Navigating the Cloud: A Washington State Law Firm’s Guide to WSBA Advisory Opinion 2215
The legal industry is rapidly transitioning to cloud-hosted services for document storage, practice management, and client communication. The benefits are clear: reduced IT costs, enhanced collaboration, and the ability to work from anywhere. But for Washington lawyers, this digital shift brings up a critical ethical question: Is it safe, and is it compliant?According to the Washington State Bar Association (WSBA) Advisory Opinion 2215, the short answer is yes. However, there is a catch. The WSBA does not "certify" or white-list particular cloud providers for law offices to use. Instead, the burden of compliance falls squarely on the shoulders of the law firm,
Attorneys have a fundamental ethical obligation under RPC 1.6 (Confidentiality of Information) and RPC 1.1 (Competence) to protect client data and stay abreast of the risks associated with modern technology. Simply signing up for a popular cloud service isn't enough; firms must conduct reasonable due diligence, protect confidential information against unauthorized access, and periodically reevaluate their chosen vendors.
If your firm is migrating to the cloud or auditing an existing provider, here is a technical evaluation checklist based on WSBA guidelines that you must review and document.
- Vendor Reputation and Security Practices:
Do not hand confidential client data to an untested startup without proper vetting. Investigate the cloud provider’s history, reputation in the industry, and their specific experience handling highly sensitive or legally protected information. - Ironclad Encryption Standards:
Your data is most vulnerable when it is moving. Ensure the provider uses robust, industry-standard encryption for information both in transit (when being sent between your office and the cloud) and at rest (when it is sitting on the provider’s servers). - Strict Access Controls and Authentication:
- Passwords alone are no longer sufficient. Your firm should require:
- Multi-Factor Authentication (MFA): For all individual user accounts.
- Role-Based Access Restrictions: Ensuring staff members only have access to the files necessary for their specific duties.
- Activity Logging: Full audit trails that allow you to see exactly who accessed, modified, or deleted a document and when.
- Service Agreements and Privacy Policies:
- Read the fine print of the Terms of Service. Look for strict confidentiality and privacy agreements.
- You need to know exactly under what circumstances the provider’s employees, server hosts, or third-party subcontractors are legally allowed to access your stored information.
- Prompt Breach Notification Commitments:
In the event of a cyberattack, time is of the essence. Your cloud provider must have a contractual commitment to notify your firm promptly of any unauthorized access, data leaks, or security breaches so you can take immediate action to protect your clients. - Data Resilience and Business Continuity:
Accidents happen, and cyber threats like ransomware are on the rise. Evaluate the provider's fail-safes. Do they offer redundant backups, file version history (to recover accidentally altered or deleted files), and clear business-continuity protections to keep your firm running during a catastrophic provider outage? - The Exit Strategy: Data Portability:
- What happens if you want to switch software, or worse, the provider goes out of business or changes ownership?
- You must have the guaranteed ability to retrieve and export all of your firm's information in a usable, non-proprietary format if the service is abruptly canceled.
- Data Lifecycle and Secure Termination:
Understand the vendor's procedures for data ownership, retention, and deletion. When a client's file reaches the end of its retention period, or if you terminate your account with the provider, there must be a verifiable procedure to securely wipe the data so no digital footprint is left behind. - Securing Your Own Perimeter:
The most secure cloud server in the world won't protect you if the device you use to access it is compromised. Due diligence extends to the security of your own office computers, mobile devices, local networks, and internet connections. (Avoid accessing unencrypted client data over public, unsecured Wi-Fi without a VPN). - Continuous Monitoring and Reevaluation:
Technology evolves rapidly, and so do security threats. Due diligence is not a one-and-done checklist. Firms must establish a firm-wide process for periodically reviewing the cloud provider, evaluating new service terms, and updating internal security configurations as the technological landscape changes.
Recommended Cloud Storage Services:
To comply with WSBA Advisory Opinion 2215, law firms typically choose between purpose-built legal document management platforms or enterprise cloud storage configured for legal compliance. Both options offer strong encryption, multi-factor authentication (MFA), role-based permissions, detailed audit logging, data portability, and robust backup protections.
| Platform | Category | Key Compliance Features | Data Portability & Retention |
| NetDocuments | Dedicated Legal DMS | Encryption in transit/at rest, SOC 2 Type II, matter-level permissioning, comprehensive audit trails. | Full document/metadata export capabilities; automated retention and deletion rules. |
| Clio Manage | Legal Practice Management | MFA, end-to-end encryption, firm-wide activity logging, role-based access control, secure client portal. | Bulk data export tools (CSV/zip), automated backups, 99.9% uptime SLA. |
| Box (Business/Enterprise) | Enterprise Cloud Storage | AES 256-bit encryption, Box Governance for retention/holds, full user activity logging, custom access tiers. | Easy multi-format file download/export, HIPAA/SOC 2 compliance, disaster recovery. |
| Microsoft 365 (OneDrive/SharePoint) | Enterprise Cloud Storage | MFA enforcement, Microsoft Purview DLP, audit logging, role-based access, version history. | Native bulk export via eDiscovery/Purview, 99.9% uptime SLA, automated backup options. |
| Tresorit | Zero-Knowledge Encrypted Storage | Swiss/EU privacy standards, zero-knowledge end-to-end encryption, revocable access links, access audit logs. | Granular retention controls, user-managed encryption keys, direct file export. |
Critical WSBA 2215 Due Diligence Steps
Request Service Level Agreements (SLAs): Verify contract terms for uptime guarantees, data breach notification timelines (usually 24–72 hours), and explicit declarations that the vendor claims no ownership over firm data.
Audit Internal Configuration: Enabling the software is only half the requirement. Your firm must mandate MFA across all employee accounts, disable public link sharing by default, and set up automatic session timeouts on mobile and local desktop clients.
Maintain Desktop Security: Secure local endpoints using disk encryption (e.g., BitLocker or FileVault), endpoint antivirus, and a firm VPN when staff access files on public Wi-Fi networks.
Conclusion
Embracing cloud technology is essential for running a modern, efficient law practice. By taking a proactive approach to vendor evaluation and prioritizing data security, Washington law firms can confidently reap the benefits of the cloud while fully honoring their ethical duties to their clients.References & Citations:
- WSBA Advisory Opinion 2215 (2012): Concludes that a lawyer may use online data storage systems to store and back up client confidential information, provided the lawyer takes reasonable care to ensure information remains confidential and secure against loss.
- Washington Rules of Professional Conduct (RPC) 1.1 (Competence): Specifically, Comment 8 notes that to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
- Washington Rules of Professional Conduct (RPC) 1.6 (Confidentiality of Information): Requires lawyers to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
- Washington Rules of Professional Conduct (RPC) 1.15A (Safeguarding Property): Outlines the duties of a lawyer to properly safeguard client property and data.
- WSBA Ethics Advisory Opinion 201601 (2016): Expands upon Opinion 2215 by addressing the ethical practices of virtual law offices and the necessity of supervising third-party vendors and cloud services.
Created & Maintained by Pacific Northwest Computers
📞 Pacific Northwest Computers offers Remote & Onsite Support Across:
SW Washington including Vancouver WA, Battle Ground WA, Camas WA, Washougal WA, Longview WA, Kelso WA, and Portland OR


No comments:
Post a Comment