What Boise Law Firms Should Ask an IT Provider About Client Data Security
A law firm's obligations around client information are set by the rules of professional conduct and by your bar, not by your IT provider. What an IT provider is responsible for is the technical control environment that makes meeting those obligations possible. These are the questions worth asking to find out whether a provider can actually support that.
This article covers IT controls only. For questions about your professional responsibilities, consult the Idaho State Bar or your own counsel.
Who can see our client files, and how do you prove it?
Ask for a written access model, not a verbal assurance. A firm should be able to see which accounts have access to which matter files, whether access is granted by role or by individual, and how quickly access is removed when someone leaves.
Follow up: does your IT provider's own staff have standing access to firm data, and is that access logged? Many do. That is not automatically wrong, but you should know it and it should be recorded.
How is client data protected in transit and at rest?
Encryption in both states is the baseline, and the answer should be specific. Which systems, which method, and who holds the keys.
Ask specifically about laptops and mobile devices. Full disk encryption on firm laptops is straightforward to implement and is one of the more common gaps we see.
How do we share files with clients and opposing counsel?
If the honest answer is email attachments, that is worth addressing. A secure portal or an encrypted transfer method should be available and should be easy enough that people actually use it. Controls that create friction get worked around, and a workaround is worse than the original problem.
What happens in the first 24 hours of a suspected breach?
You want a specific sequence, not a reassurance. Who gets called, who preserves evidence, who determines what data was involved, and how quickly you receive information you can act on.
Your notification duties are a legal question for your counsel and your bar. What your IT provider owes you is fast, accurate information about scope, because you cannot make those decisions without it.
How long is our data retained, and where?
Retention is a decision the firm makes and the IT provider implements. Ask where backups physically live, how long they are kept, and whether data can be deleted on request when a retention period ends. Confirm the answer covers backups, not just the live system.
Which of your vendors touch our data?
Most IT providers use third-party tools for backup, monitoring, email filtering, and documentation. Ask for the list and what each one can see. A provider who cannot produce that list on request has not thought about it carefully.
How do you handle remote and mobile access?
Attorneys work from courthouses, home, and travel. Ask how devices are authenticated, whether multifactor authentication covers remote access and not only email, and what happens when a phone is lost.
What a good answer sounds like
The pattern to listen for is specificity. A provider who answers with a product name is describing a purchase. A provider who answers with a process, a responsible party, and a way to verify it is describing a control.
Working with firms in the Treasure Valley
IDACOMP has supported Idaho businesses since 2002 as part of Bytagig, founded 2009. Managed clients see a 15-minute average first response, measured from ticket data rather than offered as a contractual promise. We work from CIS Controls and provide documentation firms can keep.
If your firm is reviewing its IT arrangements, we are glad to walk these questions with you, including the ones about our own access and our own vendors.










