#_ftnref142\" name=\"_ftn142\">[140]<\/a> <em>See id. <\/em>at 4.<\/p>\n<p><a href=\"#_ftnref143\" name=\"_ftn143\">[141]<\/a> <em>See id.<\/em> at 16.<\/p>\n<p><a href=\"#_ftnref144\" name=\"_ftn144\">[142]<\/a> Model Rules of Prof&#8217;l Conduct R. 5.7, cmt. 1 (1983).<\/p>\n<p><a href=\"#_ftnref145\" name=\"_ftn145\">[143]<\/a> <em>See<\/em> Model Rules of Prof&#8217;l Conduct R. 1.6.<\/p>\n<p><a href=\"#_ftnref146\" name=\"_ftn146\">[144]<\/a> Ralph C. Losey, <em>The Importance of Cybersecurity in eDiscovery<\/em>, E-Discovery Law Today (May 9, 2014) http:\/\/www.ediscoverylawtoday.com\/2014\/05\/the-importance-of-data-security-in-ediscovery\/, <em>archived at <\/em>https:\/\/perma.cc\/P64J-NYQ7.<\/p>\n<p><a href=\"#_ftnref147\" name=\"_ftn147\">[145]<\/a> Ralph C. Losey, <em>The Importance of Cybersecurity to the Legal Profession and Outsourcing as a Best Practice \u2013 Part Two<\/em>, e-Discovery Team (May 18, 2014), http:\/\/e-discoveryteam.com\/2014\/05\/18\/the-importance-of-cybersecurity-to-the-legal-profession-and-outsourcing-as-a-best-practice-part-two\/, <em>archived at <\/em>https:\/\/perma.cc\/W3HW-AHCC.<\/p>\n<p><a href=\"#_ftnref148\" name=\"_ftn148\">[146]<\/a> N.Y.C. Bar Ass\u2019n Comm. on Prof\u2019l Ethics, Formal Op. 2015-3, 4\u20135 (2015), http:\/\/www2.nycbar.org\/pdf\/report\/uploads\/20072898-FormalOpinion2015-3-LAWYERSWHOFALLVICTIMTOINTERNETSCAMS.pdf, <em>archived at<\/em> https:\/\/perma.cc\/6BHV-V2YC.<\/p>\n<p><a href=\"#_ftnref149\" name=\"_ftn149\">[147]<\/a> <em>Id. <\/em>at 1.<\/p>\n<p><a href=\"#_ftnref150\" name=\"_ftn150\">[148]<\/a> <em>Id. <\/em>at 6 (emphasis added).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BMS Publication Version PDF Cite as: Stacey Blaustein et al.,\u00a0Digital Direction for the Analog Attorney\u2014Data Protection, E-Discovery, and the Ethics of Technological Competence in Today\u2019s World of Tomorrow, 22 Rich. J.L. &amp; Tech. 10 (2016), http:\/\/jolt.richmond.edu\/v22i4\/article10.pdf. \u00a0Stacey Blaustein,* Melinda L. McLellan,** and James A. Sherer*** &nbsp; I. \u00a0Introduction \u00a0[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Over the past twenty years, the [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-3255","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-Qv","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=3255"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3255\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=3255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=3255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=3255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}