Also known as:unauthorised access · unauthorized accesses · unauth access · illegal access
Written by attorneys · grounded in primary & secondary sources — see below
Access by a third party to information relating to the representation of a client that occurs without the client's consent or other legal authorization. The term identifies the risk that lawyers must address through reasonable preventive measures when selecting and using technology or storage methods for client files.
Sources & Authorities
How it applies
Common Examples
2
Unsecured Cloud Storage Breach
Martin stored Titan EquipCo's contracts and litigation files in a personal cloud account protected only by a reused simple password and without two-factor authentication. After a provider breach, hackers accessed hundreds of confidential documents. The exposure occurred because Martin made no effort to evaluate or strengthen the account's security settings before uploading the files.
Open Wi-Fi Transmission Intercepted
Leah emailed Apex Wireless detailed antitrust strategy and draft regulatory filings while using unsecured airport Wi-Fi without a VPN or encryption. A hacker intercepted the messages and posted excerpts online. The transmission exposed the materials because Leah employed no protective measures despite the known vulnerability of public networks.
Put it into practice
Test Yourself
10
Practice Questions5
· 1 primary source
Select any source to read its text and confirm it supports the definition.
Model Codes
Hornbooks
Study Supplements
Common questions
Frequently Asked
4
What standard must a lawyer meet to avoid discipline for unauthorized access to client information?+
A lawyer must make reasonable efforts to prevent unauthorized access. Reasonableness is assessed by the sensitivity of the data, available security tools, and the lawyer's diligence in reviewing vendor practices and configuring protections such as strong passwords or encryption.
Supporting sources
Does using a consumer-grade service automatically violate the duty to prevent unauthorized access?+
No. The rule permits third-party technology when the lawyer exercises reasonable care in selecting and configuring it. Blind reliance on default settings without reviewing terms or adding safeguards, however, falls short of the required standard.
Supporting sources
Is actual disclosure or hacking required to find a violation?+
No. The duty focuses on preventive efforts before any breach occurs. Failure to implement basic protections such as access restrictions or encryption can constitute a violation even if no third party ultimately views the files.
Supporting sources
Does industry custom or prior safe use of a service excuse inadequate security measures?+
No. Custom and past experience provide some context but do not override the need for reasonable efforts calibrated to the sensitivity of the particular client information. Readily available controls that were omitted in prior matters remain relevant to the reasonableness inquiry.
Supporting sources
Professional ResponsibilityClient confidentiality · Professional obligation of confidentiality—general ruleMPREIntermediate