<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:pp="http://www.presspage.com/rss/"
     version="2.0"
     xmlns:atom="http://www.w3.org/2005/Atom">
                <channel>
                    <title><![CDATA[The Missouri Bar Newsroom]]></title>
                    <link>https://news.mobar.org/</link>
                    <description></description>
                    <language>en-us</language>
                    <lastBuildDate>Thu, 17 Sep 2026 03:24:56 +0200</lastBuildDate>
                    <pubDate>Tue, 02 Dec 2025 22:23:46 +0100</pubDate>
                    <image>
                        <title><![CDATA[The Missouri Bar Newsroom]]></title>
                        <url>https://content.presspage.com/clients/150_2361.jpg</url>
                        <link>https://news.mobar.org/</link>
                        <width>144</width>
                    </image><item>
                        <title>Management matters: Enhance your solo or small firm’s cyber security in 2026</title>
                        <link>https://news.mobar.org/management-matters-enhance-your-solo-or-small-firms-cyber-security-in-2026/</link>
                        <guid>https://news.mobar.org/management-matters-enhance-your-solo-or-small-firms-cyber-security-in-2026/</guid><pp:caseid>730121</pp:caseid><pp:subtitle>Vol. 81, No. 6 / November-December 2025</pp:subtitle><description><![CDATA[<img src="https://content.presspage.com/uploads/2361/bb38004f-b5ae-4a24-8b7f-dcf841d3bf55/500_jeffkrause.jpg?x=1764615326414" alt="Jeff Krause" width="200"><p>&nbsp;</p><p>&nbsp;</p><p>Jeffrey S. Krause is a senior consultant at Affinity Consulting Group LLC.</p><p>There is a common misperception that solo and small firm lawyers cannot afford the same level of tech security as larger firms. While it is true that firms with larger budgets can afford a larger security infrastructure, it does not necessarily mean their security is better than what a smaller firm can obtain.&nbsp;</p><p><img class="image_resized image-style-align-right" style="aspect-ratio:349/auto;width:349px;" src="https://content.presspage.com/uploads/2361/4e3f1659-6712-4890-ab18-b1e2522acff9/800_novdec25managementmatterspullquote.png?x=1764619521055" alt="NovDec25 Management Matters pull quote" width="349" height="auto">More likely, a larger security infrastructure results from more employees, including those whose job it is to maintain security, and from being a more prominent target. Small firms can also implement robust security to protect their firms and clients. Smaller firms may have fewer weak spots to protect, but they need to know those weak spots and implement security to guard them. They might also find they already pay for the tools they need.</p><p>Here are some easy ways to greatly enhance your firm’s security going into 2026 while spending little-to-no money.&nbsp;</p><h3><strong>Duty&nbsp;</strong></h3><p>One thing is clear: All lawyers have a duty to protect their clients’ data. The Missouri Rules of Professional Conduct, Rule 4-1.6(c) states: “A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of the client.”</p><p>Unless you want to argue about reasonableness, Rule 4-1.6(c) does not provide an exception for solo and small firm lawyers, giving them leeway due to firm size or budget. The duty is the same — you must take reasonable steps to protect client information. In doing so, you are also taking reasonable steps to protect business and personal information.&nbsp;</p><h3><strong>Security weak spots&nbsp;</strong></h3><p>High-profile security breaches are often reported as if a genius hacker cracked an elaborate system designed to prevent unauthorized access. While this occasionally happens, most security breaches are much less interesting. Users are careless with already-weak passwords that they may use on multiple sites.&nbsp;</p><p>For example, an employee’s password to the firm’s Clio may be the same as their Netflix password, their Facebook login, and, most dangerously, that one sketchy website they visited four years ago. Affinity Consulting’s resource on password managers, <a href="https://connect.mobar.org/viewdocument/password-manager?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" target="_blank">located in the connect.MOBAR forms bank</a>, can help you familiarize yourself with good password principles and password management programs.&nbsp;</p><p>Some organizations do not require strong passwords or an additional layer of security if a password is compromised. Devices may be lost without the data being properly secured. In other words, solo and small firm data security is about protecting data from our own mistakes.&nbsp;</p><h3><strong>Microsoft 365&nbsp;</strong></h3><p>The good news is that you likely have the tools to provide sophisticated security to your clients and their data. Microsoft 365 is nearly ubiquitous among solo and small firms and provides many of the features needed to protect data. Microsoft 365 Business Standard costs $12.50 per user per month and provides almost everything you need. You might also consider Microsoft 365 Business Premium, which has additional features related to security, at $22 per user per month.&nbsp;</p><p>Both the standard and premium plans include multi-factor authentication and an extensive list of security defaults. Both plans provide anti-spam, anti-malware, and anti-phishing features, and allow users to control access to SharePoint and OneDrive files. Correctly using these features provides a significant level of security.</p><p>The premium plan adds conditional access features, advanced anti-phishing, safe links and safe attachments, sensitivity labels, and data loss prevention services. You may decide the $9.50 per user per month is worth it to protect yourself from unforced errors. For example, the data loss prevention service notifies you when you attempt to share credit card numbers or content falling under HIPAA and may catch you from sharing that information in an insecure way. The service also provides a report of any information you shared. Proactive features like this help prevent errors, break bad sharing habits, and give you a list of information you have released “into the wild.”&nbsp;</p><h3><strong>Passwords and multi-factor authentication&nbsp;</strong></h3><p><img class="image_resized image-style-align-left" style="aspect-ratio:349/auto;width:349px;" src="https://content.presspage.com/uploads/2361/5a0a0843-1a3b-4081-a70b-5d7d35a27075/800_novdec25managementmatterspullquote2.png?x=1764619588023" alt="NovDec25 Management Matters pull quote2" width="349" height="auto">An easy way to address security weak spots is to consider password strength. With any Microsoft 365 plan, you can set password policies. Interestingly, Microsoft’s guidance regarding passwords is different than what you may have heard previously. While it does caution against easy-to-guess passwords or passphrases, it does not state that longer is necessarily better, complex character requirements are necessary, or periodic resets serve a purpose. Instead, much of the guidance centers around multi-factor authentication.&nbsp;</p><p>Most of us are familiar with MFA. It requires the user to provide two or more verification factors to gain access. For example, when a user attempts to log in from a new device or location, they enter their login and password as normal. If this information is correct, a message is sent to their phone. The message contains a code that must be entered before the user can proceed.&nbsp;</p><p>Not only does Microsoft include MFA for Microsoft 365 components, MFA can also be configured to work with other applications via Azure AD (Active Directory). In addition to text message-based codes, many sites offer software-based codes, which can be stored and viewed in programs such as Microsoft Authenticator, Google Authenticator, or Twilio’s Authy.&nbsp;</p><p>With MFA, compromised passwords cannot be used to gain full access unless the bad actor also possesses and is able to successfully log in to the device to which the message is sent. This is where device encryption comes in.&nbsp;</p><h3><strong>Device encryption</strong>&nbsp;</h3><p>Encrypting your computers, laptops, tablets, and phones is another critical step in protecting data. If you enter a code to access your tablet or phone, you are already using encryption. Entering the wrong code too many times can lock or even erase the device. Good luck getting the MFA code from a locked phone. This simple encryption protects against a lost or stolen phone being used to compromise your data.</p><p>For computers and laptops, a little more work is required. For Windows Pro devices, turn on BitLocker to encrypt the device hard drive. It does not stop someone with the credentials from accessing the computer. However, a thief would have to know how to access the stolen laptop. If they do not know the credentials, they may attempt to remove the hard drive and access data that way. They cannot do this without the BitLocker code. A similar encryption tool, FileVault, is available for Mac users.&nbsp;</p><h3><strong>Conclusion&nbsp;</strong></h3><p>No security is bulletproof, and a short article cannot cover every aspect of security. However, Microsoft 365 and Windows, which most solo and small firms already use, offer powerful security features. Implementing just a few of them can fortify the most common weak points in your firm’s security. Combined with strong passwords, your security fortifications will rival most firms, irrespective of size.</p>]]></description><category><![CDATA[journal,molawyers,PracticeManagement,LPMPracticeMgmt,LPMCyber,LPMProtect,LPMTech]]></category>
            <pubDate>Wed, 03 Dec 2025 07:00:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/6b5b4d1c-bfc0-4ae3-ab30-38f2cff35391/500_pp_novdec25managementmatters.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/6b5b4d1c-bfc0-4ae3-ab30-38f2cff35391/500_pp_novdec25managementmatters.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/6b5b4d1c-bfc0-4ae3-ab30-38f2cff35391/pp_novdec25managementmatters.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[PP_NovDec25 Management Matters]]></pp:imageTitle></item><item>
                        <title>Don’t be a cookie monster</title>
                        <link>https://news.mobar.org/dont-be-a-cookie-monster/</link>
                        <guid>https://news.mobar.org/dont-be-a-cookie-monster/</guid><pp:caseid>656020</pp:caseid><description><![CDATA[<p><strong>By Jeffrey R. Schoenberger, senior consultant at Affinity Consulting Group LLC</strong></p><p>Lawyers and their firms interact with all manner of websites and services, and care that private information is safely managed. We also operate websites and services where consumers and our clients expect the same.</p><p>In this environment of ever-increasing data collection and aggregation and concomitant breaches, regulating bodies are starting to respond to consumer complaints and have begun to act. Your law firm’s website may soon be in their crosshairs, impacting your engagement and reach with current and potential clients.</p><p>Websites know no geographic boundaries, lawyers so regulations related to data collection affects lawyers in three ways:</p><p>1) what we disclose to website visitors about data-collection practices;</p><p>2) the ability of an individual to obtain a copy of that collected data; and</p><p>3) the ability of individuals to erase that data under limited circumstances. The most important of these is disclosure of data collection.</p><p><strong>Data collection and cookies</strong></p><p>Websites store information about visitors and track their interactions via tiny text files called “cookies.” Cookies are not inherently malicious and are often helpful. Amazon uses them so you can store contents in your shopping cart while continuing to click around. Cookies are also why you’re able to stay logged in to password-protected websites.</p><p>The privacy concerns with cookies arise from “tracking cookies” or “third-party tracking cookies.” These cookies “follow” you around the internet as you browse websites and build a more intimate and complete picture of you. Have you noticed how, when you search Google or Amazon for “Sonicare toothbrush,” you subsequently see electronic toothbrush ads on other websites you visit? You’ve experienced the power and reach of tracking cookies.</p><p>Go to <a href="http://wikihow.com/View-Cookies">wikihow.com/View-Cookies</a> to learn how to review the cookies on your computer’s web browsers.</p><p><strong>Requirements</strong></p><p>To comply with the recent government regulations, websites must disclose their use of cookies. This is why, in visiting websites in the last couple of years, you’ve seen more and more “pop-up” disclosures regarding data collection and cookies.</p><p>What do you and your website need to do then?</p><p><span>- </span>Your website must provide visitors with accurate and specific information about what every cookie your website uses does.</p><p><span>- </span>You must obtain a website visitor’s consent before using any cookies beyond those necessary for essential website functions, such as allowing users to stay logged in as they bounce around and return to your website.</p><p><span>- </span>Once the visitor consents, you must document and store that consent.</p><p><span>-&nbsp;</span>Visitors must be able to access your site even if they reject certain types of nonessential cookies.</p><p><span>-&nbsp;</span>Visitors must be able to withdraw or change their consent easily.</p><p>It’s entirely likely and reasonable that you don’t have the foggiest idea what cookies your website uses or what’s stored in those cookies on visitors’ computers. That’s OK. There are several websites that will examine your website for compliance and tell you where you are deficient. If you are responsible for your website’s backend, there are tools available for WordPress, Wix, and Squarespace.</p><p>If you have no idea what the preceding sentence means, there are plenty of companies willing to walk you through the process, such as <a href="http://onetrust.com/">OneTrust</a><span>.</span></p><p><strong>Missouri data disclosure laws</strong></p><p>While Missouri has no laws specifically governing data disclosure, § 407.1500&nbsp;RSMo. regulates consumer notifications of actual data breaches. The statue defines a breach as “unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information.”</p><p>Personal information is an“individual's first name or first initial and last name plus one or more of the following:</p><p>- social security number,</p><p>- driver’s license number or other government identifying number,</p><p>- financial account numbers (in combination with a PIN or other access credentials),</p><p>- unique electronic identifier or routing code (in combination with a PIN or other access credentials),</p><p>- medical information, or</p><p>- health insurance information.</p><p>The statute provides two exceptions as to whether accessing such information qualifies as a breach. First, good faith access is not a breach. Second, a reportable breach occurs only if the accessed personal information is “not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or unusable.” A breach of encrypted information need not be reported if the encryption key was not compromised.</p><p>Additionally, a breached party’s notification obligations may be tolled based on a law enforcement request (<i>e.g.</i>, an ongoing investigation) or superseded by another law (<i>e.g.</i>, HIPAA for healthcare organizations).</p><p>Notifications from the breached party to affected individuals must happen within 45 days of the breach’s discovery, which could be long after the breach’s occurrence. If the breach impacts more than 500 state residents, the business must notify the attorney general’s office.</p><p>Finally, the law provides a private right of action under which individuals may sue. Only those whose data was breached may sue for damages, and the Missouri Attorney General’s Office may also act.</p><p>For more resources about keeping your and your clients’ information safe, visit&nbsp;<a href="https://mobar.org/lpm">The Missouri Bar’s&nbsp;Law Practice Management Resource Center</a>.</p>]]></description><category><![CDATA[molawyers,PracticeManagement,LPMTech,LPMProtect,LPMCyber,LPMManagement,LPMPracticeMgmt]]></category>
            <pubDate>Wed, 28 Aug 2024 07:00:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/ccc2177a-c335-42b5-98bf-3a0a2a5a5cdb/500_lpm-cookiemonster.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/ccc2177a-c335-42b5-98bf-3a0a2a5a5cdb/500_lpm-cookiemonster.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/ccc2177a-c335-42b5-98bf-3a0a2a5a5cdb/lpm-cookiemonster.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[LPM_Cookie monster]]></pp:imageTitle></item><item>
                        <title>Seven tips to improve your cybersecurity</title>
                        <link>https://news.mobar.org/seven-tips-to-improve-your-cybersecurity/</link>
                        <guid>https://news.mobar.org/seven-tips-to-improve-your-cybersecurity/</guid><pp:caseid>652841</pp:caseid><description><![CDATA[<p><strong>By Jeffrey Schoenberger, senior consultant at Affinity Consulting Group LLC</strong></p><p>It's common to see news about cybersecurity spiral away from the helpful and actionable toward the sensational and convoluted. In the spirit of simple, direct, actionable solutions, here are seven suggestions to improve your cybersecurity situation.</p><h3>Enable whole disk encryption</h3><p>With in-person events picking up following the COVID-19 pandemic, our laptops are on-the-go and more people are visiting the office. Enable whole disk encryption on all laptops and desktops. If a thief steals your computer, they cannot access client information absent your username and password, even if they remove the physical hard drive from the stolen computer and install it in a different machine. Whole disk encryption is built in to <a href="https://support.microsoft.com/en-us/windows/turn-on-device-encryption-0c453637-bc88-5f74-5105-741561aae838">Windows</a> and <a href="https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac">macOS</a>.</p><h3>Enable “Find My”</h3><p>Check whether your device’s remote location feature is enabled. Apple calls its service <a href="https://support.apple.com/en-us/102648">Find My</a>, and Google’s is <a href="https://support.google.com/accounts/answer/6160491?hl=en">Find My Device</a>. Microsoft's feature is also called <a href="https://support.microsoft.com/en-us/account-billing/find-and-lock-a-lost-windows-device-890bf25e-b8ba-d3fe-8253-e98a12f26316">Find My Device</a>. With these services, you can locate the lost device, lock it, have it play a sound to help you find it, and, if necessary, remotely delete the device’s contents.</p><p>Apple’s service covers Macs, iOS devices, and some AirPods. Google’s service supports Android smartphones, tablets, and Chromebooks. Windows 10 and 11 users can enable Microsoft’s Find My Device.</p><h3>Asset recovery tags</h3><p>Larger organizations have long used numbered or barcoded stickers to track what equipment they have and where it is. Companies like <a href="https://dynotag.com/">Dynotag</a> and <a href="https://www.return.me/">ReturnMe</a> take this inventory concept and make it accessible to individuals and small businesses.</p><p>You purchase an identity tag from the vendor, which could be a sticker (most common), keyring, luggage tag, or even a literal dog (or cat) tag. You then create an account and register the tag’s number to your account. If you misplace your tagged item, whoever finds the item calls an 800 number or visits a website (both listed on the tag) to arrange the item’s return.</p><p>Think of these tags as “Good Samaritan stickers.” They don’t prevent theft, but they make it easy for good people to be helpful.</p><h3>Complex passwords</h3><p>Unique, complex passwords remain essential for online security. Start with the <a href="https://connect.mobar.org/viewdocument/password-manager">LPM whitepaper on password managers</a> for good information, but with one update: Replace LastPass with <a href="https://bitwarden.com/">Bitwarden</a> following the <a href="https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/">LastPass data breach</a> in 2022. I have also used <a href="https://1password.com/">1Password</a> for years and am confident in recommending it.</p><p>If online password storage unnerves you, the open-source <a href="https://keepass.info/help/v1/setup.html">KeePass</a> stores password data only locally on your machine, not in anyone’s cloud, but that makes you responsible for backing up and securing your data.</p><p>Finally, I recently learned one reason <a href="https://www.rolodex.com/contact-management.html">Rolodex</a> still exists. A lawyer I met uses Rolodex cards for each of his passwords. For example, filed under “A” is a card for Amazon listing his email address and password. Considering the weaknesses of a single-copy paper record in one location, it’s imperfect but beats using the same password for many sites. If you prefer something more portable than a Rolodex, <a href="https://www.amazon.com/password-notebooks/s?k=password+notebooks">Amazon sells password notebooks</a>.</p><h3>Two-factor authentication</h3><p>This <a href="https://connect.mobar.org/viewdocument/two-factor-authentication">LPM whitepaper</a> provides a primer on two-factor authentication (2FA). Enable it on every web service you use that offers 2FA. Visit the <a href="https://2fa.directory/us/">2FA Directory</a> to discover whether your practice management software, bank, etc. makes 2FA available.</p><p>1Password, <a href="https://www.dashlane.com/">Dashlane</a>, and <a href="https://www.roboform.com/">Roboform</a> support storing 2FA codes in their password managers. If you’re using another program, or a Rolodex or notebook, you’ll need an app like <a href="https://apps.apple.com/us/app/google-authenticator/id388497605">Google Authenticator</a>, <a href="https://support.microsoft.com/en-us/account-billing/download-and-install-the-microsoft-authenticator-app-351498fc-850a-45da-b7b6-27e523b8702a">Microsoft Authenticator</a>, or <a href="https://authy.com/download/">Twilio’s Authy</a>.</p><h3>Admin consoles</h3><p>A practice larger than a solo lawyer, even just a single lawyer and one part-time support staffer, should buy or subscribe to the “business version” of most needed software or services. Business-tier plans typically include an administration dashboard to control device and user access.</p><p>Examine your vendors of subscription-based tools for document storage, productivity software, eSignatures, and more. Secure, centralized user access and content management are a lifesaver for a lost device, ease employee onboarding and departure, and add a “belt and suspenders” approach to client data when paired with whole disk encryption and a “find my” service.</p><h3>VPN</h3><p>If you’re working away from home or the office and need internet connectivity, don’t join whatever WiFi network is available, even if it’s “secured,” meaning anyone can ask the barista for the password. There are two sound ways to connect to the internet when away from your “known safe” networks.</p><p>First, use your smartphone as a WiFi hotspot. This will drain your phone’s battery and eat data, but it’s safe. Second, subscribe to and use virtual private network (VPN) software.</p><p>A VPN encrypts your internet traffic before it leaves your computer. Once the encrypted traffic arrives at the VPN vendor’s server, it’s decrypted and released onto the public internet. This approach prevents your coffeehouse or hotel lobby neighbors from eavesdropping. A VPN generally slows your internet connection, but it’s a tradeoff in favor of security. Visit the <a href="https://hubs.ly/Q02G6ddx0">LPM comparison chart page</a> to compare VPN providers.</p><p>Tackling these seven suggestions on a one-a-day schedule will dramatically boost your security in a week.</p><p>For more resources on opening, building, managing, protecting, and winding down a law practice, visit&nbsp;<a href="https://mobar.org/lpm">The Missouri Bar’s&nbsp;Law Practice Management Resource Center</a>.</p>]]></description><category><![CDATA[LPMProtect,PracticeManagement,LPMTech,molawyers]]></category>
            <pubDate>Wed, 07 Aug 2024 06:00:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/f0d6c4a2-92d8-4ee7-abd2-b78b2dae2fcd/500_pp-7waystoimproveyourcybersecurity.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/f0d6c4a2-92d8-4ee7-abd2-b78b2dae2fcd/500_pp-7waystoimproveyourcybersecurity.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/f0d6c4a2-92d8-4ee7-abd2-b78b2dae2fcd/pp-7waystoimproveyourcybersecurity.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[PP_7 ways to improve your cybersecurity]]></pp:imageTitle></item><item>
                        <title>Lawyers need insurance too – protecting your business</title>
                        <link>https://news.mobar.org/lawyers-need-insurance-too--protecting-your-business/</link>
                        <guid>https://news.mobar.org/lawyers-need-insurance-too--protecting-your-business/</guid><pp:caseid>489288</pp:caseid><description><![CDATA[<p style="text-align:left;"><span style="margin:0px;padding:0px;"><strong>By Charles Coffey, The Bar Plan Mutual Insurance Company&nbsp;</strong></span></p><p><i><span style="margin:0px;padding:0px;">Note: This is the final piece of a three-part series from The Bar Plan Mutual Insurance Company. The first part (</span></i><a style="text-decoration:none;" href="https://news.mobar.org/lawyers-need-insurance-too-legal-malpractice-insurance/" target="_blank" rel="noreferrer noopener"><i><span style="margin:0px;padding:0px;"><u>about legal malpractice insurance</u></span></i></a><i><span style="margin:0px;padding:0px;">) ran Dec. 15, 2021, and the second part (</span></i><a style="text-decoration:none;" href="https://news.mobar.org/lawyers-need-insurance-too-cyber-liability-insurance/" target="_blank" rel="noreferrer noopener"><i><span style="margin:0px;padding:0px;">about <u>cyber liability insurance</u></span></i></a><i><span style="margin:0px;padding:0px;">) ran Jan. 12. The author describes some of the common types of insurance that lawyers and law firms should consider purchasing. The coverages included are by no means an exhaustive list but are intended to provide you with a good starting point to determine the coverages that are necessary for you and/or your firm.&nbsp;</span></i><span style="margin:0px;padding:0px;">&nbsp;</span></p><h3>Business owner’s policy (BOP)</h3><p><span style="margin:0px;padding:0px;">The Hartford </span><a style="text-decoration:none;" href="https://www.thehartford.com/business-owners-policy" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>explains</u></span></a><span style="margin:0px;padding:0px;"> that “A Business Owner’s Policy (BOP) combines business property and business liability insurance into one business insurance policy.”&nbsp;</span></p><p><span style="margin:0px;padding:0px;">A BOP generally includes three basic insurance coverages needed by </span><a style="text-decoration:none;" href="https://www.thehartford.com/business-insurance/lawyer" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>business owners</u></span></a><span style="margin:0px;padding:0px;">:&nbsp;</span></p><p><span style="margin:0px;padding:0px;">General liability insurance to help protect you from lawsuits when your business causes injuries or property damage. For example, if a client gets hurt at your office, this can help. It also helps cover claims of slander and libel.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Commercial property insurance coverage helps protect the physical location where you practice law. It also helps cover the items you use to conduct your legal business, whether it’s leased or owned.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Business income insurance coverage helps pay for lost income if you’re forced to shut down due to a covered property loss. This includes damage from fire, wind, or theft.&nbsp;</span></p><p style="text-align:left;"><span style="margin:0px;padding:0px;">It is important to note that you can purchase these three types of coverages in standalone policies, but most people find it easier and more economical to purchase a BOP.&nbsp;</span></p><h3>Workers’ compensation insurance</h3><p><span style="margin:0px;padding:0px;">With rare exceptions, </span><a style="text-decoration:none;" href="https://labor.mo.gov/DWC/Employers#:~:text=In%20the%20state%20of%20Missouri,have%20one%20or%20more%20employees" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>Missouri law</u></span></a><span style="margin:0px;padding:0px;"> requires a business owner to carry workers’ compensation insurance if he or she has five or more employees. This type of insurance provides benefits to your employees if they suffer illnesses or injuries because of their jobs. These benefits usually cover medical care, replace lost wages during recovery, provide disability benefits, and give death benefits in the event of a work-place accident that results in death. For the business owner, </span><a style="text-decoration:none;" href="https://www.thehartford.com/workers-compensation" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>workers’ compensation insurance</u></span></a><span style="margin:0px;padding:0px;"> often helps cover legal costs if an employee sues because of a workplace illness or injury.&nbsp;</span></p><h3>Life insurance</h3><p><span style="margin:0px;padding:0px;">While planning for one’s own death is uncomfortable, it is necessary. Life insurance can help you take care of dependents, a spouse, and/or aging parents. It also often gets more expensive with age, so it is something that you should consider purchasing while young. When considering the amount of </span><a style="text-decoration:none;" href="https://www.thebarplan.com/wp-content/uploads/2019/04/GAT_GI_Brochure_2019.pdf" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>life insurance</u></span></a><span style="margin:0px;padding:0px;"> you need, consider things like your final expenses, outstanding debts, housing costs (remaining mortgage/rent expense, utilities, etc.), and the educational or medical needs of dependents.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">There are two categories of life insurance: term and whole life. Term life insurance allows one to lock in a certain death benefit for a certain number of years. Within the term category, there are two types: renewable and level term. Renewable insurance has premiums that will increase annually as you age. while the premium for a level term policy remains the same throughout the term.&nbsp;&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Whole life insurance also pays a predetermined death benefit while rates remain the same. However, unlike term life insurance, premium payments made on a whole life policy earn tax-deferred interest and sometimes dividends. You can also borrow against it (in the amount of the current value) or cash in your policy prior to your death. The downside to whole life insurance is that it is much more expensive than term.&nbsp;</span></p><h3>Employment practices liability insurance</h3><p><span style="margin:0px;padding:0px;">Employment practices liability insurance (“EPLI”) provides coverage for </span><a style="text-decoration:none;" href="https://www.abainsurance.com/content/downloadables/aba/Why_EPLI.pdf" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>employment-related claims</u></span></a><span style="margin:0px;padding:0px;"> made against you and/or your firm. Such claims could include sexual harassment, age and disability discrimination, and wrongful termination. While this is common insurance for a business, a law firm can purchase policies </span><a style="text-decoration:none;" href="https://www.abainsurance.com/firm-products/employment-practices-liability/" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>specifically tailored</u></span></a><span style="margin:0px;padding:0px;"> to its needs that include coverage for things like the failure to make someone a partner, third-party claims brought by nonemployees for harassment or discrimination, and claims related to a nonprofit controlled by the law firm.&nbsp;</span></p><h3>Business (commercial) auto insurance and non-owned auto insurance</h3><p><span style="margin:0px;padding:0px;">Many people do not realize that most personal auto policies do not cover accidents that occur while traveling for the purpose of conducting business. Given this, business auto insurance is essential to protect you from uninsured personal liability for property damage, medical care, and personal injury.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Likewise, most personal auto policies held by your employees do not provide them coverage when they are traveling in their personal vehicle for a work purpose. Non-owned auto insurance protects your employees from uninsured personal liability for property damage, medical care, and personal injury.&nbsp;</span></p><h3>Other miscellaneous insurance types</h3><p><span style="margin:0px;padding:0px;">There are numerous insurance products made to specifically cater to the needs of lawyers and law firms. Here is a non-exhaustive list of a few of the more helpful </span><a style="text-decoration:none;" href="https://lawyerist.com/finance/insurance/" target="_blank" rel="noreferrer noopener"><span style="margin:0px;padding:0px;"><u>ancillary coverages</u></span></a><span style="margin:0px;padding:0px;">:&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Commercial umbrella insurance, like a personal umbrella policy, would step in and cover damages that exceed the policy limit on your BOP.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Accounts receivable general business insurance provides protection if your accounts receivable data is lost. It can also provide coverage for interest on a loan you had to take out to offset uncollected monies.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Valuable papers and records insurance is valuable if your firm has several physical files. This policy covers the replacement cost of your records if the same were lost due to a covered peril.&nbsp;</span></p><p><span style="margin:0px;padding:0px;">Employee dishonesty insurance provides coverage in the event an employee commits fraud or embezzlement.&nbsp;</span></p><p style="text-align:left;"><i><span style="margin:0px;padding:0px;">The Missouri Bar has assembled scores of resources for members looking to </span></i><a style="text-decoration:none;" href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Protect_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Protect_a_Practice.aspx" target="_blank" rel="noreferrer noopener"><i><span style="margin:0px;padding:0px;"><u>protect a practice</u></span></i></a><i><span style="margin:0px;padding:0px;">. Members can learn more about the insurance options available from Missouri Bar member benefit providers </span></i><a style="text-decoration:none;" href="https://mobar.org/site/content/Lawyer-Resources/Member_Benefits/Plan-Insure.aspx" target="_blank" rel="noreferrer noopener"><i><span style="margin:0px;padding:0px;"><u>here</u></span></i></a><i><span style="margin:0px;padding:0px;">. The Bar Plan is a proud Missouri Bar member benefit provider and the only endorsed carrier of </span></i><a style="text-decoration:none;" href="https://www.thebarplan.com/products/malpractice-insurance/" target="_blank" rel="noreferrer noopener"><i><span style="margin:0px;padding:0px;"><u>Professional Liability Insurance</u></span></i></a><i><span style="margin:0px;padding:0px;"> for The Missouri Bar.</span></i><span style="margin:0px;padding:0px;">&nbsp;</span></p>]]></description><category><![CDATA[molawyers,PracticeManagement,LPMProtect,LPMManagement,LPMBuild]]></category>
            <pubDate>Wed, 12 Jan 2022 06:00:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-lpm-insurance.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-lpm-insurance.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-lpm-insurance.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_LPM_Insurance]]></pp:imageTitle></item><item>
                        <title>Lawyers need insurance too: cyber liability insurance</title>
                        <link>https://news.mobar.org/lawyers-need-insurance-too-cyber-liability-insurance/</link>
                        <guid>https://news.mobar.org/lawyers-need-insurance-too-cyber-liability-insurance/</guid><pp:caseid>487369</pp:caseid><description><![CDATA[<p><strong>By&nbsp;Charles Coffey,&nbsp;The Bar Plan Mutual Insurance Company&nbsp;</strong></p><p><em>This is the&nbsp;second article of a three-part series from The Bar Plan Mutual Insurance Company. The&nbsp;<a href="https://news.mobar.org/lawyers-need-insurance-too-legal-malpractice-insurance/">first&nbsp;part (about legal malpractice insurance)</a> ran&nbsp;Dec.&nbsp;15&nbsp;and the third part&nbsp;will run&nbsp;Jan. 12, 2022. In the series, the author will describe the common types of insurance that lawyers and law firms should consider purchasing. The coverages included in this series are by no means an exhaustive list but are intended to provide you with a starting point to determine the coverages that are necessary for you and/or your firm. &nbsp;</em></p><h3>Cyber&nbsp;liability&nbsp;insurance&nbsp;</h3><p>Coalition, one of the largest providers of cyber insurance in the United States,&nbsp;<a href="https://info.coalitioninc.com/rs/566-KWJ-784/images/DLC-2021-07-Coalition-Cyber-Insurance-Claims-Report-2021-h1.pdf" rel="noreferrer noopener">reports</a>&nbsp;that cybercrime &ldquo;is increasing like never before.&rdquo; The most&nbsp;common&nbsp;claim Coalition&nbsp;sees&nbsp;is business email compromise, with the average claim costing $37,000. Funds transfer fraud was the next most common, with the average amount of funds stolen being $247,000. Ransomware incidents have also increased, with the average ransomware demand being a whopping $1.2 million and the average ransomware claim costing $184,000.&nbsp;</p><p>Most notably, Coalition reports that attacks are becoming increasingly automated, so&nbsp;it&rsquo;s easier and more profitable for attackers to target medium and small businesses. Claims made against business with under 250 employees increased 57% from the first half of 2020 to 2021,&nbsp;according to Coalition.&nbsp;</p><p>Business and tax consultant firm&nbsp;PBMares&nbsp;has a great summary of the common coverages to look for in a cyber liability policy&nbsp;<a href="https://www.pbmares.com/cyber-insurance-small-businesses/" rel="noreferrer noopener">here</a>. At The Bar Plan, we recommend that you consider the following factors when assessing&nbsp;<a href="https://www.thebarplan.com/products/cyber-increased-limits/" rel="noreferrer noopener">cyber liability coverage</a>:&nbsp;&nbsp;</p><ul><li><p>Does the policy provide full unknown prior acts coverage?&nbsp;</p></li><li><p>Are there separate&nbsp;limits for&nbsp;breach&nbsp;event&nbsp;costs&nbsp;(such as notification to clients)&nbsp;and&nbsp;additional&nbsp;defense&nbsp;costs&nbsp;(such as attorneys&rsquo; fees for any suit brought against you)?&nbsp;</p></li><li><p>Is there coverage&nbsp;for data that is stored with third parties?&nbsp;</p></li><li><p>Is the coverage worldwide?&nbsp;</p></li><li><p>Does the policy include&nbsp;proactive breach response costs and voluntary notification?&nbsp;</p></li></ul><ul><li><p>Does the policy cover&nbsp;the cost of providing credit monitoring services, identity theft assistance services, credit or identity repair,&nbsp;and restoration services to affected parties?&nbsp;</p></li><li><p>Does the policy provide&nbsp;system&nbsp;failure&nbsp;coverage, and does it&nbsp;apply&nbsp;to voluntary shutdowns&nbsp;that are necessary to protect your data?&nbsp;</p></li><li><p>Does the policy&rsquo;s property&nbsp;damage exclusion apply to electronic data&nbsp;(you do not want it to)?&nbsp;</p></li><li><p>Does the coverage apply&nbsp;to&nbsp;breach of corporate information&nbsp;of all types?&nbsp;</p></li><li><p>Does the policy cover&nbsp;acts&nbsp;committed&nbsp;by rogue employees?&nbsp;</p></li></ul><ul><li><p>Does the policy cover privacy claims&nbsp;brought&nbsp;by employees?&nbsp;</p></li><li><p>Is there an extended reporting period on the policy?&nbsp;</p></li></ul><p>Most cyber liability policies provide first and third-party coverage. First-party coverage protects you from damages incurred by cyber liability events, while third-party coverage protects your clients and others affected by a cyber event. In that regard, consider whether the policy you&rsquo;re looking to purchase includes the following types of coverage in each category.&nbsp;</p><h3>First-party&nbsp;coverage&nbsp;components&nbsp;</h3><ul><li><p>Breach event&nbsp;and remediation&nbsp;costs&nbsp;</p></li><li><p>Damages to your brand/reputation/image&nbsp;</p></li><li><p>System failure(s)&nbsp;</p></li><li><p>Cyber extortion (ransomware)&nbsp;</p></li></ul><ul><li><p>Cybercrime (fraudulent funds transfer)&nbsp;</p></li><li><p>Complete failure/loss of electronic equipment&nbsp;</p></li><li><p>Property damage loss&nbsp;</p></li><li><p>Payment of a reward for the provision of information&nbsp;</p></li><li><p>Court attendance costs&nbsp;</p></li></ul><ul><li><p>Business Interruption&nbsp;</p></li></ul><h3>Third-party&nbsp;liability&nbsp;coverage&nbsp;components&nbsp;</h3><ul><li><p><a href="https://societyinsurance.com/blog/multimedia-liability-insurance/" rel="noreferrer noopener">Multimedia&nbsp;liability</a>&nbsp;(copyright, libel, slander, etc.)&nbsp;</p></li><li><p><a href="https://amtrustfinancial.com/AmtrustFinancial/media/AFSI/PDFs/Financial%20Institutions/AFSI_Financial-Institutions_Network-Security-and-Privacy-Liability-Coverage_Summary.pdf" rel="noreferrer noopener">Security &&nbsp;privacy&nbsp;liability</a>&nbsp;(the failure to protect a customer&rsquo;s information)&nbsp;</p></li></ul><ul><li><p>Regulatory&nbsp;defense and&nbsp;penalties (fines and defense expenses from regulatory agencies)&nbsp;</p></li><li><p>PCI DSS (Payment&nbsp;card&nbsp;industry&nbsp;data&nbsp;security&nbsp;standard)&nbsp;liability&nbsp;</p></li><li><p>Bodily&nbsp;injury&nbsp;liability&nbsp;</p></li><li><p>Property&nbsp;damage&nbsp;liability&nbsp;</p></li><li><p>A TCPA (Telephone Consumer Protection Act) defense&nbsp;</p></li></ul><p>The cost of cyber liability insurance has risen dramatically over the past year. However, as demonstrated above, the potential liability is great. There are many cyber liability products in the market, both from traditional insurance companies and new &ldquo;insurtechs&rdquo; that leverage technology to write cyber liability policies with the backing of larger, established insurance companies. It is worth talking to a few different entities about cyber liability insurance until you find one that meets your needs.&nbsp;</p><p><em>The Missouri Bar has assembled scores of resources for members looking to&nbsp;<a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Protect_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Protect_a_Practice.aspx" rel="noreferrer noopener">protect a practice</a>.&nbsp;Members can learn more about the insurance options available from Missouri Bar member benefit providers&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Member_Benefits/Plan-Insure.aspx" rel="noreferrer noopener">here</a>. The Bar Plan is a proud Missouri Bar member benefit provider and the only endorsed carrier of&nbsp;<a href="https://www.thebarplan.com/products/malpractice-insurance/" rel="noreferrer noopener">Professional Liability Insurance</a>&nbsp;for The Missouri Bar.</em></p>]]></description><category><![CDATA[LPMTech,LPMProtect,PracticeManagement,molawyers]]></category>
            <pubDate>Wed, 29 Dec 2021 06:00:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-lpm-cyberliabilityprotection.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-lpm-cyberliabilityprotection.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-lpm-cyberliabilityprotection.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_LPM_Cyber Liability Protection]]></pp:imageTitle></item><item>
                        <title>Lawyers need insurance too: legal malpractice insurance</title>
                        <link>https://news.mobar.org/lawyers-need-insurance-too-legal-malpractice-insurance/</link>
                        <guid>https://news.mobar.org/lawyers-need-insurance-too-legal-malpractice-insurance/</guid><pp:caseid>485900</pp:caseid><description><![CDATA[<p><strong><span><span><span>By Charles Coffey and Deanna Brady, The Bar Plan Mutual Insurance Company</span></span></span></strong></p><p><span><span><span><em>This is the first article of a three-part series from The Bar Plan Mutual Insurance Company. The second part will be published Dec. 29 and the third part Jan. 12, 2022. In the series, the authors will describe the common types of insurance that lawyers and law firms should consider purchasing. The coverages included in this series are by no means an exhaustive list but are intended to provide you with a starting point to determine the coverages that are necessary for you and/or your firm.</em> </span></span></span></p><p><span><span><span>Legal malpractice claims arise from a lawyer&rsquo;s actions or omissions falling below the standard of care when providing legal services to a client. So, how necessary is it to get Lawyers&rsquo; Professional Liability &ldquo;LPL&rdquo; Insurance &ndash; a.k.a. legal malpractice insurance? I would argue it&rsquo;s essential based on the risk shown by recent data.</span></span></span></p><p><span><span><span>The Missouri Department of Commerce & Insurance publishes a Legal Malpractice Insurance Report once a year and it recently released the <a href="https://insurance.mo.gov/reports/legmal/" style="text-decoration:underline">2020 report</a>. In 2020, 138 legal malpractice claims were closed, with 63 resulting in payments totaling $11.6 million. The average payment for a successful claim was $184,606.</span></span></span></p><p><span><span><span>Nearly 97% of paid claims involved lawyers who had been practicing for 10 years or more. The areas of practice that saw the most claims were bodily injury/property damage &ndash; plaintiff; estate, trust, and probate; family law; bodily injury/property damage &ndash; defendant; and collection and bankruptcy.</span></span></span></p><p><span><span><span>Deanna Brady, senior claims counsel at The Bar Plan, previously <a href="https://www.thebarplan.com/underinsured-lawyers/" style="text-decoration:underline">wrote an article</a> that summarized some of the factors to look for when purchasing an LPL policy. She emphasized that when making the decision on the amount of policy limits for legal malpractice insurance, there are many factors to consider, including the:</span></span></span></p><ul><li><span><span><span>potential exposure based upon the types of cases,</span></span></span></li><li><span><span><span>cost of defense of a legal malpractice claim,</span></span></span></li><li><span><span><span>jurisdiction in which a claim could be brought, and</span></span></span></li><li><span><span><span>nature and extent of both business and personal assets as they could potentially be subject to collection under a judgment if the lawyer is underinsured.</span></span></span></li></ul><h4><span><span><span><strong>&ldquo;High risk&rdquo; areas of practice</strong></span></span></span></h4><p><span><span><span>When considering lawyers&rsquo; professional liability insurance, certain areas of practice &ndash; such as trusts and estates, plaintiff&rsquo;s personal injury, securities, and intellectual property &ndash; may carry a higher risk in terms of the likelihood of a legal malpractice claim or the cost to defend or resolve the claim. Many lawyers believe the risk of claims being filed against them is minimal. However, mistakes happen. Some may find themselves in a situation where they are liable for not only their own mistakes, but also mistakes by a partner, associate, paralegal, or legal assistant within their firms.</span></span></span></p><p><span><span><span>In addition to evaluating potential exposure based on the types of current cases your or your law firm handles, lawyers should also consider past cases &ndash; this is especially true for those that practice in trusts and estates. It may be that the lawyer no longer represents large estates. Therefore, he or she may believe lower limits of liability are now appropriate. However, trusts and estates pose more risks for legal malpractice claims as non-client beneficiaries may have standing to sue. Additionally, the statute of limitations may not begin until the death of the client and the alleged negligence is discovered. As most lawyers&rsquo; professional liability policies are claims-made and reported policies, lawyers could be exposed to potential liability from estate planning conducted decades in the past. If the estate was a large estate, the lawyer may not be adequately insured to pay the client or the third-party beneficiary completely or defend the merits of the claim based upon current limits of liability.</span></span></span></p><h4><span><span><span><strong>The cost to defend &ndash; even in other jurisdictions</strong></span></span></span></h4><p><span><span><span>When choosing policy limits, a lawyer should be concerned about the potential damages that may stem from a potential lawsuit, as well as the cost to defend the lawsuit. Most legal malpractice insurance policies, unless a separate defense expense limit is purchased, are eroding policies. These policies are also referred to as wasting or &ldquo;pac-man&rdquo; policies because the limits of liability are reduced by the cost for defense and any expenses incurred.</span></span></span></p><p><span><span><span>The defense expenses are paid first, which reduces the amount available to pay any potential damages. If the policy limits are exhausted by the defense costs, the insurance carrier may have no further duty to defend an insured lawyer, and there will be no limits remaining to pay on any judgment or settlement later reached. When this occurs, the insured lawyer&rsquo;s business and personal assets could potentially be subject to collection under a judgment. If limits of liability are very low, it is possible that the costs of defense would exceed the policy limits; thus, making it very difficult for the lawyer to defend their actions.</span></span></span></p><p><span><span><span>It is also possible for a lawsuit to be filed in another, more costly jurisdiction, than the jurisdiction in which the lawyer practices. While the insured lawyer&rsquo;s policy limits may be adequate to properly defend a claim and/or make an indemnity payment in the lawyer&rsquo;s practicing jurisdiction, the same may not be said for the foreign jurisdiction.</span></span></span></p><h4><span><span><span><strong>Office sharing</strong></span></span></span></h4><p><span><span><span>If lawyers who share an office look like a firm to potential clients, it is possible for the negligence of one of the lawyers to be imputed to others who share the office. While steps should be taken to avoid any confusion, be aware of the potential damages that may stem from the liability of the other lawyers in the office. While one lawyer may practice in an area of law that poses low risk for legal malpractice claims, the same may not be said for other lawyers who share the office. If a claim is made against one for the negligence of another in an office-sharing group, lawyers may find they do not have adequate coverage to defend the claim or to make an indemnity payment.</span></span></span></p><h4><span><span><span><strong>Common misconceptions</strong></span></span></span></h4><p><span><span><span>A common misconception about legal malpractice claims is that having more insurance coverage would invite larger claims. However, if the limits of liability are low, an opposing lawyer may use that to their advantage and make an inflated opening demand to leverage their client for maximum recovery. While it is difficult to plan for this type of tactic, it is easier to defend the claim on its merits if sufficient limits of liability are in place.</span></span></span></p><p><span><span><span>While the lawyer and the insurance carrier want to compensate the claimant for the malpractice, given the low limits, the lawyer may not have the opportunity to dispute the damages or the merits of the underlying case. The lawyer may find themselves in a situation where a decision is made to pay the policy limits to the claimant rather than argue over damages and reduce the available limits for a potential judgment or settlement. Having adequate policy limits ensures that the insured lawyer can properly defend or settle a claim on its merits and not based on the amount of policy limits available.</span></span></span></p><p><span><span><span>Finally, when contemplating your limits of liability, consider all potential exposure based on your clients and the costs of defense for a legal malpractice claim. Being adequately insured affords lawyers the opportunity to make clients whole should a mistake occur, as well as defend themselves and their actions &ndash; especially when liability is questionable.</span></span></span></p><p><span><span><span><em>The Missouri Bar has scores of resources for members looking to</em> <a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Protect_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Protect_a_Practice.aspx" style="text-decoration:underline"><em>protect a practice</em></a><em>. Members can learn more about the insurance options available from Missouri Bar member benefit providers</em> <a href="https://mobar.org/site/content/Lawyer-Resources/Member_Benefits/Plan-Insure.aspx" style="text-decoration:underline"><em>here</em></a><em>. The Bar Plan is a proud Missouri Bar member benefit provider and the only endorsed carrier of</em> <a href="https://www.thebarplan.com/products/malpractice-insurance/" style="text-decoration:underline"><em>Professional Liability Insurance</em></a> <em>for The Missouri Bar.</em></span></span></span></p>]]></description><category><![CDATA[molawyers,PracticeManagement,LPMProtect]]></category>
            <pubDate>Wed, 15 Dec 2021 06:00:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-legalmalpracticeinsurance.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-legalmalpracticeinsurance.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-legalmalpracticeinsurance.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_Legal malpractice insurance]]></pp:imageTitle></item><item>
                        <title>Documenting business processes creates perfect &#039;cookbook&#039;</title>
                        <link>https://news.mobar.org/documenting-business-processes-creates-perfect-cookbook/</link>
                        <guid>https://news.mobar.org/documenting-business-processes-creates-perfect-cookbook/</guid><pp:caseid>477193</pp:caseid><description><![CDATA[<p><span><span><span><span>By</span> <a href="mailto:MoBarLPM@affinityconsulting.com?subject=Process%20Mapping%20Blog" style="text-decoration:underline"><span class="Link"><u><span>Jeffrey Schoenberger</span></u></span></a><span>, senior consultant at Affinity Consulting Group LLC</span></span></span></span></p><p><span><span><span><span>Depending on your firm&rsquo;s size, you may be one of several people, one of a few, or the only person who know how to do important firm tasks. This compartmentalization has strengths and weaknesses. For example, limiting access to financial accounts reduces the possibility of theft or falling victim to a phishing or wire fraud scheme. Compartmentalization is a form of security. On the other hand, core business functions must continue even if the managing partner, office manager, or other high-ranking employee is unavailable or compelled to take an extended, unplanned absence. Most such events are unhappy occasions &ndash; perhaps an illness impacting the employee or an elderly parent&rsquo;s health. You can&rsquo;t put off payroll, health insurance premiums, or rent payments indefinitely because the person who &ldquo;always does that&rdquo; is unavailable for an indefinite period.</span></span></span></span></p><p><span><span><span><span>Moving from the grim to the practical, unlock the knowledge stored in each staffer&rsquo;s head, including your own, by documenting fundamental business processes. This brings several advantages:</span></span></span></span></p><ol><li><span><span><span><span>Nobody needs to be interrupted while on vacation because a coworker couldn&rsquo;t complete a form or find something;</span></span></span></span></li><li><span><span><span><span>The firm has a resource to help train new hires;</span></span></span></span></li><li><span><span><span><span>The simple act of documenting your processes naturally leads you and your team to evaluate whether that process still makes sense; and</span></span></span></span></li><li><span><span><span><span>If you are a solo or small firm, when you choose to retire, your &ldquo;process cookbook&rdquo; adds value to the firm, offering interested parties something beyond a rolodex to buy (see this</span> <a href="https://news.mobar.org/succession-and-contingency-planning-for-lawyers/" style="text-decoration:underline"><span class="Link"><u><span>related blog</span></u></span></a> <span>on succession planning for lawyers firms).</span></span></span></span></li></ol><h3><strong>Step by step</strong></h3><p><span>When working with firms to create good processes, I&rsquo;ve found it helpful to speak in terms of a &ldquo;cookbook&rdquo; and &ldquo;recipes&rdquo; rather than &ldquo;manuals&rdquo; or &ldquo;process maps.&rdquo; Familiar vocabulary helps make what could be seen as a remote and unfamiliar activity more approachable. We&rsquo;ve listed out what you need to complete a task (&ldquo;ingredients&rdquo;) and the order in which you do things to get the right result (the &ldquo;steps&rdquo; in our &ldquo;recipe&rdquo;). We&rsquo;ll also group similar recipes together for easier locating later (our &ldquo;cookbook&rdquo;). Here&rsquo;s an example:</span></p><p><span><span><span><strong><u><span><span>Returning original documents to a client</span></span></u></strong><br /><span>Hopefully your firm has embraced paperless practicing. (If not, see this</span> <a href="https://news.mobar.org/paperless-practice-tips/" style="text-decoration:underline"><span class="Link"><u><span>blog</span></u></span></a> <span>to get started down that path.) A core part of a paperless firm (or paper less if you&rsquo;re still transitioning) is keeping those original documents you need for specific reasons &ndash; such as something that statutorily requires an original document &ndash; and returning all other original documents to the client.</span></span></span></span></p><p><span><span><span><strong><u><span>Ingredients</span></u></strong><br /><span>To send originals back to the client, we need the following ingredients:</span></span></span></span></p><ul><li class="UnorderedList"><span><span><span><span><span>the original documents;</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><span>name and address of the client;</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><span>a cover letter;</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><span>a mailing label; and</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><span>an appropriate envelope or other shipping container.</span></span></span></span></span></li></ul><p><span><span><span><strong><u><span>Steps</span></u></strong><br /><span>Here are the steps to prepare and mail the documents:</span></span></span></span></p><ol><li class="OrderedList"><span><span><span><span><span>Confirm that the documents are scanned and in the firm&rsquo;s document repository.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Decide how documents will be sent (<em>e.g.,</em> US Mail,</span> <a href="http://www.savewithups.com/mobar/" style="text-decoration:underline"><span>UPS</span></a><span>, etc.).</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Place documents in an appropriate envelope or shipping container.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Prepare a mailing label with the appropriate delivery service.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Open the cover letter template. If your firm doesn&rsquo;t use document templates, see the</span> <a href="https://connect.mobar.org/viewdocument/why-template-building-is-critical-f?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" style="text-decoration:underline"><span class="Link"><u><span>Why Template Building is Critical for All Law Offices</span></u></span></a> <span>white paper and the &ldquo;how to&rdquo; checklist on</span> <a href="https://connect.mobar.org/viewdocument/document-automation?LibraryFolderKey=13055251-fe4c-41fa-939a-952c1935d023&DefaultView=folder" style="text-decoration:underline"><span class="Link"><u><span>Getting Started with Document Automation</span></u></span></a><span>.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Type in the client&rsquo;s information, method of delivery, and delivery tracking information.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>If you don&rsquo;t have a digital signature stamp, print the document for the sender to sign. If you do have digital signature stamps, apply the appropriate stamp to the document and print the letter. To learn more about digital signatures, take</span> <a href="https://mobarcle.mobar.org/item/2021-electronic-document-security-digital-signatures-431660" style="text-decoration:underline"><span class="Link"><u><span>this CLE</span></u></span></a><span>.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Place the cover letter in the envelope or shipping container.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Seal the envelope or container.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Place the mailing label on the envelope or container.</span></span></span></span></span></li><li class="OrderedList"><span><span><span><span><span>Place the envelope or container in the outbox or call for a pickup, as appropriate.</span></span></span></span></span></li></ol><p><span><span><span><span>With that, we&rsquo;ve written our first recipe together or, in business-speak, mapped our first process. You can probably already imagine similar recipes or processes that would accompany this one in a cookbook or employee manual: sending and receiving intake forms from new clients; sending and receiving discovery documents; and sending paper invoices and receipts of payment.</span></span></span></span></p><h3><strong>Learning along the way</strong></h3><p><span>The first time you and your team sit down and document the steps in fundamental processes &ndash; such as taking information from a client and generating draft corporate formation documents or estate planning documents for a lawyer to review &ndash; will take a while. Here are two tips to make this process easier:</span></p><p class="UnorderedList"><span><span><span><u><strong><span>Tip 1:</span></strong></u> <span>Have the people who do the work lead that portion of the mapping. In our &ldquo;returning originals&rdquo; recipe above, if one person is responsible for drafting correspondence, that person takes the lead in outlining what happens <em><span>currently</span></em>. You gain nothing substantive by just having higher-ups guess or declaim what the process <em><span>is or should be</span></em>. There&rsquo;s a reason the process works this way now. It could be good. For example, the typist always asks the lawyer for the client&rsquo;s address because the firm&rsquo;s central client address book is reliably inaccurate or incomplete. Or it could be bad. For example, the typist doesn&rsquo;t look up the address in the central client address book because that person was never trained how to do so or lacks access to the system. The first step is knowing what happens now.</span></span></span></span></p><p class="UnorderedList"><span><span><span><u><strong><span>Tip 2:</span></strong></u> <span>Through the process mapping exercise, you will discover things you&rsquo;ll want to note for later examination or remediation. In reading our &ldquo;returning originals&rdquo; recipe above, maybe you learned about document templates for the first time. Creating a template so typists don&rsquo;t continually recreate cover letters from scratch would save time. Same thing with digital signature stamps. Make a note and set it aside as two things to investigate for process improvement.</span></span></span></span></p><p class="UnorderedList"><span><span><span><span>In the case of our typist lacking training or access to the client address book, that&rsquo;s a remediation issue. Granting access is likely either a few clicks or the purchase of an additional license. If it&rsquo;s a training issue, most vendors are happy to help train employees on their products. It&rsquo;s a simple thing to solve.</span></span></span></span></p><p><span><span><span><span>Having the employees on the &ldquo;front lines&rdquo; leading the relevant process mapping gives you an honest view of what happens now, offering you the clearest perspective of where potential changes might bring great long-term gains or quickly eliminate initially unnoticed bottlenecks.</span></span></span></span></p><h3><strong>Getting started</strong></h3><p><span>Head over to our</span> <a href="https://mobar.org/lpm" style="text-decoration:underline"><span>Practice Management Center</span></a> <span>to get started making your recipes for business success. Here are resources to guide the way:</span></p><ul><li class="UnorderedList"><span><span><span><span><a href="https://connect.mobar.org/viewdocument/everything-has-a-process-part-1-h?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" style="text-decoration:underline"><span class="Link"><u><span>Everything has a Process Part 1 - How to Identify Yours</span></u></span></a><span>: This whitepaper includes process mapping tips.</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><a href="https://connect.mobar.org/viewdocument/everything-has-a-process-part-2-h?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" style="text-decoration:underline"><span class="Link"><u><span>Everything has a Process Part 2 - How to Improve Yours</span></u></span></a><span>: This whitepaper discusses breaking large processes into smaller ones.</span></span></span></span></span></li><li class="UnorderedList"><span><span><span><span><a href="https://connect.mobar.org/viewdocument/process-workflow-worksheet-with-sam?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" style="text-decoration:underline"><span class="Link"><u><span>Process Workflow Worksheet with Sample Workflow</span></u></span></a><span>: This Excel document will guide you through documenting each step in a process.</span></span></span></span></span></li></ul><p><span><span><span><em><span><span>Missouri Bar members have access to hundreds of white papers, checklists, comparison charts, and articles for those looking to</span></span></em> <a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Open_a_Practice.aspx" style="text-decoration:underline"><em><span>open</span></em></a><em><span><span>,</span></span></em> <a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Build_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Build_a_Practice.aspx?" style="text-decoration:underline"><em><span>build</span></em></a><em><span><span>,</span></span></em> <a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Manage_a_Practice.aspx" style="text-decoration:underline"><em><span>manage</span></em></a><em><span><span>,</span></span></em> <a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Protect_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Protect_a_Practice.aspx" style="text-decoration:underline"><em><span>protect</span></em></a><em><span><span>, or</span></span></em> <a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/Wind_Down_a_Practice/site/content/Lawyer-Resources/Law_Practice_Management/Wind_Down_a_Practice.aspx" style="text-decoration:underline"><em><span>wind down</span></em></a> <em><span><span>a law practice. Have questions? At no cost, members can</span></span></em>&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Ask_an_Expert.aspx" style="text-decoration:underline"><em><span><span>ask an expert</span></span></em></a>&nbsp;<em><span><span>their legal technology or practice management questions via email or by scheduling a one-on-one, remote consultation.</span></span></em></span></span></span></p>]]></description><category><![CDATA[molawyers,PracticeManagement,LPMManagement,LPMProtect,LPMPracticeMgmt,LPMBuild,MOLawyersBenefit]]></category>
            <pubDate>Wed, 20 Oct 2021 07:00:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_lawfirmprocessescookbook.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_lawfirmprocessescookbook.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/lawfirmprocessescookbook.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Law Firm Processes Cookbook]]></pp:imageTitle></item><item>
                        <title>The importance of secure communication in 2021</title>
                        <link>https://news.mobar.org/the-importance-of-secure-communication-in-2021/</link>
                        <guid>https://news.mobar.org/the-importance-of-secure-communication-in-2021/</guid><pp:caseid>459288</pp:caseid><description><![CDATA[<p><strong>By Niki Black, MyCase&nbsp;</strong></p><p>Lawyers have an ethical obligation to preserve client confidentiality. For that reason, the need to protect client&nbsp;information&nbsp;has always been a top priority for lawyers. This means that when lawyers and their staff work remotely &ndash; a practice that has become commonplace due to the pandemic &ndash;&nbsp;it&rsquo;s&nbsp;all the more imperative for lawyers to ensure that confidential client data is protected when communicating electronically.&nbsp;</p><p>Because so many lawyers and staff have worked remotely over the past year,&nbsp;law firms have increasingly relied on online communication and collaboration tools when interacting with clients. Of course, this newfound uptick in the use of electronic communication methods&nbsp;has&nbsp;impacted the ethical obligations that lawyers have when it comes to preserving client confidentiality.&nbsp;That&rsquo;s&nbsp;why it&rsquo;s important for law firm leaders to understand cybersecurity issues and how&nbsp;those problems&nbsp;may affect their displaced workforces, especially since lawyers and other law firm employees will likely continue working&nbsp;remotely and communicating&nbsp;electronically for many more months. The good news is law firms have solid options when it comes to secure online communication.&nbsp;</p><h3><strong>Client portals: a more secure option than email&nbsp;</strong></h3><p>Since the mid-1990s, lawyers have communicated with clients via electronic means, and for many years email was an accepted way to interact with clients electronically. However, because email is inherently unsecure and is&nbsp;like&nbsp;sending a&nbsp;hand-written&nbsp;postcard through the post office, it has begun to fall out of favor &ndash; both ethically and practically &ndash; as technology&nbsp;continues to&nbsp;improve.&nbsp;</p><p>That&rsquo;s&nbsp;why ethics committees and cybersecurity security experts have increasingly recommended methods other than unencrypted email when communicating and collaborating with clients online. For example, in 2017, the American Bar Association Committee on Professional Ethics <a href="https://www.mycase.com/blog/2017/05/new-aba-ethics-standard-on-email-communication-with-clients/" rel="noreferrer noopener">concluded in ABA Opinion 477R</a> that due to &ldquo;cyber-threats and (the fact that) the proliferation of electronic communications devices&nbsp;have&nbsp;changed the landscape&nbsp;&hellip;&nbsp;it is not always reasonable to rely on the use of unencrypted email.&rdquo; Instead, the&nbsp;committee recommended that for particularly sensitive matters,&nbsp;lawyers should consider using encrypted communications,&nbsp;including encrypted email and the encrypted client communication portals built into&nbsp;law practice management software.&nbsp;</p><h3><strong>Florida issues secure communication guide&nbsp;</strong></h3><p>Recently,&nbsp;The Florida Bar issued an updated secure communications guide that included recommendations relating to remote work during the pandemic. This comprehensive guide, &ldquo;<a href="https://www-media.floridabar.org/uploads/2020/06/ADA-E-communication-FINAL_May-2020.pdf" rel="noreferrer noopener">Best Practices for Professional Electronic Communication</a>,&rdquo;offers&nbsp;an in-depth&nbsp;overview of the issues that arise when lawyers communicate and collaborate with clients electronically. The types of electronic communications addressed in the guide include texting, email, social media, telephones and cellphones, laptops, and court appearances via videoconference.&nbsp;</p><h4><strong>Email is easily&nbsp;hacked&nbsp;</strong></h4><p>The authors&nbsp;of The Florida Bar&rsquo;s communications guide&nbsp;focused on the technology issues that lawyers need to keep in mind when communicating with clients&nbsp;through&nbsp;unencrypted email.&nbsp;An important factor emphasized in the guide was the need for lawyers to understand the risks associated with using technology, including email.&nbsp;The authors emphasized how unsecure traditional email is and encouraged lawyers to find a more secure way of communicating with clients.&nbsp;</p><p>As they explained, the reason for this recommendation is that email is easily hacked.&nbsp;That&rsquo;s&nbsp;why, according to the authors, if the situation should arise where a lawyer must use email, it&rsquo;s important to scan each and every email that is received and sent: &ldquo;Attachments may contain malicious software code. Use scanning software for both outbound and inbound emails.&rdquo;&nbsp;</p><h4><strong>Emails can be easily&nbsp;intercepted&nbsp;</strong></h4><p>The authors also addressed the likelihood of&nbsp;bad actors&nbsp;interfering&nbsp;when using email. They cautioned that because email is inherently unsecure, it can be easily intercepted. Fortunately, they explained, one way to mitigate that risk is to use an encrypted email service: &ldquo;There is always a chance that your email may be intercepted. Many of these risks are mitigated if not entirely eradicated when using an encrypted email service.&rdquo;&nbsp;</p><p>Of course, email encryption technology often requires the assistance of an IT expert with the ability to set up this type of system &ndash; something that can oftentimes be a complex endeavor. Nevertheless, for some law firms, encrypted email can be a viable option.&nbsp;</p><h4><strong>Client ports are a secure and easy-to-use form of&nbsp;communication&nbsp;</strong></h4><p>The authors&nbsp;also&nbsp;turned to secure client portals.&nbsp;Due&nbsp;to&nbsp;the risks inherent in email, they recommended that lawyers consider using secure client portals like the ones built into law practice management software. They shared that client portals are a secure, safe, and easy-to-use alternative that is one of the best ways to ensure that confidential information is preserved whenever you communicate and collaborate online with clients: &ldquo;Secure client portals are an emerging and safe alternative to email. There are many case and practice management systems&nbsp;that offer a client portal component. You should seriously consider this option as a method of communication for confidential information.&rdquo;&nbsp;</p><p>Missouri Bar&nbsp;members&nbsp;receive discounted rates from&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Member_Benefits/Build-Manage.aspx" rel="noreferrer noopener">top practice management&nbsp;solutions</a>&nbsp;including&nbsp;<a href="http://bit.ly/MyCaseMissouriBar" rel="noreferrer noopener">MyCase</a>.&nbsp;To find&nbsp;the&nbsp;practice management solution that&rsquo;s best for you,&nbsp;check out&nbsp;The Missouri Bar&rsquo;s&nbsp;<a href="https://connect.mobar.org/viewdocument/practice-management-feature-conside?LibraryFolderKey=13055251-fe4c-41fa-939a-952c1935d023&DefaultView=folder" rel="noreferrer noopener">practice management features checklist</a>,&nbsp;<a href="https://www.affinityconsulting.com/compare-cloud-practice-management/" rel="noreferrer noopener">cloud-based practice management comparison chart</a>&nbsp;and&nbsp;<a href="https://www.affinityconsulting.com/compare-traditional-practice-management/" rel="noreferrer noopener">traditional practice management&nbsp;comparison chart</a>.&nbsp;Need&nbsp;additional&nbsp;help selecting a practice management solution?&nbsp;Members can schedule a&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Ask_an_Expert.aspx">no-cost, one-on-one consultation</a>&nbsp;with the experts at Affinity Consulting Group.&nbsp;&nbsp;</p><p><em>Reprinted with permission of&nbsp;MyCase.&nbsp;</em></p>]]></description><category><![CDATA[molawyers,PracticeManagement,LPMProtect,LPMTech,LPMPracticeMgmt,MOLawyersBenefit,LPMCyber]]></category>
            <pubDate>Wed, 16 Jun 2021 07:00:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-lpm-securecommunications.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-lpm-securecommunications.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-lpm-securecommunications.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_LPM_Secure Communications]]></pp:imageTitle></item><item>
                        <title>Where to start when succession planning</title>
                        <link>https://news.mobar.org/succession-and-contingency-planning-for-lawyers/</link>
                        <guid>https://news.mobar.org/succession-and-contingency-planning-for-lawyers/</guid><pp:caseid>444647</pp:caseid><description><![CDATA[<p><strong>By Danielle&nbsp;DavisRoe, Affinity Consulting Group&nbsp;</strong></p><p>Succession planning is all about leaving a legacy.&nbsp;Lawyers&nbsp;who built their firms&nbsp;from the ground up and who contributed blood, sweat, and tears&nbsp;to&nbsp;the firms deserve to leave their marks. Leaving your legacy requires years of strategic planning and decision making.&nbsp;</p><p>When considering your legacy, you must think about the people who will carry the torch once&nbsp;you&nbsp;retire, the core processes that keep business running smoothly, and how to successfully transition work and clients to those who follow in your footsteps.&nbsp;</p><p><strong>First Rate Players:</strong>&nbsp;You&nbsp;can&rsquo;t&nbsp;plan for succession without planning for those who will succeed you. Early identification of star players provides you with time to mold them into stellar leaders and rainmakers. The sooner you start working with these key players, the&nbsp;more time&nbsp;you have&nbsp;available&nbsp;to help shape them into whom the firm needs them to be.&nbsp;</p><p><strong>Fundamental Processes:</strong>&nbsp;Every firm is driven by numerous fundamental processes.&nbsp;Leaving a legacy requires identifying those processes and documenting every step&nbsp;in that process, from client intake to closing letter.&nbsp;<a href="https://connect.mobar.org/viewdocument/everything-has-a-process-part-1-h?" rel="noreferrer noopener">Process documentation</a>&nbsp;has immediate benefits. New hire on-boarding is more efficient, and process documentation helps get everyone in the firm on the same page.&nbsp;</p><p>While documenting processes, look for areas of&nbsp;<a href="https://connect.mobar.org/viewdocument/everything-has-a-process-part-2-h" rel="noreferrer noopener">potential improvement</a>&nbsp;and gaps in the firm&rsquo;s coverage. Ensure there is&nbsp;a backup for each task. Should someone suddenly leave the firm, you&nbsp;don&rsquo;t&nbsp;want to be left in the lurch.&nbsp;</p><p><strong>Future Transitions:</strong>&nbsp;Transitioning work and clients is never easy. The most successful transitions&nbsp;start&nbsp;before retirement is on the horizon.&nbsp;When possible, ensure that every client works with and trusts at least two&nbsp;lawyers&nbsp;in the firm. Your clients must be comfortable with your replacement before you decide to retire.&nbsp;</p><p>Train associates to handle every type of matter that comes in. Work side-by-side on the complicated matters and provide them guidance on how to handle the thorniest issues. Then, when you are ready to retire, they will be ready to handle the workload.&nbsp;</p><p><a href="https://connect.mobar.org/viewdocument/succession-planning" rel="noreferrer noopener">Succession planning</a>&nbsp;isn&rsquo;t&nbsp;easy. It requires strategic planning and must be kept in mind with every decision your firm makes. It is never too early to start planning for retirement.&nbsp;</p><p><em>Missouri Bar members can access&nbsp;white papers, checklists, and charts&nbsp;related to succession planning and process documentation,&nbsp;including the&nbsp;<a href="https://connect.mobar.org/viewdocument/planning-ahead-a-guide-to-protect" rel="noreferrer noopener">Planning Ahead Guide</a>,&nbsp;at&nbsp;<a href="https://mobar.org/lpm" rel="noreferrer noopener">mobar.org/LPM</a>.&nbsp; &nbsp;</em></p><p><em>Members&nbsp;can also&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Ask_an_Expert.aspx" rel="noreferrer noopener">email their questions to or set up a one-on-one remote consultation</a>&nbsp;with&nbsp;Affinity Consulting Group.&nbsp;</em></p>]]></description><category><![CDATA[PracticeManagement,molawyers,LPMManagement,LPMWindDown,LPMProtect,MOLawyersBenefit]]></category>
            <pubDate>Wed, 07 Apr 2021 07:00:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-successionplanningv24-6-21.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-successionplanningv24-6-21.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-successionplanningv24-6-21.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_Succession Planning V2 4-6-21]]></pp:imageTitle></item><item>
                        <title>Ethics: Moving between private practice and government service</title>
                        <link>https://news.mobar.org/ethics-moving-between-private-practice-and-government-service/</link>
                        <guid>https://news.mobar.org/ethics-moving-between-private-practice-and-government-service/</guid><pp:caseid>446112</pp:caseid><pp:subtitle>Vol. 77, No. 2 / Mar. - Apr. 2021</pp:subtitle><pp:summary><![CDATA[<p><em><span><span><span><span><span><span><span>Supreme Court Rule 4-1.11 is designed to limit potential ethical problems when lawyers move from government service to private practice and vice versa.</span></span></span></span></span></span></span></em></p>
]]></pp:summary><description><![CDATA[<p><span style="color:#000080;"><strong>Sharon K. Weedin</strong><br />Sharon K. Weedin is staff counsel for the Office of Chief Disciplinary Counsel in Jefferson City.</span></p><p>For example, the rule seeks to prohibit a lawyer who formerly worked for the government from improperly using confidential government information, say for the advantage of a future private client. The rule attempts to limit potential problems without unduly hampering the government&rsquo;s ability to recruit good lawyers, primarily by loosening the strict imputation rule.</p><p><strong>The Rule</strong></p><p>It may be helpful to categorize Rule 4-1.11&rsquo;s lettered subsections. Subsections (a), (b), and (c) are directed to lawyers who formerly served as government officers or employees. Subsection (d) addresses lawyers currently serving as government officers or employees. Subsection (e) applies to lawyers holding public office. Subsection (f) defines &ldquo;matter&rdquo; as it is used in Rule 4-1.11.</p><p>Subsection (a) prohibits a former employee of the government from representing a client in a matter in which the lawyer personally and substantially<a href="#2"><sup>2</sup></a> participated when the lawyer worked for the government, unless the government gives informed consent,<a href="#3"><sup>3</sup></a> confirmed in writing,<a href="#4"><sup>4</sup></a> to the representation. Additionally, the former government lawyer is subject to Rule 4-1.9(c), which prohibits use or revelation of information relating to a matter in which the lawyer formerly represented a client.</p><p>An example of a scenario contemplated by subparagraph (a) follows. Unless the Missouri Department of Natural Resources gives written, informed consent, a former staff lawyer for the department who, while a department lawyer, worked on a case alleging a company released pollutants into the waterways in violation of state regulations is prohibited, or should be disqualified, from defending the company against those allegations after going to work for a law firm.</p><p>In accordance with subparagraph (b), the law firm, which had been defending the company before it hired the lawyer from DNR&rsquo;s ranks, may continue representing the company if it promptly notifies DNR that the lawyer has become associated with the firm and timely screens the lawyer from any participation in the matter.<a href="#5"><sup>5</sup></a> The notice is intended to allow the government agency the opportunity to assure itself that proper screening has occurred. Further, the disqualified lawyer is prohibited from receiving any part of the fee directly relating to the representation.<a href="#6"><sup>6</sup></a> Continued representation by other lawyers in the firm, with notice and screening, is allowed here while it is not in a private practice to private practice scenario, where disqualification is imputed to all the lawyers in the new firm.<a href="#7"><sup>7</sup></a> The rationale for not imposing strict imputation in the government to private practice scenario is discussed in Comment 4. One factor is the fear that the stricter rule would inhibit government recruiting of qualified lawyers, who might shy away from government service if their future job prospects in the private sector are constrained by the prospect of a firm&rsquo;s loss of clients due to strict imputation.</p><p>Subsection (c) prohibits a lawyer who previously worked for the government, and who acquired &ldquo;confidential government information&rdquo;<a href="#8"><sup>8</sup></a> about a &ldquo;person&rdquo; while so employed, from representing a client whose interests are adverse to that person in a matter in which the confidential government information could be used to the material disadvantage of that person. The firm with which the disqualified lawyer is now associated is permitted the continued representation if the disqualified lawyer is screened and is apportioned no part of the fee directly related to the representation.</p><p>As an example, if a lawyer learns, while working as an assistant attorney general, that the individual is about to be indicted for tax fraud, the now former assistant attorney general could not use that confidential information, say in settlement negotiations, to the material disadvantage of the individual in the course of litigation while practicing in his or her new firm. Again, the restriction is not imputed to other members of the firm, who may litigate against the individual so long as the former assistant attorney general is screened and apportioned no fee directly from the litigation.</p><p>Subsection (d) applies to lawyers currently serving as public officers or employees and addresses conflicts the lawyers may have with former client matters. The lawyers now working for the government are subject to Rule 4-1.7, the concurrent conflict of interest rule. The lawyer is also subject to all the provisions of Rule 4-1.9. Subsection (d) thus counsels a lawyer moving from private practice into government service from handling matters the lawyer participated in &ldquo;personally and substantially&rdquo; while in private practice. For example, a private practice lawyer who was defending a client in a criminal case should not continue the representation after taking a position as an assistant prosecuting attorney in the county where the charges were pending.<a href="#9"><sup>9</sup></a></p><p>A more complicated scenario occurs when a lawyer leaves a position as a government employee and moves to another government job, specifically when a public defender moves to a prosecuting attorney&rsquo;s office. The Supreme Court of Missouri, in <em>State v. Lemasters,</em><a href="#10"><sup>10</sup></a> discussed Rule 4-1.11 in the context of a lawyer who left the public defender&rsquo;s office and went to work as an assistant prosecutor in the same county where she had been defending a client against criminal charges. The former client, Lemasters, moved to disqualify all of the lawyers in the prosecuting attorney&rsquo;s office on the grounds that his former lawyer&rsquo;s conflict disqualified all of the lawyers in the office.</p><p>The court found that Lemasters&rsquo; former lawyer, who was a former government lawyer due to her prior position in the Missouri State Public Defender system, was disqualified by Rule 4-1.11(a) from participating in any way in Lemasters&rsquo; prosecution. Rule 4-1.11(a)(1) also prohibited the lawyer from revealing any information relating to Lemasters to her new colleagues or using any information to Lemasters&rsquo; disadvantage. The evidence showed the new prosecutor had complied with these obligations.<a href="#11"><sup>11</sup></a></p><p>Lemasters nevertheless argued that his former lawyer&rsquo;s conflict should be imputed to all the lawyers in the prosecutor&rsquo;s office. In analyzing Lemasters&rsquo; claim, the court found Rule 4-1.11(b)&rsquo;s conflict imputation language did not apply to the &ldquo;public defender to prosecutor&rdquo; scenario because that subsection applies to a job move to a &ldquo;firm,&rdquo; a word that does not include lawyers working together as government employees, such as in a county prosecutor&rsquo;s office.<a href="#12"><sup>12</sup></a> Instead, the court found Rule 4-1.11(d), &ldquo;which deals with conflicts arising from prior representations by <em>current</em> public officers or employees,&rdquo; (emphasis in original) applied to the Lemasters scenario. The court noted there was no imputation language in Rule 4-1.11(d) and cited the language in Comment 2, which states the subsection does not impute the conflicts of a lawyer currently serving as a government employee to associated employees, while noting that screening would be prudent.<a href="#13"><sup>13</sup></a></p><p>Rule 4-1.11(d)(2)(ii) prohibits a lawyer currently working for the government from negotiating for a job with a party in a matter in which the lawyer is participating &ldquo;personally and substantially.&rdquo; An exception is made for judicial law clerks, so long as the clerk notifies the judge about the job negotiation.<a href="#14"><sup>14</sup></a></p><p>Subsection (e) addresses lawyers who &ldquo;also hold public office&rdquo; and prohibits engagement in activities in which the lawyer&rsquo;s personal or professional interests conflict with the lawyer&rsquo;s &ldquo;official duties or responsibilities.&rdquo;<a href="#15"><sup>15</sup></a> Comment 11 notes a public official&rsquo;s position on policy matters may conflict with a client&rsquo;s interests. Nor is the lawyer holding public office permitted to &ldquo;attempt to influence any agency of any political subdivision&rdquo; for which the lawyer serves as a public officer, except as part of the lawyer&rsquo;s official duties or as authorized by &sect;&sect; 105.450 RSMo to 105.496 RSMo.<a href="#16"><sup>16</sup></a> Other lawyers in a firm in which the lawyer holding public office is associated may continue or undertake a matter the public officer would be disqualified from pursuing so long as that lawyer is screened.<a href="#17"><sup>17</sup></a></p><p>Subsection (f) defines &ldquo;matter&rdquo; for the purposes of Rule 4-1.11. Notably, matter is defined to include decisions involving a specific party or parties, which may be a narrower definition than is found in Rule 4-1.9.<a href="#18"><sup>18</sup></a></p><p><strong>Conclusion</strong></p><p>Conflicts analysis can be complicated. Supreme Court Rule 4-1.11 specifically applies to a lawyer who leaves government service to work in the private sector, who leaves a private practice to join the government, or who moves between government positions. The rule should be read, and reread, by lawyers transitioning into and away from government service.</p><p><strong>Endnotes</strong></p><p><a id="1" name="1">1</a> Sharon K. Weedin is staff counsel for the Office of Chief Disciplinary Counsel in Jefferson City.</p><p><a id="2" name="2">2</a>&nbsp; Rule 4-1.0(l).</p><p><a id="3" name="3">3</a>&nbsp; Rule 4-1.0(e).&nbsp; <em>See also</em> Rule 4-1.11, Comment 1, where it is acknowledged that statutes or regulations may inhibit a government agency&rsquo;s authority to give consent.</p><p><a id="4" name="4">4</a>&nbsp; Rule 4-1.0(b).</p><p><a id="5" name="5">5</a>&nbsp; Rule 4-1.0(k), and Rule 4-1.11, Comments 9, 10, and 11.</p><p><a id="6" name="6">6</a>&nbsp; Rule 4-1.11, Comment 6 clarifies that the disqualified lawyer may receive any salary or partnership share established by independent agreement.</p><p><a id="7" name="7">7</a>&nbsp; Rule 4-1.10, the general rule concerning imputation of conflicts of interest. In most cases, the conflicts of an incoming lawyer are imputed to all members of the firm, without the possibility of screening. Rule 4-1.10(d) specifically carves out an exception to the strict imputation rule for former or current government lawyers and cites Rule 4-1.11.</p><p><a id="8" name="8">8</a>&nbsp; Confidential government information is defined in Rule 4-1.11(c) as &ldquo;information that has been obtained under governmental authority&rdquo; and which, at the time the rule is being applied, the government is prohibited from disclosing and is not otherwise available to the public.</p><p><a id="9" name="9">9</a>&nbsp;&nbsp; <em>In re Smith</em>, 29 So.3d 1232 (La. 2010).</p><p><a id="10" name="10">10</a> <em>State v. Lemasters, </em>456 S.W.3d 416 (Mo. banc 2015).</p><p><a id="11" name="11">11</a> <em>Id. </em>at *420.</p><p><a id="12" name="12">12</a> <em>Id. </em>at *421.</p><p><a id="13" name="13">13</a> The Court confirmed its Lemasters reasoning in <em>State ex rel. Peters-Baker v. Round</em>, 561S.W.3d 380 (Mo. banc 2018), in which a defendant unsuccessfully argued for the imputed disqualification of an entire prosecutor&rsquo;s office due to his former public defender&rsquo;s move to that office.</p><p><a id="14" name="14">14</a> Rule 4-1.11(d)(2)(ii); Rule 4-1.12(b).</p><p><a id="15" name="15">15</a> <em>See</em> Rule 4-1.7.&nbsp; Subsection (e) in Missouri&rsquo;s Rule 4-1.11 is not found in the Model Rules of Professional Conduct.&nbsp;</p><p><a id="16" name="16">16</a> Chapter 105, Public Officers and Employees, RSMo.</p><p><a id="17" name="17">17</a> Rule 4-1.11, Comment 10, provides context for the word &ldquo;matter&rdquo; as it is used in this subsection.</p><p><a id="18" name="18">18</a>&nbsp;<em>See</em> ABA Comm. On Ethics and Professional Responsibility Formal Op. 97-409 (1997).</p>]]></description><category><![CDATA[journal,LPMManagement,LPMMoney,LPMPracticeMgmt,LPMProtect,PracticeManagement]]></category>
            <pubDate>Tue, 06 Apr 2021 17:17:31 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_journal---ethics.jpg?10000" length="0" type="image/jpg" />
                <pp:image>https://content.presspage.com/uploads/2361/500_journal---ethics.jpg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/journal---ethics.jpg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Journal - Ethics]]></pp:imageTitle></item><item>
                        <title>Management Matters: Don&#039;t think disaster can&#039;t or won&#039;t happen to your firm</title>
                        <link>https://news.mobar.org/management-matters-dont-think-disaster-cant-or-wont-happen-to-your-firm/</link>
                        <guid>https://news.mobar.org/management-matters-dont-think-disaster-cant-or-wont-happen-to-your-firm/</guid><pp:caseid>446118</pp:caseid><pp:subtitle>Vol. 77, No. 2 / Mar. - Apr. 2021</pp:subtitle><pp:summary><![CDATA[<p><em>Mother Nature is an equal opportunity disruptor.</em></p>
]]></pp:summary><description><![CDATA[<p><span style="color:#000080"><strong><img alt="" src="https://content.presspage.com/uploads/2361/journaljenniferramovs.png?x=1617149530019" style="float:left; height:187px; margin:5px 10px; width:150px" />Jennifer M. Ramovs</strong><br />Jennifer M. Ramovs is the director of practice management at Affinity Consulting. At no cost, Missouri lawyers can email their practice management questions to an expert or schedule a one-on-one, remote consultation. Ramovs is available at </span><a href="mailto:jramovs@affinityconsulting.com"><span style="color:#000080">jramovs@affinityconsulting.com</span></a><span style="color:#000080">.</span></p><p>Whether a firm is the new kid on the block or a venerable institution, it is undeniably susceptible to a catastrophe that can appear with little notice while wielding devastating results. However, that is not to say firms are helpless to the powerful hands of the fates. With a handful of best practices, Missouri lawyers can protect their firms, teams, and clients from a disaster that might knock the proverbial wind out of a business, but most importantly, never render it irreparably harmed. If lawyers are diligent with their preparation and willing to embrace beneficial technologies and procedures, these simple tips can insulate them from the constant threat of disaster.</p><p><strong>Get Organized</strong></p><p>The first step in preparing for the unforeseen is to organize all files, including client files and employee documentation. This critical, initial step should encompass paper files as well as electronic data, making sure everything is concise and put into its proper place. Lawyers should use offsite, deep storage facilities whenever appropriate, as long as the facility has its own adopted procedures and mechanisms to mitigate the impact of a disaster.</p><p><strong>Leverage Technology</strong></p><p>Obviously, in this digitized world, data plays a critical role in nearly every aspect of a firm&rsquo;s operations. As such, preserving the integrity of that data in the face of a natural disaster should be an ongoing priority for every firm. Continuing the previous step of getting organized, proper offsite storage of vital digital information must be adequately secured from both the forces of nature as well as human-based threat.</p><p>Any cloud-based data storage must be properly encrypted and secured to prevent highly sensitive information from slipping into the hands of the black hats of the world. Finding and maintaining such protocols should be mandatory for a firm&rsquo;s IT department as a constant influx of case files, documentation, and client communication requires a continually fluid yet perpetually secure storage solution.</p><p>Neither courts nor clients will pause if a disaster strikes a firm, so it&rsquo;s important to be prepared to seamlessly hit the ground running, no matter what catastrophes might come. Remember, locally based servers providing data backup can still make a firm susceptible to disaster if a regional calamity strikes a business, the storage provider, or the surrounding area.</p><p><strong>Have a Preparedness Plan</strong></p><p>Of course, in the event of a disaster, the immediate priority must be to protect staff from harm. Routinely practicing evacuation procedures makes certain all team members know precisely what to do in the event of an emergency. Regarding the office itself, lawyers should formalize a disaster plan with the office manager or equivalent, creating a list of all parties a firm might need to contact.</p><p>A preparedness plan should include insurance companies, vendors, property management, financial institutions, local first responders, and any contracted security providers or alarm systems. Firm leaders should also keep ongoing, detailed files of belongings &ndash; including office equipment, furniture, and anything else that would need to be replaced by an insurance carrier.</p><p>While it is impossible to completely shield a firm from the significant impact of disaster, even unforeseen and devastating events are not insurmountable with a bit of time, effort, and diligence. Most importantly, lawyers shouldn&rsquo;t think disasters can&rsquo;t or won&rsquo;t strike their firms; staff, clients, and efforts are too important to underestimate nature&rsquo;s indifference. Lawyers can check out The Missouri Bar&rsquo;s Law Practice Management site at <a href="https://mobar.org/LPM" target="_blank">mobar.org/LPM</a> for more resources to be prepared.</p><p><br /><strong>Endnote</strong></p><p><a id="1" name="1">1</a> Jennifer M. Ramovs is the director of practice management at Affinity Consulting. At no cost, Missouri lawyers can email their practice management questions to an expert or schedule a one-on-one, remote consultation. Ramovs is available at <a href="mailto:jramovs@affinityconsulting.com">jramovs@affinityconsulting.com</a>.</p>]]></description><category><![CDATA[journal,PracticeManagement,LPMProtect,LPMTech,LPMCyber]]></category>
            <pubDate>Tue, 06 Apr 2021 17:16:58 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_untitleddesign67.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_untitleddesign67.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/untitleddesign67.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Untitled design(67)]]></pp:imageTitle></item><item>
                        <title>How to use the Law Practice Management comparison charts</title>
                        <link>https://news.mobar.org/how-to-use-the-law-practice-management-comparison-charts/</link>
                        <guid>https://news.mobar.org/how-to-use-the-law-practice-management-comparison-charts/</guid><pp:caseid>435953</pp:caseid><description><![CDATA[<p><strong>By Jeffrey Schoenberger, Affinity Consulting&nbsp;</strong></p><p>Have you tried to compare products or services slightly off the beaten consumer path? Or well-known products for a non-marquee feature? Despite&nbsp;that product&rsquo;s market&nbsp;being worth tens to hundreds of millions of dollars, the information is difficult to come by.&nbsp;</p><p>If you&rsquo;re in the market for a pillow or bedsheets, there are obvious sources of information such as&nbsp;the website&nbsp;Consumer Reports&nbsp;that rate pillows and bedsheets on relevant categories like softness, durability, and ease of cleaning, for example. Easy enough. But suppose you want to buy a pillow made in America or in a union shop? It&rsquo;s harder to come by that information in part because most buyers are not including those features in their buying decisions. In that case, your best recourse is to look for manufacturers who brag about location or employees. You could also look to sites that promote &ldquo;Made in America&rdquo; products.&nbsp;</p><p>The same information gap occurs with tech products too. To begin with, honest feature comparison sites that aren&rsquo;t littered with ads are hard to come by for the general consumer. And once found, those sites target the broadly relevant features.&nbsp;Websites like&nbsp;PC Magazine&nbsp;or&nbsp;CNET&nbsp;will compare Dropbox, OneDrive, and G Drive, but they&rsquo;re unlikely to do so with a legal professional in mind. General audience news sources will talk price, speed, and ease of use, all relevant to legal professionals as well as the general public, but they won&rsquo;t address more esoteric things important to&nbsp;lawyers. A&nbsp;PC Magazine&nbsp;comparison won&rsquo;t address data center locations, what the service does when served with a subpoena or warrant, or how you could use a &ldquo;roll your own&rdquo; encryption on top of the service.&nbsp;</p><p>For legal-specific products, the problem is worse. While potential buyers can compare Dropbox, OneDrive, and G Drive, software and services targeted at legal professionals have websites and marketing materials that often offer vague descriptions of capabilities, lacking important caveats, and many times hide pricing behind a &ldquo;Request a Consultation&rdquo; form that results in a sales call.&nbsp;</p><p>These problems are exacerbated because&nbsp;lawyers, particularly those new to the profession or unaccustomed to comparing and choosing software, may lack a good idea of what features they want in a practice management solution, for example.&nbsp;</p><p><strong>Using&nbsp;Your&nbsp;Resources to Make Good Legal Tech Decisions&nbsp;</strong></p><p>That&rsquo;s&nbsp;where&nbsp;the&nbsp;<a href="https://mobar.org/site/Lawyer_Resources/Practice-Management/site/content/Lawyer-Resources/Law_Practice_Management/Practice_Management.aspx" rel="noreferrer noopener">Law Practice Management Resource Center</a>&nbsp;come into play.&nbsp;We&rsquo;ve&nbsp;collected and analyzed information&nbsp;in key law&nbsp;practice&nbsp;tech&nbsp;areas&nbsp;so&nbsp;you don&rsquo;t have to. Let&rsquo;s walk through an example:&nbsp;</p><p>Suppose you find your case and matter organization lacking. You can&rsquo;t access documents unless you&rsquo;re in the office. You rely on one or more people to figure out what, if anything, a client owes you and how much, if anything, the client has in&nbsp;their&nbsp;trust account. A client calls,&nbsp;texts, or emails you inquiring about case statuses, and you spend time rifling through emails, handwritten notes, and your memory to give&nbsp;updates. You talked with clients all day but, at the end of the day, are hard-pressed to remember who you talked to for how long and what was discussed. The clients are happy, but poor recollection has cost you billable time. Not good!&nbsp;</p><p>If we treat this like a law school exam, we can unpack it and get an idea of issues this law office should address when evaluating a new practice management system.&nbsp;</p><ul><li><p>Document access: You want to be able to access documents from outside the office. Is it just&nbsp;documents&nbsp;or do you also want access to case information? How important is it that access works well on tablets or iPhones, or is good laptop access enough?&nbsp;</p></li><li><p>Accounting: You want to know what the client owes and what&rsquo;s in his trust account irrespective of whether the bookkeeper or support staffer, if any, is reachable. Do you want to know other financial information as well, like upcoming rent or office supply bills in the same program? If not, what accounting program do you use now, and will it share data with your prospective practice management program? Should clients be able to see and pay bills over the internet?&nbsp;</p></li></ul><ul><li><p>Case status: Most practice management programs hold general case information, party contact information, calendar dates, and tasks. Most also have some form of document storage. All would be an improvement over the &ldquo;rifling&nbsp;lawyer&rdquo; in our hypothetical&nbsp;scenario, but&nbsp;there are wrinkles in the options. How important is mobile access and&nbsp;from what device? Many programs can capture email and sync calendars and contacts but are you a Microsoft 365 or Google Workspace firm? Many products, particularly the web-based ones, offer client portals where the client can see upcoming appointments, share documents, exchange secure messages with the&nbsp;lawyer, and see bills. Is this case status &ldquo;self-help&rdquo; a feature you want? Some programs integrate with voice over internet phone (VOIP)&nbsp;systems&nbsp;so phone call numbers and length become proposed time entries, so you don&rsquo;t lose billable time as in our hypothetical&nbsp;situation. How valuable is that?&nbsp;</p></li></ul><p>As with a law school exam, our one paragraph hypothetical became three paragraphs of additional questions and considerations.&nbsp;You&nbsp;don&rsquo;t&nbsp;want to do all the leg work yourself!&nbsp;</p><p>Our&nbsp;Law Practice Management Resource Center&nbsp;offers checklists and whitepapers to spur these types of questions. Find the checklists (<a href="https://connect.mobar.org/viewdocument/moving-to-a-new-pm-system?LibraryFolderKey=13055251-fe4c-41fa-939a-952c1935d023&DefaultView=folder" rel="noreferrer noopener">here</a>&nbsp;and&nbsp;<a href="https://connect.mobar.org/viewdocument/practice-management-feature-conside?LibraryFolderKey=13055251-fe4c-41fa-939a-952c1935d023&DefaultView=folder" rel="noreferrer noopener">here</a>) and&nbsp;<a href="https://connect.mobar.org/viewdocument/practice-management-software-implem?LibraryFolderKey=a138ac72-1753-437f-9b70-99cd9abe1988&DefaultView=folder" rel="noreferrer noopener">whitepaper</a>&nbsp;relevant to practice management software on&nbsp;our&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Practice_Management.aspx" rel="noreferrer noopener">Law Practice Management</a>&nbsp;website.&nbsp;Once&nbsp;you&rsquo;ve&nbsp;picked your&nbsp;&ldquo;must have&rdquo; features and prioritized their importance, then head over to the&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Checklists___Charts.aspx" rel="noreferrer noopener">Checklists and Charts</a>&nbsp;resource,&nbsp;scroll down to the&nbsp;&ldquo;Manage a Practice&rdquo;&nbsp;heading,&nbsp;and&nbsp;you&rsquo;ll&nbsp;find two relevant comparison charts. The&nbsp;<a href="https://www.affinityconsulting.com/compare-traditional-practice-management/" rel="noreferrer noopener">&ldquo;Practice Management Server-based&rdquo;</a>&nbsp;comparison chart compares vendors offering software that would install on a desktop or server that you&nbsp;maintain. This route is popular with&nbsp;lawyers&nbsp;who have more complex needs, want to integrate with other desktop software such as&nbsp;PCLaw&nbsp;or Microsoft Word, and those who&nbsp;don&rsquo;t&nbsp;want client data stored with a cloud-based provider. The&nbsp;<a href="https://www.affinityconsulting.com/compare-cloud-practice-management/" rel="noreferrer noopener">&ldquo;Practice Management Cloud-based&rdquo;</a>&nbsp;comparison chart compares vendors whose offerings run in a web browser, requiring little to no software maintenance on the user&rsquo;s side. This route is better for&nbsp;lawyers&nbsp;newer to practice, those who are more mobile,&nbsp;those&nbsp;who&nbsp;desire&nbsp;tablet or smartphone apps, and those who&nbsp;don&rsquo;t&nbsp;want to make an upfront investment in software and hardware to run traditional software.&nbsp;</p><p>The comparison chart organization makes feature analysis easy. For example, if you are committed to desktop/server software over a web-based&nbsp;solution&nbsp;but&nbsp;want the ability to email or text appointment reminders to clients, then&nbsp;<a href="https://coyoteanalytics.com/">Coyote Analytics</a>&nbsp;is your answer. Or if you&rsquo;re committed to a web-based&nbsp;offering&nbsp;but&nbsp;want offline access to case information because you have spotty internet, then&nbsp;<a href="https://www.smokeball.com/">Smokeball</a>&nbsp;is your answer.&nbsp;Missouri Bar members receive&nbsp;discounts on many top practice management programs,&nbsp;including <a href="https://demo.smokeball.com/missouri-bar/">Smokeball</a>,&nbsp;at the&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Member_Benefits/Build-Manage.aspx">Member Benefits</a>&nbsp;section of the bar&rsquo;s website.&nbsp;</p><p>Finally, once you&rsquo;ve selected a practice management solution, be sure to&nbsp;<a href="https://connect.mobar.org/viewdocument/pre-conversion-data-cleanup?LibraryFolderKey=13055251-fe4c-41fa-939a-952c1935d023&DefaultView=folder" rel="noreferrer noopener">clean up your data</a>&nbsp;before moving case and billing information to the new system.&nbsp;</p><p><strong>Much More to Discover&nbsp;</strong></p><p>Practice management software is just one example of high-value, legal tech decisions that&nbsp;the&nbsp;comparison charts can help you make. Comparisons exist for everything from document management solutions (that can talk to your practice management solution) to document assembly tools (that can pull information from practice management software into documents) to voice over internet phone (VOIP) that can automatically create times from phone calls. Visit all the&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Checklists___Charts.aspx" rel="noreferrer noopener">checklists and comparison&nbsp;charts</a>&nbsp;available for bar members.&nbsp;</p><p>If you have any questions or want information from experts who&rsquo;ve implemented these solutions for law&nbsp;practices&nbsp;and legal organizations, visit LPM&rsquo;s&nbsp;<a href="https://mobar.org/site/content/Lawyer-Resources/Law_Practice_Management/Ask_an_Expert.aspx" rel="noreferrer noopener">Ask an Expert</a>&nbsp;to email questions or schedule a phone or video call.&nbsp;</p>]]></description><category><![CDATA[PracticeManagement,molawyers,MOLawyersBenefit,LPMOpen,LPMProtect,LPMDocs,LPMPracticeMgmt,LPMMoney,LPMTech]]></category>
            <pubDate>Tue, 09 Feb 2021 13:28:15 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_tw-lawpracticemanagementcenter2-9-21.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_tw-lawpracticemanagementcenter2-9-21.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/tw-lawpracticemanagementcenter2-9-21.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[TW_Law Practice Management Center 2-9-21]]></pp:imageTitle></item><item>
                        <title>Ethics: Ethical considerations amid a pandemic</title>
                        <link>https://news.mobar.org/ethical-considerations-amid-pandemic/</link>
                        <guid>https://news.mobar.org/ethical-considerations-amid-pandemic/</guid><pp:caseid>434455</pp:caseid><pp:subtitle>Vol. 77, No. 1 / Jan. - Feb. 2021</pp:subtitle><pp:summary><![CDATA[<p><em>The COVID-19 pandemic altered not only the world&rsquo;s workforce, but also the particulars of the practice of law. Whether a lawyer is asked to self-quarantine to prevent further spread or if that same lawyer is adapting to working remotely, there are ethical considerations when adapting to an ever-increasing remote work life.</em></p>
]]></pp:summary><description><![CDATA[<p><span style="color:#000080"><strong><img alt="" src="https://content.presspage.com/uploads/2361/500_journal-kaylakemp.jpg?x=1612280865184" style="border-style:solid; border-width:1px; float:left; height:99px; margin-left:5px; margin-right:5px; width:90px" />Kayla Kemp</strong></span></p><p><span style="color:#000080">Kayla Kemp is staff counsel at the Office of Chief Disciplinary Counsel.<a href="https://news.mobar.org/ethical-considerations-amid-pandemic/#1" target="_blank"><sup>1</sup></a></span></p><p>Thankfully, there are an abundance of resources and technological solutions which can be utilized to facilitate practicing during a pandemic. As lawyers, we must be mindful to ensure that as we adapt, we must continue to meet our ethical duties under the Missouri Rules of Professional Conduct (&ldquo;Rules&rdquo;).&nbsp;</p><p><strong>Planning for Incapacitation During a Pandemic</strong></p><p>Lawyers should be prepared to adapt to a rapidly changing environment, whether that be a natural disaster, pandemic, or some other act of God. Not only do we need to be prepared for abrupt changes to the ways in which we meet with clients or appear before courts, but we also need to be prepared for incapacity, more so now than ever before. Like the general population, our profession&rsquo;s population is increasingly aging. According to the 2020 American Bar Association Profile of the Legal Profession, the median age of lawyers as of 2019 was 47.5 years old.<a href="#2"><sup>2</sup></a> Nearly one in six lawyers are 65 or older.<a href="#3"><sup>3</sup></a> This is notable because the Center for Disease Control (CDC) warns the risk for severe illness with COVID-19 increases with age. Those who are 50-64 years of age are four times more likely to be hospitalized than the comparison group, which consisted of those 18-29 years old. The risk of death was 30 times higher for those 50-64 years old compared to the comparison group.<a href="#4"><sup>4</sup></a> Those figures increase with each following age group. Nonetheless, every lawyer must consider the possibility of becoming incapacitated with little to no notice.</p><p>Lawyers should ensure that, in the event of incapacity, they are comporting with ethical obligations. One way to ensure compliance is to have a succession plan in place. Rule 5.26 allows lawyers to take an important step in ensuring that representation is not disrupted by sudden incapacity. Now is a good time to consider designating a trustee pursuant to Rule 5.26, which allows a lawyer to choose someone who can take over the lawyer&rsquo;s legal practice upon an unexpected absence. By selecting a trustee, you can involve that same trustee in your succession plan. By actively preparing for the possibility of incapacity, a lawyer can better facilitate a smooth transition in the event the unexpected occurred. Aside from designating a trustee, a plan should be developed for any event which may keep you out of your physical office. This plan should encompass how your usual means of communication will continue to be monitored. Someone will need to go to your physical office to check mail, voicemails, or faxes. Also, be sure to include clear instructions regarding receiving and retaining client records and property. For additional resources in succession planning, visit The Missouri Bar&rsquo;s website, <a href="https://mobar.org" target="_blank">MoBar.org</a>.<a href="#5"><sup>5</sup></a></p><p><strong>Mental Health Concerns </strong></p><p>The physical threat COVID-19 presents is not the only health risk. On Feb. 19, 2020, the American Lawyer released the results of its year-long &ldquo;Mental Health and Substance Abuse Survey,&rdquo; which found that 31.2% of the more than 3,800 respondents surveyed reported they were depressed. Additionally, 64% reported anxiety, 10.1% reported an alcohol problem, and 2.8% reported a drug problem.<a href="#6"><sup>6</sup></a> These findings predate the onset of the pandemic in the United States.</p><p>The CDC released findings noting that in June of 2020 the rates of depression and anxiety amongst adults in the United States were three to four times higher than the corresponding point in 2019.<a href="#7"><sup>7</sup></a> Approximately 40% of those surveyed reported struggling with mental health or substance abuse. According to the same study, rates of suicidal ideation, substance abuse, and alcohol consumption are steadily rising. Lawyers should familiarize themselves with the mental health and substance use resources available through The Missouri Bar.<a href="#8"><sup>8</sup></a> Depression and anxiety can result in lawyers neglecting their responsibilities and, therefore, harming their clients. Just as lawyers ought to be proactive in planning for physical incapacitation, lawyers should also be proactive in caring for their mental well-being. A lawyer who is grappling with these serious health issues needs to make every effort to seek help, such as through the Missouri Lawyers&rsquo; Assistance Program (MOLAP).<a href="#9"><sup>9</sup></a> Through MOLAP, all Missouri Bar members can speak with a licensed clinical social worker by calling 800-688-7859. The program is free and confidential.</p><p><strong>Competence Amidst Chaos</strong></p><p>The first obligation set forth in the Rules is that of competence. Rule 4-1.1 &ndash; Competence &ndash; Comment [6] dictates&nbsp;&ldquo;[t]o maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology ... .&rdquo;</p><p>Keeping abreast of changes to the practice of law necessities brings an awareness of the risks associated with working remotely. Despite the challenges presented during the current pandemic, lawyers have the duty to remain competent.&nbsp;Comment [3] to Rule 4-1.1 provides guidance on a lawyer&rsquo;s ethical obligation during such a situation as a global pandemic:</p><blockquote>In an emergency a lawyer may give advice or assistance in a matter in which the lawyer does not have the skill ordinarily required where referral to or consultation or association with another lawyer would be impractical. Even in an emergency, however, assistance should be limited to that reasonably necessary in the circumstances, for ill-considered action under emergency conditions can jeopardize the client&rsquo;s interest.</blockquote><p>In the event of an emergency, a lawyer may give advice in a matter the lawyer does not possess the skill ordinarily needed to provide such advice. Of course, advising without the necessary skill is only acceptable where referral or consultation with another lawyer is impractical.</p><p>Lawyers must continue to educate themselves on technological innovations which can be utilized to virtually serve their clients. Also, lawyers need to stay current on any legal changes that allow them to continue to meet clients&rsquo; needs to enter into contracts, update wills, or create personal health care directives.</p><p><strong>Remote Notarization</strong></p><p>On April 6, 2020, Gov. Mike Parson issued Executive Order 20-08 suspending a statutory requirement that a notary public must conduct such notarization of official documents while the signer personally appears. Executive Order 20-08 was set to expire June 15, 2020; then, Executive Order 20-12 extended remote notarization to Aug. 28, 2020. Subsequently, Executive Order 20-14 and Executive Order 20-19 extended remote notarizations until March 31, 2021.</p><p>The practice of remote notarization provides a secure and safe method to execute legal documents. Notarization can occur while utilizing audio-video technology, provided certain conditions are met:&nbsp;</p><p>(1) If the signatory is not personally or otherwise known to the notary, the signatory must display a valid photo ID to the notary during the video conference;</p><p>(2) The signatory must affirmatively represent that they are physically situated in the State of Missouri, and the notary must be physically located in the State of Missouri and say in which county they are physically located for the jurisdiction on the notarial certificate;</p><p>(3) The video conference must be a live and interactive audio-visual communication between the signatory, notary, and any other necessary persons to allow for direct interaction at the time of signing;</p><p>(4) The notary must record in their journal the exact time and software used to perform the notarial act, along with all other required information; and</p><p>(5) The document must contain a notarial certificate, a jurat, or acknowledgement, which states that the signatory appeared remotely pursuant to Executive Order 20-14.</p><p><strong>Electronic Notarization</strong></p><p>While Missouri already permits electronic notarization, which is the use of electronic signatures and seals, Executive Order 20-14 allows for remote and electronic notarization to occur together when:</p><p>(1) The notary public is registered as an electronic notary public with the Missouri Secretary of State;</p><p>(2) The document must be electronically signed with a software approved by the Missouri Secretary of State; and</p><p>(3) The notary must affix the electronic notary seal to the electronic document.</p><p>Lawyers should do their due diligence and check with the Missouri Secretary of State to confirm they are using a registered remote notary<a href="#10"><sup>10</sup></a> and the software used to electronically sign the document<a href="#11"><sup>11</sup></a> is approved.</p><p><strong>Cyber Security </strong></p><p>While there are many benefits to utilizing technology to facilitate legal services, there are also risks. For example, Zoom &ndash; a platform used to facilitate virtual audio and visual meetings &ndash; has had security breaches. In July 2019, a vulnerability in Zoom&rsquo;s Macintosh desktop client was found which let malicious websites turn on a Macintosh user&rsquo;s webcam without that user&rsquo;s knowledge.<a href="#12"><sup>12</sup></a> Then, in January 2020, another vulnerability was discovered. Unauthorized users could enter Zoom meetings that were not password protected and did not have Zoom&rsquo;s Waiting Room feature &ndash; which allows for manual admission into Zoom meetings &ndash; enabled. Security flaws such as these are not unique to Zoom. Consequently, when utilizing third-party platforms, lawyers ought to take precautions such as using updated software and taking reasonable security measures.</p><p>Rule 4-1.6(c) specifies &ldquo;[a] lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information of the client.&rdquo; Comment [15] details the factors to be considered in determining whether a lawyer acted completely by undertaking reasonable efforts to prevent inadvertent or unauthorized disclosure of information related to client representation. The ABA&rsquo;s Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 477R, &ldquo;Securing Communication of Protected Client Information,&rdquo; which provides guidance as to security measures that should be employed given the ever-increasing cybersecurity threats that exist when transmitting information over the internet:<a href="#13"><sup>13</sup></a></p><blockquote>However, cyber-threats and the proliferation of electronic communications devices have changed the landscape and it is not always reasonable to rely on the use of unencrypted email. For example, electronic communication through certain mobile applications or on message boards or via unsecured networks may lack the basic expectation of privacy afforded to email communications.<a href="#14"><sup>14</sup></a></blockquote><p>While cyber security was a matter of grave concern in 2017, the threat of harm has only increased.<a href="#15"><sup>15</sup></a> In 2019, there were more than 5,000 data breaches reported.<a href="#16"><sup>16</sup></a> These breaches amounted to approximately 8 billion exposed records. Educating yourself on the various types of cyberattacks which can leave your client-confidential information vulnerable is the first step.<a href="#17"><sup>17</sup></a></p><p><strong>Third-party Service Providers </strong></p><p>For those lawyers whose devices are managed by a third party, include explicit terms in your contracts detailing which security practices are to be followed. These security features can include audits that report security status and the health of your devices. The National Institute for Standards and Technology and the Institute for Standards Organization provide best practices for guidance on how to strengthen your network&rsquo;s defenses. Lawyers should consider including clauses in their contracts which detail how third parties will secure remote access. Methods to help secure remote access to your network include VPNs, multi-factor authentication, and rotating strong passwords. After all, Comment [1] to Rule 4-5.3 &ndash; Responsibilities Regarding Nonlawyer Assistants requires lawyers with managerial authority make reasonable assurances that the nonlawyers in the firm and those who work outside the firm act in a way compatible with the ethical obligations of the lawyer.</p><p>As technology evolves, so does our obligation to act reasonably under the Rules of Professional Conduct. And as we adapt, we must consider what further efforts we can take to meet our ethical duties. The current global pandemic has shifted our way of life, both at work and at home. It is important for every lawyer to understand the resources available to help alleviate the burden they may feel.</p><p><strong>Endnotes</strong></p><p><a id="1" name="1">1</a> Kayla Kemp is staff counsel at the Office of Chief Disciplinary Counsel. Special thanks to Melinda J. Bentley, legal ethics counsel, whose presentation, &ldquo;Ethical Considerations for Missouri Lawyers Practicing During the COVID-19 Pandemic: A Conversation with the Chief Disciplinary Counsel & Ethics Counsel,&rdquo; was invaluable.</p><p><a id="2" name="2">2</a> Am. Bar Ass&rsquo;n, 2020 American Bar Association Profile of the Legal Profession (2020), <a href="https://www.americanbar.org/news/reporter_resources/profile-of-profession/" target="_blank">https://www.americanbar.org/news/reporter_resources/profile-of-profession/</a>.</p><p><a id="3" name="3">3</a> Am. Bar Ass&rsquo;n, 2020 American Bar Association Profile of the Legal Profession (2020), <a href="https://www.americanbar.org/news/reporter_resources/profile-of-profession/" target="_blank">https://www.americanbar.org/news/reporter_resources/profile-of-profession/</a>.</p><p><a id="4" name="4">4</a> Centers for Disease Control and Prevention, COVID-19: Older Adults (2020), <a href="https://www.cdc.gov/coronavirus/2019-ncov/need-extra-precautions/older-adults.html" target="_blank">https://www.cdc.gov/coronavirus/2019-ncov/need-extra-precautions/older-adults.html</a>.</p><p><a id="5" name="5">5</a> The Missouri Bar, Planning Ahead: A Guide to Protect Your Clients&rsquo; and You Survivors&rsquo; Interests in the Event of Your Disability of Death (2005).</p><p><a id="6" name="6">6</a> Lizzy McLellan, <em>Lawyers Reveal True Depth of Mental Health Struggles, </em>Law.com (Feb. 19, 2020, 11:00 AM), <a href="https://www.law.com/2020/02/19/lawyers-reveal-true-depth-of-the-mental-health-struggles/" target="_blank">https://www.law.com/2020/02/19/lawyers-reveal-true-depth-of-the-mental-health-struggles/</a>.</p><p><a id="7" name="7">7</a> Czeisler M&Eacute; et al., <em>Mental Health, Substance Use, and Suicidal Ideation During the COVID-19 Pandemic &ndash; United States, June 24&ndash;30, 2020,</em> MMWR Morb. Mortal Wkly. Rep. 2020;69:1049-1057 (2020).&nbsp;</p><p><a id="8" name="8">8</a> Coronavirus Resource Center for Lawyers, <a href="https://mobar.org/site/content/Lawyer-Resources/Coronavirus_Resource_Center_for_Lawyers.aspx?WebsiteKey=dd54fe1d-87c8-4d7e-9547-e59fcd729541" target="_blank">https://mobar.org/site/content/Lawyer-Resources/Coronavirus_Resource_Center_for_Lawyers.aspx?WebsiteKey=dd54fe1d-87c8-4d7e-9547-e59fcd729541</a> (last visited Jan. 11, 2021).</p><p><a id="9" name="9">9</a> Missouri Lawyers&rsquo; Assistance Program, <a href="https://mobar.org/molap/" target="_blank">https://mobar.org/molap/</a> (last visited Jan. 11, 2021).</p><p><a id="10" name="10">10</a> Registered Electronic Notaries, <a href="https://www.sos.mo.gov/RegisteredElectronicNotary" target="_blank">https://www.sos.mo.gov/RegisteredElectronicNotary</a> (last visited Jan. 11, 2021).</p><p><a id="11" name="11">11</a> Approved Notary Software Vendors, <a href="https://s1.sos.mo.gov/Business/Notary/softwarevendors" target="_blank">https://s1.sos.mo.gov/Business/Notary/softwarevendors</a> (last visited Jan. 11, 2021).</p><p><a id="12" name="12">12</a> Jonathan Leitschuh, <em>Zoom Zero Day: 4+ Million Webcams & Maybe an RCE? Just Get Them to Your Website!,</em> Medium.com (July 8, 2019), <a href="https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5" target="_blank">https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5</a>.</p><p><a id="13" name="13">13</a> ABA Committee on Ethics & Pro. Resp., Formal Op. 477R (2017).</p><p><a id="14" name="14">14</a> <em>Id. </em>at pg. 5.</p><p><a id="15" name="15">15</a> Microsoft Digital Defense Report, September 2020, <a href="https://www.microsoft.com/en-us/security/business/security-intelligence-report" target="_blank">https://www.microsoft.com/en-us/security/business/security-intelligence-report</a> (last visited Jan. 11, 2021).</p><p><a id="16" name="16">16</a> Rae Hodge, <em>2019 Data Breach Hall of Shame,</em> cnet.com (Dec. 27, 2019, 4:00 AM), <a href="https://www.cnet.com/news/2019-data-breach-hall-of-shame-these-were-the-biggest-data-breaches-of-the-year/" target="_blank">https://www.cnet.com/news/2019-data-breach-hall-of-shame-these-were-the-biggest-data-breaches-of-the-year/</a>.</p><p><a id="17" name="17">17</a> <em>See</em> Melinda J. Bentley, <em>Ethics: The Ethical Implications of Technology in Your Law Practice: Understanding the Rules of Professional Conduct Can Prevent Potential Problems, </em>76 J.MoBar (2020).</p>]]></description><category><![CDATA[journal,LPMManagement,LPMMoney,LPMPracticeMgmt,LPMProtect,PracticeManagement,LPMCyber]]></category>
            <pubDate>Wed, 03 Feb 2021 14:14:15 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_journal---ethics.jpg?10000" length="0" type="image/jpg" />
                <pp:image>https://content.presspage.com/uploads/2361/500_journal---ethics.jpg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/journal---ethics.jpg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Journal - Ethics]]></pp:imageTitle></item><item>
                        <title>Management Matters: Here to help</title>
                        <link>https://news.mobar.org/management-matters-here-to-help/</link>
                        <guid>https://news.mobar.org/management-matters-here-to-help/</guid><pp:caseid>434505</pp:caseid><pp:subtitle>Vol. 77, No. 1 / Jan. - Feb. 2021</pp:subtitle><pp:summary><![CDATA[<p><em>In early 2020, The Missouri Bar launched a new Law Practice Management Center at <a href="https://mobar.org/LPM" target="_blank">mobar.org/LPM</a> to help lawyers even better serve their clients. The Law Practice Management Center is organized to follow the life cycle of a law practice, helping lawyers open, build, manage, protect, and wind down. Here, we&rsquo;ll talk about what you will find in each of those areas of the website &ndash; and what to do if you need additional resources.</em></p>
]]></pp:summary><description><![CDATA[<p><strong>Affinity Consulting Representatives<a href="http://news.mobar.org/management-matters-here-to-help/#1"><sup>1</sup></a></strong></p><p><strong>Open</strong><br />In this section of the website, members will find technology checklists, purchasing guides, tips for finding the best deals on legal technology, and links to Missouri Bar member benefits, including discounts on services and products. Members will also find a guide for starting a law practice and a new lawyer&rsquo;s guide to the bar.</p><p><strong>Build</strong><br />Tools for marketing, advertising, navigating social media, earning referrals, and, of course, links to articles and relevant ethics opinions on these topics are located under this section. We worked to think of everything bar members may need in one spot, so it&rsquo;s easy to find, and easy to use.</p><p><strong>Manage</strong><br />This is the most densely populated area of the site, with helpful checklists and whitepapers on practice management; time billing and accounting; documents; e&ndash;filing; technology; time management; hiring and firing; working with clients; and limited scope representation. There are also comparison charts to help lawyers navigate software and technology options.</p><p><strong>Protect</strong><br />Lawyers have an ethical obligation to protect client data, and with so many devices being used to access and consume client and matter information, protecting it can be overwhelming. Lawyers owe it to their clients, employees, and law licenses to check out this section. Here, members will also find information for disaster preparedness, cybersecurity planning, and more.</p><p><strong>Wind Down</strong><br />Whether members are closing their practices and planning for retirement or merging law offices for a new venture, in this section of the website they will find helpful checklists to makes sure they have left no stone unturned. Succession planning checklists and guidelines live here, too &ndash; and it is never too early to start planning.</p><p><strong>Ask an Expert</strong><br />The resources don&rsquo;t stop there. If bar members don&rsquo;t find what they are looking for, they can email Affinity Consulting any question about the management and technology at their firms. While Affinity Consulting can&rsquo;t provide legal advice, their experts can connect lawyers with the tools and re-sources to help open, operate, and wind down their practices.</p><p>Members can also schedule a short consultation with one of Affinity Consulting&rsquo;s consultants. Best of all? These services are included in your Missouri Bar membership. No extra fees, and no separate login; just the resources Missouri Bar members need to make good decisions and run a successful law practice.</p><p>The Law Practice Management Center can be Missouri Bar members&rsquo; go-to resource for all their law office management and technology needs. Get started at <a href="https://MoBar.org/LPM" target="_blank">MoBar.org/LPM</a>.</p><p><br /><strong>Endnotes</strong></p><p><a id="1" name="1">1</a> As a Missouri Bar member benefit, lawyers can speak with Affinity Consulting experts regarding legal technology and law practice management questions. At no cost, Missouri lawyers can email their question to an expert or schedule a one-on-one, remote consultation. Learn more at <a href="https://MoBar.org/LPM" target="_blank">MoBar.org/LPM</a>.</p><p>&nbsp;</p>]]></description><category><![CDATA[journal,PracticeManagement,LPMProtect,LPMManagement,LPMBuild,LPMWindDown,LPMOpen]]></category>
            <pubDate>Wed, 03 Feb 2021 14:13:01 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_untitleddesign67.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_untitleddesign67.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/untitleddesign67.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Untitled design(67)]]></pp:imageTitle></item><item>
                        <title>Ethics: The ethical implications of technology in your law practice: Understanding the Rules of Professional Conduct can prevent potential problems</title>
                        <link>https://news.mobar.org/ethics-the-ethical-implications-of-technology-in-your-law-practice-understanding-the-rules-of-professional-conduct-can-prevent-potential-problems/</link>
                        <guid>https://news.mobar.org/ethics-the-ethical-implications-of-technology-in-your-law-practice-understanding-the-rules-of-professional-conduct-can-prevent-potential-problems/</guid><pp:caseid>377525</pp:caseid><pp:subtitle>Vol. 76, No. 1 / January - February 2020</pp:subtitle><pp:summary><![CDATA[<p><em>Implementing and using technology devices and systems in your law practice can be both exciting and daunting. How do you select a device such as a phone, laptop, computer, or other hardware? How do you select a piece of software, case management system, document management system, backup system, or accounting system?</em></p>
]]></pp:summary><description><![CDATA[<p><span style="color:#000080"><strong><img alt="Melinda J. Bentley" src="//content.presspage.com/uploads/2361/500_melinda-bentley-100x130.png?x=1581788524988" style="float:left; height:130px; margin:5px 10px; width:100px" />Melinda J. Bentley</strong></span></p><p><span style="color:#000080">Melinda J. Bentley is Legal Ethics Counsel for the Advisory Committee of the Supreme Court of Missouri.</span></p><p>How do you become competent in making those selections and using those technologies? What if there is a loss of a device or data? How do you train your staff? While the Rules of Professional Conduct (Rules) cannot tell you what to buy, fortunately, they do give you clear standards, and further guidance is provided through the Comments to the Rules to assist you with implementing and using technology devices and systems in your practice.<a href="#2"><sup>2</sup></a> Further, by having a keen understanding of the Rules and Comments, you, as a lawyer, can be proactive in both preventing potential problems and being able to respond efficiently and ethically if a difficulty, large or small, occurs.</p><p><strong>Key Ethics Rules: Building A Framework of Understanding</strong></p><p>Three key ethics obligations are at the forefront of establishing a lawyer&rsquo;s understanding in order to prevent potential technology problems: competence, confidentiality, and responsibilities regarding nonlawyer assistants.</p><p><em>Rule 4-1.1 &ndash; Competence</em></p><p>The first key ethics obligation underlying a lawyer&rsquo;s use of technology is found in Rule 4-1.1, which states that &ldquo;[a] lawyer shall provide competent representation to a client. Competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.&rdquo; Further, Comment [6] provides that &ldquo;[t]o maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, <em>including the benefits and risks associated with relevant technology,</em> engage in continuing study and education, and comply with all continuing legal education requirements to which the lawyer is subject.&rdquo; <em>(emphasis added.)</em></p><p><em>Rule 4-1.6 &ndash; Confidentiality of Information</em></p><p>The second key ethics obligation underlying a lawyer&rsquo;s use of technology is found in Rule 4-1.6(a), which generally prohibits a lawyer from revealing information relating to the representation of a client unless an exception is met. In 2017, the Supreme Court of Missouri adopted an additional requirement for lawyers in Rule 4-1.6(c) that &ldquo;[a] lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of the client.&rdquo; Such disclosure or access to confidential client information not only applies to physical information, such as paper documents in a client file, but also to electronically stored information. Think of the large amount of confidential client information lawyers have electronically. That electronic confidential client information makes lawyers&rsquo; duty of technology competence under Rule 4-1.1 that much more critical.</p><p><strong>Reasonable Efforts on Unauthorized Access and Inadvertent or Unauthorized Disclosure</strong>. What constitutes reasonable efforts by a lawyer to safeguard confidential client information to prevent inadvertent or unauthorized disclosure, or unauthorized access? Comment [15] provides guidance to Rule 4-1.6(c) that lawyers are required to act competently regarding safeguarding this information. First, Comment [15] specifically creates three categories of safeguarding information from: (1) unauthorized access by third parties; (2) inadvertent or unauthorized disclosure by the lawyer or other persons who are participating in the representation of the client; (3) and/or inadvertent or unauthorized disclosure by those who are subject to the lawyer&rsquo;s supervision. When describing these categories, Comment [15] references Rules 4-1.1 (Competence), 4-5.1 (Responsibilities of Partners, Managers, and Supervisory Lawyers), and 4-5.3 (Responsibilities Regarding Nonlawyer Assistants).</p><p>Second, Comment [15] provides factors to consider in determining the reasonableness of the lawyer&rsquo;s efforts, including but not limited to:</p><blockquote>the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer&rsquo;s ability to represent clients (e.g., by making a device or important piece of software excessively difficult to use).</blockquote><p>Comment [15] notes that there is no violation of Rule 4-1.6(c) &ldquo;if the lawyer has made reasonable efforts to prevent the access or disclosure.&rdquo;<a href="#3"><sup>3</sup></a></p><p>Additionally, Comment [15] provides guidance that the client may require the lawyer to implement special security measures that are not required by Rule 4-1.6, but it also notes that a client may give informed consent to forgo otherwise required security measures under Rule 4-1.6. &ldquo;Informed consent,&rdquo; as defined in Rule 4-1.0(e), requires communication of &ldquo;adequate information and explanation about the material risks of and reasonably available alternatives to the proposed course of conduct.&rdquo; Per Rule 4-1.0(e), guided by Comment [6], informed consent in this context means discussing the material advantages and disadvantages of forgoing security measures, discussing available options and alternatives, and possibly advising the client to seek other counsel on this decision. Factors as to reasonableness will depend on the experience of the client or if the client is independently represented by counsel.<a href="#4"><sup>4</sup></a></p><p>Further, Comment [15] references that it is beyond the scope of the Rules to determine if state or federal data privacy laws require additional safeguards over client confidential information, or notification in the event of a loss of electronic information or unauthorized access to such information.</p><p>Finally, Comment [15] advises lawyers to consult Rule 4-5.3 (Responsibilities Regarding Nonlawyer Assistants) and its Comments [3] and [4] regarding supervision of nonlawyer assistants outside the firm.</p><p><strong>Reasonable Precautions in Transmission.</strong> Comment [16] to Rule 4-1.6 notes that a &ldquo;lawyer must take reasonable precautions to prevent &hellip; information [relating to the representation of a client] from coming into the hands of unintended recipients.&rdquo; In offering guidance on this responsibility, Comment [16] provides two factors to consider when determining if the lawyer can have a reasonable expectation of confidentiality: first, the &ldquo;sensitivity of the information,&rdquo; and second, &ldquo;the extent to which the privacy of the communication is protected by law or by a confidentiality agreement.&rdquo;</p><p>Comment [16] provides that no special security measures are required &ldquo;if the method of communication affords a reasonable expectation of privacy.&rdquo;<a href="#5"><sup>5</sup></a> Just as with the considerations previously discussed in Comment [15], Comment [16] provides guidance that the client may require the lawyer to implement special security measures that are not required by Rule 4-1.6, but it also notes that a client may give informed consent to forgo otherwise required security measures under Rule 4-1.6. Further, a lawyer may be required to take additional steps to comply with other law, but that is an issue beyond the scope of the Rules.</p><p><em>Rule 4-5.3 &ndash; Responsibilities Regarding Nonlawyer Assistants</em></p><p>The third key ethics obligation underling a lawyer&rsquo;s use of technology is found in Rule 4-5.3, which applies to a lawyer&rsquo;s responsibilities for the conduct of nonlawyers who are &ldquo;retained by or associated with a lawyer.&rdquo; Rule 4-5.3(a) sets the requirements for firm-wide measures to ensure that partners or lawyers with comparable managerial authority make reasonable efforts to make sure the firm has measures in place to give reasonable assurance that the nonlawyer assistant&rsquo;s conduct is compatible with the professional obligations of the lawyer. Similarly, Rule 4-5.3(b) requires a lawyer with direct supervisory responsibility to make reasonable efforts to make sure the nonlawyer assistant&rsquo;s conduct is compatible with the professional obligations of the lawyer. Per Rule 4-5.3(c), lawyers are responsible for the conduct of nonlawyer assistants who they employ, retain, or associate with if the conduct of the nonlawyer assistant would be a violation of the Rules of Professional Conduct if engaged in by the lawyer and if one of two scenarios is present:</p><blockquote>(1) the lawyer orders or, with the knowledge of the specific conduct, ratifies the conduct involved; or</blockquote><blockquote>(2) the lawyer is a partner, or has comparable managerial authority in the law firm in which the person is employed, or has direct supervisory authority over the person and knows of the conduct at a time when its consequences can be avoided or mitigated but fails to take reasonable remedial action.</blockquote><p>Comment [2] to Rule 4-5.3 provides guidance on supervising the conduct of nonlawyer assistants employed by a lawyer, including but not limited to administrative assistants, investigators, law student interns, and paralegals. It describes making sure such assistants receive &ldquo;appropriate instruction and supervision concerning the ethical aspects of their employment,&rdquo; particularly on preserving confidentiality.<a href="#6"><sup>6</sup></a> Ways to ensure appropriate instruction include written policies and protocols, as well as regular instruction on the Rules of Professional Conduct and relevant substantive areas of law in which the nonlawyer is providing assistance. Further, specific protocols should be implemented within the law firm to ensure appropriate supervision of the work product of the nonlawyer.</p><p>Comment [3] to Rule 4-5.3 provides guidance on using nonlawyer assistants outside the firm who assist the lawyer in rendering legal services to a client, including but not limited to retaining investigative or paraprofessional services, hiring a document management company, sending client documents to a third party for printing or scanning, and using a service based on the internet to store client information. Lawyers using these services still must make reasonable efforts to ensure that the services are provided in a manner compatible with the lawyer&rsquo;s professional obligations, and the extent of those efforts will depend on the circumstances.<a href="#7"><sup>7</sup></a></p><p><strong>Applying the Rules to Potential Technology Issues</strong></p><p><em>The Growing Need for Technology Competence</em></p><p>As provided for in Rule 4-1.1 and its Comment [6], lawyers do have an ethical obligation to be competent in technology, including its risks and its benefits, in a lawyer&rsquo;s practice. For example, a lawyer in Oklahoma was publicly censured in 2016 based on a reciprocal discipline from the United States Bankruptcy Court for the Western District of Oklahoma where the lawyer was suspended for failure to file documents in a manner that was compatible with applicable rules.<a href="#8"><sup>8</sup></a> The lawyer failed to report his discipline in the Bankruptcy Court to the Oklahoma Bar Association and also failed to timely notify his clients of his suspension.<a href="#9"><sup>9</sup></a> During the hearing before the trial panel of the Oklahoma Bar Association&rsquo;s Professional Responsibility Tribunal, the lawyer &ldquo;acknowledged his problems with the bankruptcy court were caused by his lack of expertise in computer skills and his frustration trying to meet the federal court&rsquo;s expectations with electronic pleading requirements.&rdquo; The trial panel reported that the lawyer&rsquo;s problems were not with his knowledge of substantive bankruptcy law, but instead &ldquo;technological proficiency.&rdquo;<a href="#10"><sup>10</sup></a> The Supreme Court of Oklahoma, in issuing its public censure of the lawyer, encouraged him to &ldquo;continue to improve his computer skills, or better, to hire an adept administrative assistant to do his pleadings.&rdquo;<a href="#11"><sup>11</sup></a></p><p>While hiring adept support staff is helpful in some circumstances when properly supervised per Rule 4-5.3, it is not a substitute for a lawyer&rsquo;s own technology competency as required by Rule 4-1.1. What are some ways to gain technology competency skills? The answers will be different for each lawyer depending on the lawyer&rsquo;s practice setting and level of technological savvy. One of the best ways to gain the requisite skill and knowledge about the risks and benefits of relevant technology for a law practice is by taking continuing legal education programs related to technology.<a href="#12"><sup>12</sup></a> While Missouri does not require that lawyers receive specific minimum continuing legal education (MCLE) credits related to technology competence, it does offer MCLE accreditation of a number of technology programs that help lawyers gain and maintain professional competence as it relates to the practice of law, professional responsibility, or law office management.<a href="#13"><sup>13</sup></a></p><p>There are several resources readily available to help lawyers build their technology competence, including articles, publications, blogs, podcasts, and more. When it comes to these resources, lawyers should be sure to check that they are receiving information from reputable sources that are appropriate for their practice settings.<a href="#14"><sup>14</sup></a> Malpractice insurance providers may also have resources or standards for insureds.</p><p>Additionally, lawyers should read the terms and conditions of service carefully for each new hardware or software item they consider incorporating into their practices to ensure the item has appropriate safeguards for maintaining client confidential information.<a href="#15"><sup>15</sup></a> Further, lawyers should consider consulting an information technology (IT) professional for assistance.<a href="#16"><sup>16</sup></a></p><p><em>Email and Other Electronic Communications</em></p><p>If lawyers are using email to communicate with clients, they must take reasonable precautions to prevent the unintended interception of confidential client information and should only use email upon proper consideration of Rule 4-1.6 and Comments [15]-[16].<a href="#17"><sup>17</sup></a> While email may be appropriate in some circumstances, other circumstances where the lawyer is transmitting highly sensitive information may require special security measures to comply with Rule 4-1.6.<a href="#18"><sup>18</sup></a> Special security measures may include using email encryption software, placing password protection on attachments, or using &ldquo;a well vetted and secure third-party cloud based file storage system to exchange documents.&rdquo;<a href="#19"><sup>19</sup></a> Remember that Rule 4-1.6(c) requires a lawyer to &ldquo;make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of the client.&rdquo; In looking to the factors discussed in Comment [15] to Rule 4-1.6 as to reasonable efforts to prevent access or disclosure, consider having a conversation with the client at the outset of the representation to determine if email is an appropriate means of communication. Some points to consider are:</p><ul><li>How do the lawyer and the client want to use email to communicate?</li><li>What information will the lawyer and client be exchanging by email?</li><li>What are the terms and conditions of the platforms that host both the lawyer&rsquo;s email and the client&rsquo;s email? Are the platforms ensuring privacy or are they mining emails for personal information?</li><li>How is the client going to be accessing the email?<a href="#20"><sup>20</sup></a> On a personal or work phone or computer? Who else has access to that device or the email account?</li></ul><p>Consider these points, as well as the sensitivity of the information being transmitted, to determine if additional security measures are necessary or if email should even be used.<a href="#21"><sup>21</sup></a> By asking some of these questions, it should help the lawyer determine if he or she is acting reasonably in using email as a form of communication.</p><p>Other forms of electronic communication may include online client portals that have communication features or by texting. Similar questions about confidentiality and appropriateness of the medium should be asked for each of these other potential forms of electronic communication.</p><p>Also, lawyers should be mindful that if they are using one of these forms of electronic communication with clients, the correspondence needs to be retained for the client files in accordance with Rule 4-1.22 (Retaining Client Files) and Advisory Committee of the Supreme Court of Missouri Formal Opinions 115 (no withholding of property belonging to the client to enforce payment of fees or expenses) and 127 (scanning client files).<a href="#22"><sup>22</sup></a></p><p><em>Data Backups, Case and Document Management Systems, and Electronic File Retention</em></p><p>When considering how to backup data, a lawyer should consider the nature of the information to be backed up. Most of it will likely be confidential client information, but it may include items such as trust account records, business records, and much more. Whether a lawyer is considering online (i.e., cloud)and/or on-site backups, those backups pertaining to confidential client information are governed by Rule 4-1.6 and guided by Comments [15] and [16].<a href="#23"><sup>23</sup></a></p><p>Guidance is provided to lawyers regarding cloud backups in Missouri Informal Advisory Opinion 2018-09. It describes how lawyers need to maintain competence in using relevant technology per Rule 4-1.1, safeguard confidential client information per Rule 4-1.6(c), and supervise per Rule 4-5.3.<a href="#24"><sup>24</sup></a> It also cautions lawyers to read the terms and conditions of service carefully to determine ownership and security of client information and the level of access the attorney and provider will have to that client information. It goes on to describe what constitutes reasonable efforts to safeguard confidential client information while using cloud computing, including but not limited to:</p><ul><li>Security measures protecting confidentiality of client information during transmission and storage;</li><li>Prompt notification of attorney in the event of a security breach or provider&rsquo;s receipt of a subpoena for client information;</li><li>Ownership of data solely by attorney or attorney&rsquo;s firm;</li><li>No access rights by the provider to client information, except as required by law;</li><li>Regular data backup by the provider;</li><li>Handling of client information in the event attorney&rsquo;s relationship with the provider is terminated;</li><li>Compliance with applicable law regarding data storage and transmission;</li><li>Reliable access to data by attorney;</li><li>No access to data by third parties, including advertisers, except as required by law; and</li><li>Domestic storage of data or, alternatively, storage in a jurisdiction subject to United States data protection laws or equivalent.<a href="#25"><sup>25</sup></a></li></ul><p>It also provides guidance that lawyers should review the provider policies and practices periodically, as these can change.<a href="#26"><sup>26</sup></a></p><p>For on-site backups, lawyers should consider such things as the physical security of the equipment storing the confidential information, level of encryption, and redundancy (the same data being stored in multiple ways in case one system fails). Lawyers should consult with an IT professional to assist in properly setting up and maintaining this system.</p><p>Many case or document management systems are now provided by vendors as cloud-based services, though some are still provided for on-site network usage. When selecting a case or document management system, lawyers should consider similar factors as just discussed for cloud or on-site back-ups.</p><p>When backing up client information, lawyers should be mindful that they are required to securely store client files for six or 10 years after the completion or termination of the representation absent having an agreement with the client based on informed consent confirmed in writing.<a href="#27"><sup>27</sup></a> The six-year client file retention applies to client files where the representation was completed or terminated on or after July 1, 2016, and the 10-year requirement applies where the representation was completed or terminated prior to July 1, 2016.<a href="#28"><sup>28</sup></a> &ldquo;Client files, except for items of intrinsic value, may be maintained by electronic, photographic, or other media provided that printed copies can be produced. These records shall be readily accessible to the lawyer.&rdquo;<a href="#29"><sup>29</sup></a> Advisory Committee of the Supreme Court of Missouri Formal Opinion 127 permits the destruction of paper files (except for items of intrinsic value) prior to the expiration of the required retention period if the files are maintained electronically for the required period in accordance with the Rules of Professional Conduct.<a href="#30"><sup>30</sup></a></p><p><em>Keeping Client Confidential Information Secure on Phones, Laptops, Tablets, Etc.</em></p><p>Just as lawyers have an obligation to secure physical files of clients from unauthorized access, the same is true of electronic files lawyers maintain on portable electronic devices such as phones, laptops, tablets, and other similar devices.<a href="#31"><sup>31</sup></a> Whether the devices are those of the firm, or lawyers and employees are permitted to bring their own devices and use them for firm business, reasonable measures may include some of the following suggestions:</p><ul><li>Take reasonable steps to ensure confidentiality by, at a minimum, having strong passwords to access these devices.<a href="#32"><sup>32</sup></a></li><li>Passwords should be changed periodically.<a href="#33"><sup>33</sup></a></li><li>Consider additional safeguards such as encrypting the data on these devices, using multi-factor authentication to access firm systems.<a href="#34"><sup>34</sup></a></li><li>Avoid public Wi-Fi and only choose secure Wi-Fi, as well as consider using a virtual private network (VPN).<a href="#35"><sup>35</sup></a></li><li>For lost or stolen devices, have a way to remotely disable the devices and destroy the data contained on those devices.<a href="#36"><sup>36</sup></a></li><li>Implement firewalls, keep updated anti-malware, anti-spyware, and anti-virus protections on all devices where confidential client information is stored or transmitted.<a href="#37"><sup>37</sup></a></li><li>Apply all security patches and updates for software and devices.<a href="#38"><sup>38</sup></a></li></ul><p>These suggestions are some starting points for what constitutes reasonable measures to secure client confidential information and are not intended to be an exclusive list. As previously suggested, lawyers should be sure to consider the type of client confidential information and applicable state and federal laws. The prudent lawyer will consider consulting with an IT professional, the lawyer&rsquo;s malpractice insurance carrier, and other appropriate resources for additional guidance.</p><p><em>Metadata</em></p><p>Another source of client confidential information lawyers should be mindful of securing is metadata, meaning electronically embedded data.<a href="#39"><sup>39</sup></a> Informal Advisory Opinion 2014-02 asks in the litigation context if a lawyer &ldquo;has an ethical obligation to make good faith efforts to prevent the inadvertent electronic transmission of embedded metadata to opposing party or counsel?&rdquo; Citing Rule 4-1.6, guidance is provided that the lawyer must use reasonable care to ensure that no confidential client information related to the representation is revealed without the client&rsquo;s consent, including confidential information that is contained in embedded metadata.<a href="#40"><sup>40</sup></a> It provides that this may require scrubbing documents of metadata before transmitting them.<a href="#41"><sup>41</sup></a> However, the Informal Advisory Opinion goes on to note:</p><blockquote>Efforts to protect confidential information must be exercised in light of Attorney&rsquo;s obligation pursuant to Rule 4-3.4(a) not to unlawfully obstruct another party&rsquo;s access to evidence or unlawfully alter, destroy, or conceal evidence. Removing metadata with evidentiary value before transmitting certain documents may constitute a violation of laws governing discovery and therefore violate Rule 4-3.4(a). This informal opinion does not render an opinion about the existence of discoverable evidence in particular metadata or about the effect on substantive legal privileges of the pre-transmission removal or lack of removal of metadata.<a href="#42"><sup>42</sup></a></blockquote><p><em>Responding to a Loss of Client Confidential Information Due to a Lost Device or File, Data Breach, or Cyberattack</em></p><p>Lawyers are custodians of highly sensitive information and can be prime targets for hackers.<a href="#43"><sup>43</sup></a> Missouri Informal Advisory Opinion 2017-02 discusses a lawyer&rsquo;s ethical duties when a nonlawyer assistant has disclosed client confidential information to third parties, but the ethics analysis as it relates to disclosing this breach to the client will be similar in the event of a lost device or file, data breach, or cyberattack. It advises that lawyers have an obligation under Rule 4-1.4 (Communication) to disclose the confidentiality breach to the affected client and explain the matter to the extent necessary for the client to make an informed decision about the representation. That disclosure also needs to occur in the event of a lost device or file where client confidential information is disclosed, whether lost by the lawyer or a nonlawyer assistant employed or retained either inside or outside the law firm, as the lawyer is responsible for that conduct under Rule 4-5.3. A similar communication is also necessary in the event of a data breach or cyberattack where confidential client information is disclosed.<a href="#44"><sup>44</sup></a></p><p>Rule 4-1.6(c), requiring reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation, also notes in Comments [15] and [16] that state and federal data privacy laws may govern or impose notification requirements upon a loss of electronic information or unauthorized access, so lawyers should be mindful of these laws both in how they choose to safeguard confidential client information and handle a loss of such information.</p><p><em>Working with IT Professionals and Vendors Outside the Law Firm</em></p><p>While lawyers may be aware of the obligations to train and supervise nonlawyer assistants within the firm, Rule 4-5.3, Comment [3] reminds lawyers that these same obligations apply regarding nonlawyer assistants employed or retained outside the firm. These include outside IT professionals lawyers may hire to help support their firms and vendors who provide services based on the internet to store client information such as data backup provides, case or document management programs, or other similarly based services used within the firm. Lawyers have the obligation to make reasonable efforts to ensure that the services are provided in a manner compatible with their professional obligations under the Rules.</p><p>Reasonable efforts will vary depending on the circumstances, &ldquo;including the education, experience and reputation of the nonlawyer; the nature of the services involved; the terms of any arrangements concerning the protection of client information; and the legal and ethical environments of the jurisdictions in which the services will be performed, particularly with regard to confidentiality.&rdquo;<a href="#45"><sup>45</sup></a>&nbsp;Directions should be communicated to the nonlawyer in a manner appropriate under the circumstances so as to give reasonable assurance that the conduct of the nonlawyer is compatible with the professional obligations of the lawyer.<a href="#46"><sup>46</sup></a> Missouri Informal Advisory Opinions 20070008 and 20050068 both suggest confidentiality agreements should be used when working with nonlawyer vendors and service providers outside the firm. Such agreements are also advisable when working with outside IT professionals, as well as direct training, as appropriate, on confidentiality and other applicable professional obligations of lawyers to ensure the IT professionals&rsquo; conduct is compatible with the conduct of lawyers.</p><p><em>Be Aware of Scams</em></p><p>Lawyers are frequently the targets of potential scams, as lawyers may hold trust account funds for clients as well as sensitive confidential client information. These potential scams often start as emails from those purporting to be legitimate sources, such as potential clients, known clients, financial institutions, businesses, government entities, etc., but are actually phishing attempts to gain access to funds and/or personal information of lawyers or clients. Additionally, emails containing links or attachments from known or unknown senders may contain viruses, malware, spyware, ransomware, or other mechanisms to corrupt computer systems and/or gain access to sensitive information. Lawyers must be savvy to these potential scams and train themselves and their nonlawyer assistants to prevent these breaches.</p><p>Trust account scams are some of the most common attacks against lawyers. Lawyers who believe they may have clients who have provided fraudulent checks in an effort to obtain good funds from lawyers&rsquo; trust accounts wonder how to ethically proceed. Guidance has been provided in Informal Advisory Opinion 2018-06, which addresses such a potential scam scenario in which a lawyer&rsquo;s purported prospective client sent the lawyer a bogus check for deposit into the trust account. That Informal Advisory Opinion discusses whether the lawyer may report this purported prospective client to law enforcement. Whether a lawyer-client relationship exists is a question of law and fact that is outside the scope of the Rules of Professional Conduct, but if the lawyer had a prospective client relationship under Rule 4-1.18, the lawyer would not be able to use or disclose information gained in the consultation except as would be permitted under Rule 4-1.9 as though this person were a former client.<a href="#47"><sup>47</sup></a> If no lawyer-client relationship existed, and this person was not a prospective client, the lawyer would not have a duty of confidentiality and would be free to make a report to law enforcement authorities.<a href="#48"><sup>48</sup></a></p><p><strong>Conclusion</strong></p><p>As a lawyer, you should work to gain and maintain competence in technology, engage in reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of clients, and exercise appropriate professional responsibilities over the conduct of nonlawyer assistants both inside and outside the law firm. Focusing on these key ethics rules will assist you in selecting technology devices and systems in your firm, and help prevent breaches of client confidential information. If you have questions about the Rules of Professional Conduct regarding incorporating technology into your law practice, you are encouraged to contact the Legal Ethics Counsel office (<a href="http://www.MO-Legal-Ethics.org" target="_blank">www.MO-Legal-Ethics.org</a>) to seek an informal advisory opinion about your prospective conduct.</p><p><strong>Endnotes</strong></p><p><a id="1" name="1">1</a> Melinda J. Bentley is Legal Ethics Counsel for the Advisory Committee of the Supreme Court of Missouri.</p><p><a id="2" name="2">2</a> <em>See</em> Rule 4, Scope [14].</p><p><a id="3" name="3">3</a> Rule 4-1.0(h) defines &ldquo;reasonable&rdquo; or &ldquo;reasonably&rdquo; to be &ldquo;conduct of a reasonably prudent and competent lawyer.&rdquo;</p><p><a id="4" name="4">4</a> <em>See</em> Rule 4-1.0, Comment [6].</p><p><a id="5" name="5">5</a> <em>See infra</em> discussion of email.</p><p><a id="6" name="6">6</a> <em>See also</em> Mo. Informal Advisory Opinions 2018-04 and 2017-02 (interpreting Rule 4-5.3 as it applies to nonlawyer assistants within a law firm). Informal Advisory Opinions are published on The Missouri Bar&rsquo;s website at: <a href="https://mobar.org/site/Lawyer_Resources/Legal_Ethics_Opinions/site/content/Lawyer-Resources/Legal_Ethics_Opinions.aspx" target="_blank">https://mobar.org/site/Lawyer_Resources/Legal_Ethics_Opinions/site/content/Lawyer-Resources/Legal_Ethics_Opinions.aspx</a></p><p><a id="7" name="7">7</a> See Mo. Informal Advisory Opinion 2018-09 (interpreting Rule 4-5.3 as it applies to use of a cloud computing vendor outside the firm).</p><p><a id="8" name="8">8</a> <em>State of Oklahoma ex rel., Oklahoma Bar Ass&rsquo;n v. Oliver</em>, 2016 OK 37, 369 P.3d 1074 (2016).</p><p><a id="9" name="9">9</a> <em>Id.</em> at &para;15, 369 P.3d at 1077.</p><p><a id="10" name="10">10</a> <em>Id.</em> at <span dir="RTL">&para;5, 369</span> P.3d at 1075.</p><p><a id="11" name="11">11</a> <em>Id.</em> <span dir="RTL">&para;15, 369</span> P.3d at 1077.</p><p><a id="12" name="12">12</a> <em>See</em> Mo. Informal Advisory Opinion 2018-09 (providing guidance on technology competence through continuing legal education courses).</p><p><a id="13" name="13">13</a> <em>See</em> Rule 15.04(b): &ldquo;A program or activity may be an accredited program or activity if it directly contributes to the professional competency of lawyers or judges and has significant intellectual or practical content related to the development or practice of law, professional responsibility, or law office management.&rdquo; <em>See also</em> Rules Related to The Fla. Bar, Ch. 6, R. 6-10.03(b) (requiring Florida lawyers to take at least three of 33 MCLE credit hours every three years in approved technology programs), and 27 N.C.A.C. Ch. 1D &ndash; <span dir="RTL">&sect;</span> .1518(a)(2) (requiring North Carolina lawyers to take at least one hour annually of MCLE devoted to technology training.)</p><p><a id="14" name="14">14</a> <em>See</em> Mo. Informal Advisory Opinion 2018-09.</p><p><a id="15" name="15">15</a> <em>See Id.</em> and Rule 4-1.6, discussion <em>supra; see also</em> Legal Ethics Counsel Resource Page &mdash; Electronic Comunication Resources, <a href="http://molegalethics.org/electronic-communication-resources/" target="_blank">http://molegalethics.org/electronic-communication-resources/</a>.</p><p><a id="16" name="16">16</a> See <em>Id.</em> and Rules 4-1.6 and 4-5.3, discussion <em>supra</em>.</p><p><a id="17" name="17">17 </a><em>See</em> Mo. Informal Advisory Opinion 2012-01 (providing guidance on use of email).</p><p><a id="18" name="18">18</a> <em>Id.</em></p><p><a id="19" name="19">19</a> ABA Comm&rsquo;n on Ethics & Prof&rsquo;l Responsibility, Formal Opinion 477R (revised May 22, 2017).</p><p><a id="20" name="20">20</a> <em>See</em> Mo. Informal Advisory Opinion 990007 (providing guidance on use of email, including consideration of settings of sender and receiver).</p><p><a id="21" name="21">21</a> <em>See</em> Rule 4-1.6, Comment [15].</p><p><a id="22" name="22">22</a> Mo. Sup. Ct. Advisory Committee Formal Opinions are published on the website of the Supreme Court of Missouri at: <a href="http://www.courts.mo.gov/page.jsp?id=11696" target="_blank">http://www.courts.mo.gov/page.jsp?id=11696</a>.</p><p><a id="23" name="23">23</a> <em>See supra</em> discussion of Rule 4-1.6.</p><p><a id="24" name="24">24</a> <em>See supra</em> discussions of Rules 4-1.1, 4-1.6, and 4-5.3.</p><p><a id="25" name="25">25</a> Mo. Informal Advisory Opinion 2018-09.</p><p><a id="26" name="26">26</a> <em>Id.</em></p><p><a id="27" name="27">27</a> <em>See</em> Rule 4-1.22.</p><p><a id="28" name="28">28</a> <em>Id.</em></p><p><a id="29" name="29">29</a> <em>Id.</em></p><p><a id="30" name="30">30</a> <em>See also</em> Legal Ethics Counsel Resource Page, File Retention Resources, <a href="http://molegalethics.org/file-retention-resources/" target="_blank">http://molegalethics.org/file-retention-resources/</a>.</p><p><a id="31" name="31">31</a> <em>See</em> Mo. Informal Advisory Opinion 980030 (providing guidance on preventing physical client file access in an office-sharing arrangement) and Rule 4-1.6(c).</p><p><a id="32" name="32">32</a> ABA Comm&rsquo;n on Ethics & Prof&rsquo;l Responsibility, Formal Opinion 477R (2017) (revised May 22, 2017).</p><p><a id="33" name="33">33</a> <em>Id.</em></p><p><a id="34" name="34">34</a> <em>Id.</em></p><p><a id="35" name="35">35</a> <em>Id. See also</em> Jill D. Rhodes & Robert S. Litt, The ABA Cybersecurity Handbook 35 (2d ed. 2018) (&ldquo;Wireless communication creates opportunities for hackers to intercept sensitive data such as passwords for logging in to corporate networks and online banking sites. Public Wi-Fi locations such as airports, hotels, and coffee shops &mdash; convenient places to check email &mdash; often do not have security features necessary to protect confidential client data.&rdquo;).</p><p><a id="36" name="36">36</a> ABA Formal Opinion 477R, <em>supra</em> note 32<em>.</em></p><p><a id="37" name="37">37</a> <em>Id.</em></p><p><a id="38" name="38">38</a> <em>Id. See also</em> Rhodes & Litt, <em>supra</em> note 35, 21-22 (2d ed. 2018), (describing cyber-attacks against law firms due to outdated software that had not been updated).</p><p><a id="39" name="39">39</a> See Rule 4-4.4, Comment [2] (describing metadata as a form of electronically stored information).</p><p><a id="40" name="40">40</a> Mo. Informal Advisory Opinion 2014-02.</p><p><a id="41" name="41">41</a> <em>Id.</em></p><p><a id="42" name="42">42</a> <em>Id.</em></p><p><a id="43" name="43">43</a> <em>See</em> ABA Comm&rsquo;n on Ethics & Prof&rsquo;l Responsibility, Formal Opinion 483 (2018).</p><p><a id="44" name="44">44</a> <em>Id.</em></p><p><a id="45" name="45">45</a> Rule 4-5.3, Comment [3].</p><p><a id="46" name="46">46</a> <em>Id.</em></p><p><a id="47" name="47">47</a> Mo. Informal Advisory Opinion 2018-06.</p><p><a id="48" name="48">48</a> <em>Id.</em></p>]]></description><category><![CDATA[journal,PracticeManagement,LPMTech,LPMProtect,Archive,LPMCyber]]></category>
            <pubDate>Mon, 17 Feb 2020 09:16:39 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_depositphotos-87054694-xl-2015.jpg?10000" length="0" type="image/jpg" />
                <pp:image>https://content.presspage.com/uploads/2361/500_depositphotos-87054694-xl-2015.jpg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/depositphotos-87054694-xl-2015.jpg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Depositphotos_87054694_xl-2015]]></pp:imageTitle><pp:imageDescription><![CDATA[Walking direction on asphalt]]></pp:imageDescription></item><item>
                        <title>Executive summary: A legacy of service: Helping our neighbors navigate disaster recovery</title>
                        <link>https://news.mobar.org/executive-summary-a-legacy-of-service-helping-our-neighbors-navigate-disaster-recovery/</link>
                        <guid>https://news.mobar.org/executive-summary-a-legacy-of-service-helping-our-neighbors-navigate-disaster-recovery/</guid><pp:caseid>354626</pp:caseid><description><![CDATA[<p><span><i>As I drove into the office this morning, I could see the brown and muddy ground along the highway where floodwaters once stood. During today&rsquo;s lunch-time jog, evidence of the tornado that hit Jefferson City just weeks ago existed in the roar of chainsaws cutting through mangled trees and the bright blue tarps covering roof damage.</i> </span></p><p><span>From the Bar Center&rsquo;s front door, one can see Simonsen Ninth Grade Center, its windows shattered and now covered by plywood. The Missouri Bar Center received only minor roof damage; we were so fortunate. Sadly, many of our friends and neighbors were not, and flooding continues in many areas across Missouri.</span></p><p><span>Our state is geographically positioned to get its share of natural disasters, including severe storms such as ice storms and tornados, as well as flooding. According to the Federal Emergency Management Agency (FEMA), Missouri has had 70 disasters since 1953, including the devastating Joplin tornado in 2011 and the floods of 1993. During both of these significant disasters, Missouri lawyers stepped up to help their fellow citizens, just as they have during the recent flooding and storms.</span></p><p><span>Each time the rivers rise, it&rsquo;s hard to avoid comparing the levels to that seen in the Great Flood of &lsquo;93. For several months spanning the spring and summer of 1993, floodwaters affected nine states, covering 400,000 square miles and causing more than $15 billion in damage. Missouri Bar members assisted with the statewide sandbagging effort, where &ldquo;[s]ore backs and good consciences were the only reward,&rdquo; wrote then-President John Black in September 1993. The Missouri Bar Young Lawyers&rsquo; Section coordinated lawyer volunteers, who staffed Disaster Assistance Centers and helped people with insurance questions and legal documents that were lost in the flooding. Legal Services of Eastern Missouri prepared a training booklet for volunteer lawyers, and The Missouri Bar partnered with local bar associations across the state to help those impacted and working to rebuild.</span></p><p><span>As the floodwaters receded, consumer fraud became a concern. President Black wrote that &ldquo;human vultures flock to the sites of disasters and prey on the downtrodden. Through an aggressive public education effort, lawyers helped alert flood victims to the risks posed by dishonest and exploitive people.&rdquo; In this next phase of assistance, The Missouri Bar partnered with local bar associations to hold &ldquo;Call-A-Lawyer&rdquo; programs across the state, and President Black and then-Attorney General Jeremiah &ldquo;Jay&rdquo; Nixon appeared on a statewide call-in radio program to provide consumer rights advice. Helping Missouri&rsquo;s citizens during this time was a huge team effort among legal services offices, the bar&rsquo;s YLS, and local bar associations &ndash; an effort that would be repeated in the wake of the devastating 2011 tornado in Joplin.</span></p><p><span>The EF-5 tornado on the afternoon of May 22, 2011 &ndash; the seventh-deadliest tornado in our nation&rsquo;s history &ndash; left more than 150 dead and 1,100 injured. With more than $2.8 billion in damage, many lost their homes, and six of our members lost their law offices. It&rsquo;s hard to describe the devastation and power &ndash; we found photographs and documents on my parents&rsquo; farm, some 45 miles away as the crow flies. The Missouri Bar, aided by its YLS, provided free legal advice at multi-agency resource centers and through a legal hotline, as well as resources to help Missouri lawyers assist victims. As then-President John Johnston wrote at the time, despite their own losses, the Jasper County Bar &ldquo;pushed aside its own sorrows, and is already giving free advice to other folks in distress.&rdquo;</span></p><p><span>Each time disaster occurs, members of local bars, legal aid offices, and area attorneys come together to help those in need. As Johnston wrote, &ldquo;Times like this define who we are. We are a great people. We demonstrate this every time something horrible happens to our neighbors. Together, we will help our neighbors get through this. On behalf of The Missouri Bar, our deepest gratitude to all our members who volunteer their expertise and make donations to those in need.&rdquo;</span></p><p><span>On our 75th anniversary, we salute each of you who have stepped forward to assist a neighbor during a time of crisis and disaster. You are a significant part of why we are proud to be Missouri lawyers. Unfortunately, help is still needed as recent floodwaters recede, and we also need to be ready when the next disaster strikes. If you would like to volunteer for the free Disaster Recovery Legal Assistance hotline, you can sign up online at www.mobar.org or contact Brett Rowles, our legal and community services coordinator, at 573-638-2242 or <a href="mailto:browles@mobar.org">browles@mobar.org</a>. You can also sign up to do pro bono your way through a virtual, walk-in clinic where Missouri lawyers answer non-criminal legal questions from low-income Missourians at a time and place that best fits your schedule. Go to <a href="http://Missouri.FreeLegalAnswers.org">Missouri.FreeLegalAnswers.org</a> and click &ldquo;Volunteer Attorney Registration&rdquo; to get started. Thank you for all you do to continue our profession&rsquo;s legacy of service to Missouri citizens in need.</span></p>]]></description><category><![CDATA[molawyers,MOLawyersHelp,ExecutiveSummary,journal,PracticeManagement,LPMProtect]]></category>
            <pubDate>Sat, 17 Aug 2019 15:47:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_sebrinabarrett-597469.jpg?70064" length="0" type="image/jpg" />
                <pp:image>https://content.presspage.com/uploads/2361/500_sebrinabarrett-597469.jpg?70064</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/sebrinabarrett-597469.jpg?70064</pp:imageOriginal><pp:imageTitle><![CDATA[Sebrina Barrett]]></pp:imageTitle></item><item>
                        <title>Your Money or Your Data</title>
                        <link>https://news.mobar.org/your-money-or-your-data/</link>
                        <guid>https://news.mobar.org/your-money-or-your-data/</guid><pp:caseid>373699</pp:caseid><pp:subtitle>Vol.75, No. 2 / March - April 2019</pp:subtitle><pp:summary><![CDATA[<p><i>Trends in other industries make it clear that lawyers must prepare for ransomware attacks. Here&rsquo;s how to get started.</i></p>
]]></pp:summary><description><![CDATA[<p>Shaun Jamison[<a href="#1">1</a>]</p><p><i>Trends in other industries make it clear that lawyers must prepare for ransomware attacks. Here&rsquo;s how to get started.</i></p><p><img alt="Your Money or Your Data" src="http://www.mobar.org/uploadedImages/Home/Publications/Journal/2019/03-04/money-or-data.jpg" title="Your Money or Your Data" /></p><p>Earlier this year, ransomware cyber attacks at Hollywood Presbyterian Medical Center in Los Angeles, California and MedStar Health, based in Columbia, Maryland, made headlines and alarmed health providers and patients. The ransomware attacks, which involve a virus that is designed to hold data hostage until the victim pays for a &ldquo;key&rdquo; to regain access to their data, should also serve as a warning to lawyers.</p><p>Indeed, in a recent ransomware case involving the Brown Law Firm in Jacksonville, Florida, the firm was not able to access its client data.[<a href="#2">2</a>] Instead, the firm received a message stating that their data was not accessible and it would be destroyed unless the firm paid the equivalent of $2,500 in Bitcoins to the hackers behind the attack. Although the firm hired an information technology (IT) professional, it ultimately decided to pay the ransom on the advice of that IT contractor; the risk of losing the data by attempting to circumvent the ransomware was too great. Such attacks are often successful because the hackers behind the assault ask for a relatively small amount, knowing they can spread fees over many victims. This attack strategy also makes it an easier choice for the lawyer to pay.</p><p><b>What is Ransomware?</b></p><p>Ransomware is a malicious computer program (also known as malware) that is introduced into a computer system like a virus and allows the attacker to block access to the victim&rsquo;s computer data and demand payment for restoring the data. Typically, there is a time element to the ransom demand: The owners of the data are threatened with its destruction if the ransom is not paid within a predefined number of hours. If you do not represent likely targets of ransomware, does this affect you as an attorney? Yes, because your law firm or corporate legal department is a target.</p><p><b>What is the Risk?</b></p><p>Lawyers, just like health and finance professionals, maintain confidential and sensitive information which they are obligated to protect and need to access to serve their clients. Lawyers can be locked out of data, and the data may be sold or made public.</p><p><b>Should I Pay?</b></p><p>This is the big question, and one without a great answer. If you pay, you are likely to get your data back. However, you will be a more likely target in the future and you will unwillingly be funding attacks on other lawyers. Further, there is no guarantee the hackers will honor the agreement.[<a href="#3">3</a>] Prevention is ideal, but if you are the victim of an attack, you will have to evaluate whether you can both restore data and protect against its release without paying the hacker. Ironically, sometimes even the police are left with no better option than paying the ransom.[<a href="#4">4</a>] The FBI has sent mixed signals on whether to pay or not, most recently advising against it.[<a href="#5">5</a>] Consulting with an IT professional and law enforcement will help you with the decision-making process.</p><p><b>Preventing Ransomware Attacks</b></p><p>While there is no means of attainng perfect assurance against a ransomware attack, the following precautions can help to mitigate risk and to diminish the impact of a breach on your practice.</p><p><i>Good backup</i>: If you have a backup, you can restore the data to the point of last back up. But you still have a confidentiality issue[<a href="#6">6</a>] and the requirement to safeguard client property.[<a href="#7">7</a>] You will be obligated to report client data was compromised.</p><p><i>Good firewall</i>: A firewall is the watch guard of the firm&rsquo;s network. Think of the firewall as a security bubble. If you turn it on high, you can shut down virtually all communications, but users will complain that system is unusable. If you turn it down too much, you will be open to attack. So you have to find the right balance.</p><p><i>Training</i>: Make sure you and your staff are trained to avoid infecting your network with ransomware. End users can enable breaches by downloading a suspicious attachment or clicking on an unknown link. Hackers use &ldquo;human engineering&rdquo; to trick you into clicking on attachments. If you receive a communication that normally would not come by email, do not open the attachment. Call the sender to confirm. Working from home on an unsecured computer can also compromise the network. Network security is only as good as the weakest link. Any device connected to the network needs to be inspected. Educate your staff on how to avoid risks. Use strong passwords and keep them secure. Keep your antivirus software current, but don&rsquo;t assume it is protecting you.</p><p><i>Encrypt your data</i>: This may not prevent an attack, but it will mean an attacker cannot release your clients&rsquo; confidential data without great effort.</p><p><i>Install an ad blocker</i>: Some ransomware can be delivered via pop-up advertisements.</p><p><i>Hire an expert</i>: Lawyers know what happens when their clients go DIY (do-it-yourself) on complex legal work. Likewise, you should considering hiring an IT professional to evaluate your network&rsquo;s security rather than relying on your own knowledge of cyber security.</p><p><i>Use work computers only for work</i>: Have a computer not connected to your law office network for surfing the Internet, or consult your IT professional for other ideas to isolate and protect sensitive areas of your network.[<a href="#8">8</a>]</p><p><i>Screen and monitor employees</i>: As noted above, an employee might accidentally open a suspicious attachment or click or an inappropriate link, but in addition some employees might sell your password. According to a recent survey, 56 percent of employees would sell passwords for $1,000 or less.[<a href="#9">9</a>]</p><p><i>Review your insurance coverage</i>: Do not assume you have coverage for cyber attacks. Check with your carrier.[<a href="#10">10</a>]</p><p><b>Dealing With Ransomware Attacks</b></p><p>If, despite your best efforts, you become the victim of a ransomware attack, there are several things you will need to do.</p><p><i>IT</i>: Call for IT help, whether internal or an external consultant. Do not undertake any measures on your own unless you are a cyber security expert.</p><p><i>Insurance</i>: Call your insurance carrier. They may be able to help you unwind the problem. And in any case, you may have a notification requirement to secure coverage for an event.</p><p><i>Law enforcement</i>: Call law enforcement.</p><p><i>Work your plan</i>: If you are part of an organization, contact those individuals internally who are identified in your plan, such as partners.</p><p><i>Assess the situation</i>: Can you fix it with a backup? Was data actually accessed? Is paying a ransom advisable?</p><p><i>Determine notification requirements</i>: Once the attack has been resolved and you are up and running, determine notification requirements. You will want to review the ethics rules as well as any state law requiring notification of a breach. Further, if you have any health data, you may have notification requirements under HIPAA.[<a href="#11">11</a>] Failing to disclose, even if you are not required to, may have negative consequences from a trust and public relations standpoint. Weigh your options carefully.</p><p><i>Reassess</i>: Once you are up and running and the system is all clear, take some time to figure out what went wrong and how you can avoid problems in the future.</p><p>Ransomware attacks on lawyers are likely to increase. When the Hollywood and Medstar medical data attacks happened, it seemed like the beginning of a trend. Turns out a recent survey shows that half of the hospitals participating in the research had been subjected to ransomware attacks.[<a href="#12">12</a>] So the two publicized episodes were public confirmation of a trend, not the possible beginning of one. It may well be the same in the legal industry. Once hackers see success with victims motivated to recover and protect their clients&rsquo; data, they will continue the attacks as long as it remains profitable. This summer, we learned hackers are targeting lawyers using phony ethics complaints to trick them into downloading an attachment infected with ransomware.[<a href="#13">13</a>]</p><p>Staying up to date is part of your defense. The ABA&rsquo;s Cyber Security Legal Taskforce is a good source of information.[<a href="#14">14</a>] The Better Business Bureau and the FTC have scam alerts. ABA members can also sign up to receive FBI Cybersecurity Alerts.[<a href="#15">15</a>] You should document your cyber security policy and use it to train your employees and have as a reference in case of attack. Your will want to have it in paper form in case you cannot access your computers. Your policy should outline the procedures for your response. You don&rsquo;t want to be trying to figure out what to do when your office is paralyzed by an attack.</p><p>Lawyers are obligated to keep up with technology to protect their clients&rsquo; interests or to hire someone with the expertise to do it for them.[<a href="#16">16</a>] By keeping up with the risks and educating and monitoring your staff, you can avoid having to pay a ransom for your data and the possibility of seeing your clients&rsquo; data compromised.</p><p><i>This article originally appeared in the September 2016 issue of</i> Bench & Bar of Minnesota<i>, the official magazine of the Minnesota State Bar Association, and is reprinted with permission.</i></p><p><b>Endnotes</b></p><p><a id="1" name="1">1</a> Shaun Jamison is a professor of law with Concord Law School of Kaplan University and is the former chair of the Minnesota State Bar Association Practice Management and Marketing Section. Jamison teaches CyberLaw, Legal Research, and the Future of Law Practice. He may be contacted at <a href="mailto:sgjamison@gmail.com">sgjamison@gmail.com</a>.</p><p><a id="2" name="2">2</a> &ldquo;Florida Law Firm Hit by Ransomware Scheme&rdquo; (2/16/2016) <a href="http://www.batblue.com/florida-law-firm-hit-by-ransomware-scheme/">http://www.batblue.com/florida-law-firm-hit-by-ransomware-scheme/</a> (now <a href="https://opaq.com/">https://opaq.com/</a>)</p><p><a id="3" name="3">3</a> Katie Dvorak, &ldquo;Hackers return for more money in ransomware attack at Kansas hospital,&rdquo; FierceHealthCare (5/23/2016) <a href="http://www.fiercehealthcare.com/it/hackers-return-for-more-money-ransomware-attack-at-kansas-heart-hospital">http://www.fiercehealthcare.com/it/hackers-return-for-more-money-ransomware-attack-at-kansas-heart-hospital</a>.</p><p><a id="4" name="4">4</a> &ldquo;When hackers cripple data, police departments pay ransom,&rdquo; Boston Globe (4/6/2016) <a href="https://www.bostonglobe.com/business/2015/04/06/tewksbury-police-pay-bitcoin-ransom-hackers/PkcE1GBTOfU52p31F9FM5L/story.html">https://www.bostonglobe.com/business/2015/04/06/tewksbury-police-pay-bitcoin-ransom-hackers/PkcE1GBTOfU52p31F9FM5L/story.html</a>.</p><p><a id="5" name="5">5</a> Paul, &ldquo;FBI&rsquo;s Advice on Ransomware? Just Pay The Ransom,&rdquo; Security Ledger (10/22/2015) <a href="https://securityledger.com/2015/10/fbis-advice-on-cryptolocker-just-pay-the-ransom/">https://securityledger.com/2015/10/fbis-advice-on-cryptolocker-just-pay-the-ransom/</a>, but see a more recent declaration from FBI Cyber Division Assistant Director James Trainor saying companies should not pay ransom: Katie Dvorak, &ldquo;Hackers return for more money in ransomware attack at Kansas hospital,&rdquo; FierceHealthCare (5/23/2016) <a href="https://www.fiercehealthcare.com/it/hackers-return-for-more-money-ransomware-attack-at-kansas-heart-hospital">https://www.fiercehealthcare.com/it/hackers-return-for-more-money-ransomware-attack-at-kansas-heart-hospital</a>.</p><p><a id="6" name="6">6</a> ABA Model Rule 1.6(c) &ndash; A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.</p><p><a id="7" name="7">7</a> ABA Model Rule 1.15 &ndash; &hellip; property shall be identified as such and appropriately safeguarded. Complete records of such account funds and other property shall be kept by the lawyer and shall be preserved for a period of [five years] after termination of the representation.</p><p><a id="8" name="8">8</a> Scott Perry, &ldquo;Law Firms Kill Web Access In the Name of Cybersecurty,&rdquo; (5/26/2016) Above the Law <a href="http://abovethelaw.com/?sponsored_content=it-security-vs-users&rf=1">http://abovethelaw.com/?sponsored_content=it-security-vs-users&rf=1</a>.</p><p><a id="9" name="9">9</a> Tara Seals, &ldquo;Employees Would Sell Passwords for $1000 or Less,&rdquo; retrieved 4/15/2016: <a href="http://www.securion.io/#!Employees-Would-Sell-Passwords-for-1000-or-Less/c14jh/56f137afOcf266a29260bfe">http://www.securion.io/#!Employees-Would-Sell-Passwords-for-1000-or-Less/c14jh/56f137afOcf266a29260bfe</a>.</p><p><a id="10" name="10">10</a> Peter S. Vogel, &ldquo;Bad news for P.F. Chang &ndash; Court rules that all claims for 2014 data breach are not covered under its cyberinsurance!&rdquo; Lexology (6/2/2016) <a href="https://www.lexology.com/library/detail.aspx?g=4dc04202-1357-4b3c-8c96-43aeac63e00f">https://www.lexology.com/library/detail.aspx?g=4dc04202-1357-4b3c-8c96-43aeac63e00f</a>.</p><p><a id="11" name="11">11</a> Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936 (1996).</p><p><a id="12" name="12">12</a> Katie Dvorak, &ldquo;Poll: Most hospitals have been targets of ransomware attacks,&rdquo; FierceHealthIT, retrieved 4/12/2016: <a href="https://www.fiercehealthcare.com/it/poll-most-hospitals-have-been-targets-ransomware-attacks">https://www.fiercehealthcare.com/it/poll-most-hospitals-have-been-targets-ransomware-attacks</a>.</p><p><a id="13" name="13">13</a> Mike Mosedale, &ldquo;Ransomware scam targets lawyers with phony ethics complaints,&rdquo; Minnesota Lawyer (6/7/2016) <a href="http://minnlawyer.com/2016/06/07/yikes-ransomware-scam-targets-lawyers-with-phony-ethics-complaints/">http://minnlawyer.com/2016/06/07/yikes-ransomware-scam-targets-lawyers-with-phony-ethics-complaints/</a>.</p><p><a id="14" name="14">14</a> ABA Cyber Security Legal Taskforce, <a href="https://www.americanbar.org/groups/cybersecurity/">https://www.americanbar.org/groups/cybersecurity/</a></p><p><a id="15" name="15">15</a> Log in to sign up to receive alerts at this link: <a href="https://shop.americanbar.org/eBus/MyABA/MyLists.aspx">https://shop.americanbar.org/eBus/MyABA/MyLists.aspx</a>.</p><p><a id="16" name="16">16</a> ABA Model Rule 1.1 &ndash; A lawyer shall provide competent representation to a client. Competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.</p><p>&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p>]]></description><category><![CDATA[journal,PracticeManagement,LPMProtect,LPMMoney,Archive]]></category>
            <pubDate>Mon, 01 Apr 2019 15:07:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_missouribar75-logofinal-2019-818099.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_missouribar75-logofinal-2019-818099.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/missouribar75-logofinal-2019-818099.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Missouri Bar 75_Logo[FINAL]-2019]]></pp:imageTitle><pp:imageDescription><![CDATA[The Missouri Bar&amp;#039;s 75th Anniversary Logo]]></pp:imageDescription></item><item>
                        <title>Cryptocurrency and blockchain: Here we go down the rabbit hole</title>
                        <link>https://news.mobar.org/cryptocurrency-and-blockchain-here-we-go-down-the-rabbit-hole/</link>
                        <guid>https://news.mobar.org/cryptocurrency-and-blockchain-here-we-go-down-the-rabbit-hole/</guid><pp:caseid>444067</pp:caseid><pp:subtitle>Vol. 74, No. 6 / Nov.-Dec. 2018</pp:subtitle><description><![CDATA[<p><span><span><span><span><span><span>Doug Fredrick<sup>1</sup></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>As our society, as well as our economy, rapidly evolves into a digital format, the law must come to grips with how to account for things that did not previously exist. The advent of the Internet spawned new ways to communicate, do business, and commit crimes. In the same way, electronic devices have fundamentally transformed the practice of law over the course of the last decade; briefcases have been replaced by iPads and fax machines by Microsoft Outlook.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Accordingly, entirely new categories of evidence have found their way into the courtroom: e-mails to prove a contract was breached, digital videos to prove an assault occurred, text messages to prove a parent is unfit, and metadata embedded in digital photographs to prove the location or identity of where the photograph was taken. Most of these intangible things can be converted into a tangible format by printing them off onto paper, but inherently intangible assets are by no means foreign concepts to the judiciary. The goodwill of a business has long been recognized as having value,<sup>2</sup> and digital music is now a viable commercial product.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>We are currently experiencing the beginning of the next evolutionary step of our economy as blockchain technology weaves its way into the fabric of our financial and business transactions.</span></span></span></span></span></span></span></span>&emsp;<span><span><span><span><span><span><span><span>One of the reasons blockchain and cryptocurrencies can be difficult to understand is because they are truly unique concepts with no reference point or previously existing thing with which to compare them. Cell phones had land lines, electric vehicles had combustion engines, and digital photographs had Kodak film and Polaroids, but digitally encrypted mathematical problems created and solved by supercomputers that are utilized for financial transactions aren&rsquo;t quite as intuitive. In 2017, cryptocurrencies were thrust into the headlines and, accordingly, into the consciousness of the general public. As our society continues to transform into a digital format, it is reasonably foreseeable that cryptocurrencies will become more commonplace in the courtroom. This article will educate the reader about the basic concepts underpinning blockchain technology, explain the essential tenets of Bitcoin and other cryptocurrencies, examine the uses of smart contracts, and discuss how these assets, products, and services may soon be treated under the law.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Key Terms and Concepts</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Some of the concepts discussed in this article are extraordinarily technical or abstract in nature. In order to facilitate a meaningful understanding of the issues discussed herein, the following definitions are provided:</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Cryptocurrency: An electronic form of currency that has no tangible format.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Bitcoin: The most prominent of all cryptocurrencies.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Blockchain: An electronic ledger that records digital transactions.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Node: A supercomputer that is used to facilitate the creation and transaction of cryptocurrencies.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Cryptocurrency and the Law</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The law must continually evolve to account for new things, and it takes time for the corpus of jurisprudence to make sense of something that did not previously exist. Although blockchain technology and cryptocurrency were both invented in 2008, they have only recently begun to be implemented on a large scale. As these two separate but interrelated technologies become more enmeshed into our economy and society, it is time for lawyers and judges alike to begin building a foundation of understanding on which will evolve the structural analysis of legal issues surrounding the private, commercial and criminal uses of cryptocurrencies.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Where It All Began</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The Internet is a platform on which countless applications and products have been built, such as e-mail, social media, and online shopping, with smart phones as conduits for these products and services. Similarly, blockchain technology is a new platform on which cryptocurrencies, smart contracts, and other financial products and services are being created.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The genesis of Bitcoin and blockchain technology was in October 2008, when Satoshi Nakamoto published a white paper on a cryptography e-mail list entitled &ldquo;Bitcoin: A Peer-to-Peer Electronic Cash System.&rdquo; <sup>3</sup> In that publication, he introduced the world to blockchain technology and, simultaneously, a new unit of value called Bitcoin. He described Bitcoin as &ldquo;[a] purely peer-to-peer version of electronic cash.&rdquo;<sup>4</sup> In January 2009, Nakamoto released the software on which the first units of Bitcoin were created.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The identity of Satoshi Nakamoto only contributes to Bitcoin&rsquo;s ethereal nature, because it remains a mystery to this day. Theories have abounded as to the gender, age, and nationality of the person behind the screen name.<sup>5</sup> Some have even postulated that Satoshi Nakamoto is actually the product of a conglomerate of individuals. Regardless of whether Satoshi Nakamoto is a person or many people, what is undeniable is that blockchain technology and cryptocurrency are very much part of our reality, and they are proving to be the next evolution in digital transactions. For example, &ldquo;Ripple has licensed its blockchain technology to over 100 banks,&rdquo;<sup>6</sup> and in October 2017 American Express adopted Ripple&rsquo;s blockchain technology.<sup>7</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Blockchain Technology</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>&ldquo;[F]or all of its merits, [blockchain technology] is not [entirely] a new technology.&rdquo;<sup>8</sup> &ldquo;Rather, it is a combination of proven technologies applied in a new way. It was the particular orchestration of three technologies (the Internet, private key cryptography, and a protocol governing incentivization) that made . . . Satoshi Nakamoto&rsquo;s idea so useful.&rdquo;<sup>9</sup> Essentially, blockchain is an open, public, decentralized ledger that records transactions between two parties in a permanent manner.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Traditional electronic payments such as credit cards, PayPal, ApplePay and Automated Clearing House (ACH) payments move through phone lines, cellular networks or the Internet, and utilize the software and hardware that is created and installed by the company that is facilitating the transaction. The same company that facilitates the transactions maintains a central ledger that keeps track of all transactions that flow through their network, software, and hardware.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>By contrast, transactions sent through a blockchain enable one person or entity to send cryptocurrency directly to another person or entity without the use of a third-party intermediary. The ledger that records the transactions is public and available to all of the computers connected to that particular blockchain network. As a means of comparison, a similar file-sharing system, called Napster, was created in 1999 that allowed users (albeit illegally) to share music directly with one another. Although Napster had no central ledger of any kind, it was a way to transfer digital files directly between two people.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>There are many different blockchain networks; each one has its own unique unit of value that is tailored to a particular use. Bitcoin is one of many different cryptocurrencies. As of the time of writing, the most popular &ldquo;cryptos&rdquo; are (in order of market capitalization) Bitcoin, Ethereum, Ripple, Bitcoin Cash, EOS, and Stellar.<sup>10</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>How Transactions Work (Generally Speaking)</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>In a practical sense, transferring cryptocurrencies is no different than paying bills or transferring money between accounts online or through an app on your smart phone; the process takes just a minute or two to complete (the actual transmission of funds can take anywhere from a few seconds to several days). Technically speaking, a transaction begins when User 1 initiates a request to send cryptocurrency to User 2. This is typically done through a smart phone app or a website. The supercomputers that are connected to that particular blockchain network first validate that User 1 owns the amount of cryptocurrency requested to be transferred. Next, they validate that User 1 hasn&rsquo;t previously sent/spent the currency that will be transferred. This prevents cryptocurrency from being spent more than once.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Double-spending is a problem unique to digital currencies because digital information and assets can be reproduced relatively easily. Physical currencies do not have this issue because they cannot be easily replicated, and the parties involved in a transaction can immediately verify the bona fides of the physical currency. With digital currency, there is a risk that the sender/spender could make a copy of the digital currency and send it to a merchant or another party while retaining the original.<sup>8</sup> To double-spend a cryptocurrency, digital bank robbers would need to rewrite the entire blockchain, and to do that they would have to control more than half of the network&rsquo;s puzzle-solving capacity. Such a &ldquo;51 percent attack&rdquo; would be prohibitively expensive and complex. As of January 20, 2015, Bitcoin miners had 13,000 times more combined number-crunching power than the world&rsquo;s 500 biggest supercomputers.<sup>11</sup> That collective computing power has increased exponentially in the last three years. The way the large-scale thefts of cryptocurrencies that have been covered in the media in recent years were not a result of this kind of &ldquo;brute force&rdquo; hack. Rather, they were the result of more traditional methods of online theft: tricking someone to disclose their login information or private key, reliance on an insecure/unstable third party, someone impersonating a cryptocurrency recipient, or an &ldquo;exit scam&rdquo; where individuals set up a digital wallet or exchange, confiscate all the cryptocurrency, and then claim they were hacked.<sup>12</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Once a majority of computers on the network confirm that User 1 owns the amount of cryptocurrency requested to be transferred and hasn&rsquo;t previously spent it, the transaction gets added to the public ledger as a &ldquo;block&rdquo; in the chain of transactions. Since there is no intermediary that controls the ledger, transactions cannot be reversed or changed in any way, because it would require undoing all of the blocks that came before the block being altered. This unique attribute of blockchain technology prevents the same cryptocurrency from being fraudulently transferred.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Cryptocurrencies are stored in accounts commonly referred to as wallets, which are essentially digital accounts that can be accessed by logging into a website or using a smart phone app. Unlike bank accounts, they are not insured by the FDIC. However, it does insure up to $250,000 of U.S. dollars in Coinbase wallets, if held by a U.S. citizen.<sup>13</sup> Most wallets are not designed to contain U.S. dollars or euros.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Each wallet is randomly assigned a unique public key that is comprised of 34 alphanumeric characters that cannot be changed. Each public key has a corresponding private key that is a series of 64 alphanumeric characters. Using the example from above, User 1 would type in or scan User 2&rsquo;s public key into their request to send funds, and then User 1 would authenticate and finalize the transaction with their private key. This history of the public keys of both users on the blockchain is then reviewed and approved by multiple supercomputers connected to the blockchain network.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Creation of Cryptocurrencies</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Cryptocurrencies are created in one of two ways: by issue or by mining. Some companies, through massive amounts of computer code, have created their own currency and/or blockchain network, such as Ethereum and Ripple. These companies simply release a fixed number of their unique units of value (&ldquo;coins&rdquo;) onto their networks. Coins can also be released by the mining process. The term &ldquo;mining&rdquo; is misleading, because the process is nowhere near what the average person thinks of when they picture minerals being dug or blasted out of the earth. &ldquo;Every ten minutes or so [supercomputers (called &ldquo;nodes&rdquo; or &ldquo;miners&rdquo;)] collect a few hundred pending bitcoin transactions (a &ldquo;block&rdquo;) [from the network] and turn them into a mathematical puzzle.&rdquo;<sup>14</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The first miner to find the solution announces it to others on the network. The other miners then check whether the sender of the funds has the right to spend the money, and whether the solution to the puzzle is correct. If enough of [the nodes on the network agree with the solution and announce] their approval, the block is cryptographically added to the ledger and the miners move on to the next set of transactions (hence the term &ldquo;blockchain&rdquo;). The miner who found the solution gets 25 Bitcoins as a reward, but only after another 99 blocks have been added to the blockchain ledger. All this gives miners an incentive to participate in the system by validating transactions.<sup>15</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Understanding the Value of Cryptocurrencies</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>In order to begin to understand the value of cryptocurrency, one must first ask, &ldquo;Why does anything have value?&rdquo; The rhetorical answer is, &ldquo;Because people believe it does.&rdquo; The reason a yellow-colored mineral called gold has value is because people collectively believe it does. Why is a piece of paper produced by a slot machine with a bar code and numbers printed on it worth the stated value? Because people believe it is. Will the casino guaranty the exchange of that piece of paper for U.S. currency? In most cases, yes. Can you take that certificate to the gas station next door and trade it for fuel? No. The reason fiat currencies such as the U.S. dollar have been successful is because governments have convinced a critical mass of people that a rectangular piece of paper is worth the amount printed on the bill.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Moving on to digital transactions, if money is fraudulently transferred out of a bank account, the FDIC will put money back into that account. But what really happens? A series of digital transactions occur and people believe they have their money back because that&rsquo;s what it says on their computer screen. If you want to buy a cup of coffee with a credit card, you swipe a plastic card in an electronic device, a series of computers in different locations communicate with each other to verify available funds and complete the transaction, and then &ndash; based on the faith in that computer system &ndash; the barista hands you a cup of coffee. We have been living in a digital economy for quite a while now; in that sense, cryptocurrencies do not require a very large leap of faith.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The two most common aspects of cryptocurrency that challenge the traditional notions of monetary value are:1) the absence of a centrally controlled ledger and an entity that controls all of the data, and 2) the lack of an entity that will replace or refund your money if it is stolen or if the entity that holds your money collapses. The cryptography and mathematical certainty of blockchain transactions negates the necessity of those two concepts.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Another hallmark of value is scarcity. When Satoshi Nakamoto unleashed Bitcoin, there were a total of 50 coins, and the mathematical formula would (and does) produce batches of new coins every 10 minutes. Nakamoto established a limit of 21 million Bitcoins that would ever be created. If the current rate of mining of Bitcoins sustains itself, that limit is expected to be reached around the year 2140. A total of 60 million Ether were created <sup>16</sup> and Ripple initially created 100 billion of its coins.<sup>17</sup></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Before a thing can be valued, it must first be clearly defined. A dollar is first and foremost a form of currency and means of exchange. A currency/asset hybrid is the American Gold Eagle, which is the official gold bullion coin of the United States. A Gold Eagle is utilized primarily as a store of value and it is regulated and traded as a commodity, but it can also be legally used as a means of exchange if two parties are willing to use it in that way.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Some cryptocurrencies will evolve into commodities, while others will become true means of exchange. As Bitcoin has ascended in value, transaction times have slowed due to a saturation of the network, government entities have begun to regulate it, and it is being treated more like a commodity. By way of comparison, while Bitcoin has become the digital cousin of gold, Litecoin is thought of as the digital cousin of silver &ndash; less valuable, with quicker transaction times, and thus more amenable as a means of exchange.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Valuing Cryptocurrency in Dissolutions of Marriage</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>As of the date of publication, no Missouri appellate court has issued an opinion that contains the word &ldquo;cryptocurrency&rdquo; or any variation thereof. Therefore, we must look at the existing framework of common law that defines how courts assign value to assets and commodities.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>&ldquo;[A] trial court is prohibited from entering a valuation of marital property not supported by evidence at trial, but the trial court, nonetheless, enjoys broad discretion in valuing marital property.&rdquo;<sup>18</sup> The trial court is entitled to believe or disbelieve the testimony of either party concerning the valuation of marital property in a dissolution proceeding, and can disbelieve expert testimony. The judicial determination of value must be an informed judgment, but fair &ldquo;value&rdquo; is not susceptible of determination by any precise mathematical computation.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Generally, &ldquo;the appropriate date for valuing marital property in a dissolution proceeding is the date of trial.&rdquo;<sup>19</sup> &ldquo;However, where the division of property is not reasonably proximate to the time of trial, the valuation date should be the date of the division of the property, &lsquo;in that it cannot be said that distributions based upon stale valuations are based on value, for value is by no means a constant.&rsquo;&rdquo;<sup>20</sup> Market conditions and changing economic circumstances can render assets that had been valuable months or years earlier virtually worthless in the present, and vice versa.<sup>13</sup> To distribute marital property without regard to such fluctuations would be illogical.<sup>13</sup> Hence, in those cases where the date of trial is not reasonably proximate to the date of the actual distribution of the marital property, the court should hold another hearing to determine the value of the marital property at the time of its division.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Cryptocurrencies have existed for approximately 10 years, but in many ways they are still in their infancy. The wild fluctuations in value they experience should become less frequent as the technology matures, acceptance grows, and regulation increases. Until then, they will continue to have extreme vacillations in value in sometimes unpredictable ways. In order to prevent the value of cryptocurrencies from becoming stale, judgments must be entered in a timely manner; otherwise, subsequent evidentiary hearings will be necessary.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>There is no single, universally recognized entity that announces the value of cryptocurrencies. The New York Stock Exchange is relied upon when valuing stocks or bonds. The values published by the NYSE are generally accepted by the public to be the actual, true value of the stocks listed on that exchange. In the same way, several web sites have been created to track the values of cryptocurrencies. However, the three largest cryptocurrency exchanges &ndash; Coinbase, Kraken, and Bitstamp &ndash; sometimes assign slightly different values to the same cryptocurrency. A court could base its valuation of cryptocurrency on a snapshot of one of these exchanges.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>In addition to its spot price, a cryptocurrency&rsquo;s market capitalization (the price of a cryptocurrency multiplied by the total number of coins issued) is displayed on these exchanges. This can be a useful means of valuation, but it is not always reliable, because sometimes the number of available coins on a particular blockchain do not yet exist because they have not yet been mined or are being released slowly into the market over time.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>A more specific method of proving the value of a specific crypto wallet would be a screen shot of the wallet, which will display the current value of all cryptocurrencies held in that account, just like a bank account or brokerage account. It is possible that a litigant may have developed a proprietary blockchain during the marriage. In order to value the technology itself, Metcalfe&rsquo;s law may be helpful. While more theoretical in nature, Metcalfe postulated that the value of a network is proportional to the square of the number of the users on the network. Common examples of this law are cellular telephone networks and social media platforms, such as Instagram, Twitter and Facebook; the more individuals who participate in the network, the more valuable the network becomes. If the blockchain that the litigant created has no users and is simply sitting on a hard drive somewhere, it may have relatively little value, but the more computers that are connected to that network and utilizing that blockchain&rsquo;s technology, the more valuable it may be.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Written Discovery</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Generally, cryptocurrencies should be clearly defined. A recommended definition of &ldquo;cryptocurrency&rdquo; is: A digital unit of value that utilizes blockchain technology and cryptography and includes, but is not limited to, Bitcoin, Bitcoin Cash, Litecoin, Ether, Ripple, and any other digital coin, token or alt-coin.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><i><span><span><span>Recommended Requests for Production of Documents:</span></span></span></i></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Screen shots that display the current balance of all cryptocurrencies in each wallet, exchange or other cryptocurrency account owned by you or any entity in which you have an ownership interest since the date of the marriage;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>A ledger of all transactions (i.e., purchases/sales of cryptocurrency or exchange of cryptocurrency for goods or services) for each wallet, exchange or account listed above;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Copies of all bank statements that reflect transactions to or from a cryptocurrency wallet, exchange or cryptocurrency account of any kind since the date of the marriage;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Copies of all credit card statements that reflect transactions to or from a cryptocurrency wallet, exchange or cryptocurrency account of any kind since the date of the marriage;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Copies of all brokerage account statements that reflect transactions to or from a cryptocurrency wallet, exchange or cryptocurrency account of any kind since the date of the marriage; and</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Copies of all text messages or emails that you have sent to another person or entity since the date of the marriage that discuss or pertain to any cryptocurrency owned by you at any point during the marriage (regardless of whether owned solely or jointly with another person or entity).</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><i><span><span><span>Recommended Interrogatories:</span></span></span></i></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>List the public key for all cryptocurrency wallets or cryptocurrency accounts of any kind owned by you or any entity in which you have an ownership interest or control over (regardless of whether owned solely or jointly with another person or entity) at any point in time during the marriage;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>List all cryptocurrency wallets or accounts of any kind that you have owned (solely or jointly with another person or entity) since the date of the marriage;</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>List all individual cryptocurrencies that you have purchased, sold or otherwise transacted since the date of the marriage, the amount of each transaction, and the relevant date(s) of each transaction; and</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>State the source of funds (including the name of the financial institution and relevant account numbers) that was utilized to make all purchases of cryptocurrency since the date of the marriage. This includes any account from which debt or credit of any kind, U.S. dollars or other government currency was used to purchase or trade for cryptocurrency.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Smart Contracts</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Smart contracts are digital transactions that incorporate blockchain technology in an &ldquo;if-then&rdquo; fashion. For example, the details of the sale of a vehicle (sales price, taxes and fees, all of the information otherwise contained on a certificate of title, verification of funds of the buyer) could be uploaded onto a blockchain network. Once both parties certify that the vehicle has physically changed possession from the seller to the buyer, the funds are transferred and the information from the sale becomes a permanent part of the blockchain&rsquo;s public ledger, everything happening instantaneously and simultaneously. Rather than placing trust in the Department of Revenue to keep accurate records that are sometimes difficult to access and/or view, trust would be placed in the blockchain. The only source of error would lie with the individual who is building/coding the transaction by typing inaccurate data, but even much of that information would preexist on the blockchain (previous owners, VIN, make, model, year, and possibly maintenance and accident history), making the possibility of error negligible. Smart contracts can also implement business rules, such as transactions that take place only if two or more parties endorse them, or contingent transactions that are triggered only if another transaction has been completed first.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>The sequential nature of blockchain networks naturally lends itself to transactions such as recording documents that transfer ownership of real estate or vehicles, as well as maintaining medical records, are processes that could benefit from this technology. The Recorder of Deeds&rsquo; office is especially predisposed to implementation of blockchain technology, because a large part of what they do is maintain a public ledger, so it would be a relatively small step to digitize and automate the process of recording real estate documents and even marriage certificates. Several years ago, Missouri transitioned away from a filing system that utilized fax machines and hand-delivered documents and moved to an electronic filing system. The next logical step would be to transition to a blockchain-based system. Each county would likely need to have its own blockchain network, which may be easily implemented, although the technicalities of how that might happen are outside the scope of this article. Obviously, achieving that reality will not happen any time soon, but if Moore&rsquo;s Law (roughly stated: the speed of computing doubles every two years) is applied to blockchain technology in general, it will not be as far off as one might think.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Smart contracts are already gaining recognition under the law. &ldquo;The governor of Tennessee [recently] signed a bill that legally recognizes blockchain data and smart contracts under state law.&rdquo;<sup>21</sup> The spread of blockchain networks is bad for centralized institutions and bureaucracies, such as banks and government authorities. It is possible that the need to have documents notarized may eventually become irrelevant or redundant, because all of the necessary information could be embedded into the blockchain and transferred instantly and infallibly. The public ledger would also remove the need for reconciling each transaction with a notary book. Given the increase in the hacking and theft of information from large companies such as retail stores, banks, and credit card companies, as well as governmental institutions like the United States Office of Personnel Management,<sup>22</sup> transactions that are incapable of being modified or changed (and provide complete transparency of the public ledger) could be a good thing.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Looking to the Future</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Although this article has focused on the relevance of cryptocurrency in the area of family law, the concepts discussed herein also apply to many other legal issues, including the collection of money judgments, whether or not punitive damages are appropriate, analyzing whether or not to file suit against an individual, piercing of the corporate veil, and a litany of bankruptcy issues. In a profession that frequently looks to the past for guidance on current issues, lawyers must begin to expand their thinking and analysis to accommodate the implications of cryptocurrencies, and not just in the courtroom.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>Receipt of electronic payments is a major variable in the area of practice management. Gone are the days when clients might pay with a traveler&rsquo;s check, and the use of cash as a payment method is in steady decline. &ldquo;Credit cards and other forms of electronic payments have become an integral part of our nation&rsquo;s commerce and the way many people prefer to pay. In 2009, credit cards officially surpassed paper check transactions in the United States.&rdquo;<sup>23</sup> American Consumer Credit Counseling conducted a survey that found &ldquo;80% of consumers use their debit card to pay for everyday purchases such as gas, meals, and groceries.&rdquo;<sup>24</sup> The difference between Apple Pay and credit cards is that Apple Pay does not utilize a tangible card to make payments, and all aspects of the transaction are facilitated by an iPhone. As previously discussed, paying with a credit card, Apple Pay and now Bitcoin are seemingly small but significant steps away from traditional methods of transacting money and toward a fully digital economy. The full spectrum of legal professionals should endeavor to understand this relatively new development in our society and derive new methods of applying the law to this new means of currency and value.</span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span>Endnotes</span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span>1 Doug Fredrick received his bachelor&rsquo;s degree in business administration and his Juris Doctor from the University of Missouri-Kansas City. He is a solo practitioner and focuses primarily in the areas of family law, business transactions and litigation, and real estate transactions and litigation. He has argued before the Supreme Court of Missouri and the Southern District of the Missouri Court of Appeals. He currently teaches Entrepreneurship 301 in the Breech School of Business at Drury University and serves as the faculty sponsor for the Cryptocurrency Club.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>2 <i>Hanson v. Hanson</i>, 738 S.W.2d 429, 434 (Mo. banc 1987).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>3 Satoshi Nakamoto, <i>Bitcoin: A Peer-to-Peer Electronic Cash System</i>, https://bitcoin.org/bitcoin.pdf.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>4 <i>Id.</i> (Abstract).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>5 L.S., <i>Who Is Satoshi Nakamoto?</i>, <span>The Economist (N</span>ov. 2, 2015), https://www.economist.com/blogs/economist-explains/2015/11/economist-explains-1.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>6 Jeff John Roberts, <i>Is Ripple for Real? A Closer Look at the Company Behind the Third Most Valuable Digital Currency,</i> <span>Fortune</span> (Oct. 23, 2017), http://fortune.com/2017/10/23/bitcoin-ripple-brad-garlinghouse/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>7 <span>Reuters</span>, <i>American Express Is Getting Into Blockchain-Based Payments With Ripple</i>, <span>Fortune</span> (Nov. 16, 2017), http://fortune.com/2017/11/16/amex-payments-ripple-blockchain/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>8 Nolan Bauerle, <i>What is Blockchain Technology?</i>, <span>Coindesk</span>, https://www.coindesk.com/information/what-is-blockchain-technology/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>9 <i>Id.</i></span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>10 <span>Cryptocurrency Market</span>, https://www.tradingview.com/markets/cryptocurrencies/prices-all/ (June 11, 2018).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>11 L.S., <i>How Bitcoin Mining Works</i>, <span>The Economist (</span>Jan<span>. 20, 2015</span>), https://www.economist.com/blogs/economist-explains/2015/01/economist-explains-11.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>12 Jeff John Roberts, <i>How Bitcoin Is Stolen: 5 Common Threats</i>, <span>Fortune</span> (Dec. 8, 2017), http://fortune.com/2017/12/08/bitcoin-theft/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>13 <i>How Is Coinbase Insured?,</i> <span>Coinbase,</span> https://support.coinbase.com/customer/portal/articles/1662379-how-is-coinbase-insured.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>14 L.S., <i>How Bitcoin Mining Works,</i> <span>The Economist (J</span>an. 20, 2015), https://www.economist.com/blogs/economist-explains/2015/01/economist-explains-11.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>15 <i>Id.</i></span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>16 <span>Ether</span>: <span>The Crypto-Fuel for the Ethereum Network</span>, https://www.ethereum.org/ether.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>17 Selena Larson, <i>Cryptocurrency Boom: Why Everyone Is Talking About Ripple,</i> <span>CNN Business</span> (Jan<span>. 4, 2018, 2:24 AM ET),</span> http://money.cnn.com/2018/01/02/technology/what-is-ripple-cryptocurrency/index.html.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>18 <i>Tarneja v. Tarneja</i>, 164 S.W.3d 555, 559 (Mo. App. S.D. 2005).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>19 <i>Romkema v. Romkema</i>, 918 S.W.2d 294, 298 (Mo. App. E.D. 1996).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>20 <i>Wright v. Wright</i>, 1 S.W.3d 52, 57 (Mo. App. W.D. 1999).</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>21 Nikhilesh De, <i>Smart Contracts Now Recognized Under Tennessee Law</i>, <span>Coindesk (M</span>ar. 23, 2018, 21:01 UTC), https://www.coindesk.com/blockchain-bill-becomes-law-tennessee/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>22 Evan Perez, <i>FBI Arrests Chinese National Connected to Malware Used in OPM Data Breach,</i> <span>CNN Politics</span> (Aug. 24, 2017, 6:29 PM ET), https://www.cnn.com/2017/08/24/politics/fbi-arrests-chinese-national-in-opm-data-breach/index.html.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span>23 Amy Porter, <i>Get Paid Faster Than a Speeding Bullet: Accept Credit Cards</i>, <span>ABA GPSolo Magazine (June 29, 2017)</span>, https://www.americanbar.org/groups/gpsolo/publications/gp_solo/2011/july_august/get_paid_faster_than_speeding_bullet_accept_credit_cards/.</span></span></span></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span>24 <span>ConsumerCredit.com,</span> https://www.consumercredit.com/financial-education/infographics/infographic-cash-vs-card. &ldquo;As of December 2017, 37 percent of . . . North America retailers&rdquo; already accepted payment with Apple Pay. <span>Statista The Statistics Portal,</span> <i>Digital Payment Methods That North American Retailers Accept or Plan to Accept as of December 2017,</i> https://www.statista.com/topics/4322/apple-pay/.</span></span></span> </span></span></span></p>]]></description><category><![CDATA[LPMProtect,PracticeManagement]]></category>
            <pubDate>Mon, 19 Nov 2018 11:21:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_journallogo1.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_journallogo1.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/journallogo1.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Journal Logo(1)]]></pp:imageTitle></item><item>
                        <title>New Year’s resolution: Improve your passwords</title>
                        <link>https://news.mobar.org/new-years-resolution-improve-your-passwords/</link>
                        <guid>https://news.mobar.org/new-years-resolution-improve-your-passwords/</guid><pp:caseid>444084</pp:caseid><description><![CDATA[<p><span><span><span><span><span><span><span>Cindy Neagle<sup>1</sup></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span>We all experience password fatigue, that feeling when you receive yet another notification to create or change a password. The password must meet certain criteria, typically a minimum number of characters containing a combination of uppercase, lowercase, numbers, and/or symbols. Exasperated, you ask yourself, &ldquo;How am I going to remember a new password?&rdquo; So you take the easy route and add an additional exclamation point to your current password or use a password from a different account.</span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>While you are more likely to remember these passwords, re-using or creating predictable passwords leaves you vulnerable to hackers. Stolen passwords, phishing, spear-phishing, and ransomware are serious threats to any internet user, but particularly so for attorneys, who are mandated to protect confidential client information.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><strong><span><span><span><span>Best Practices for Creating Strong Passwords</span></span></span></span></strong></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>You know the basics of password security. Do not store your written passwords under your keyboard; do not use your username, the word &ldquo;password,&rdquo; qwerty, or personal/confidential information as a password; and finally, do not use a single dictionary word. So how do you protect yourself?</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Stop Re-Using Pa5sw0rds!</span></span></span></span></em> <span><span><span><span>Even if you create a strong password, using it for a number of accounts increases the likelihood that it may be stolen. While it is less critical to create unique passwords for each site you visit that does not store your personal or confidential information, never use that password for any site storing such information. Most importantly, you should never re-use your email password at any online site. If your do and one of the eCommerce sites is hacked, your email account is compromised.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Longer is Better<strong>.</strong></span></span></span></span></em> &nbsp;<span><span><span><span>While many sites require a minimum of eight characters, you should create a longer password. Each additional character you add will exponentially increase your password strength. A password consisting of 15 lowercase letters offers better security than an eight-digit password containing mixed, but predictable, characters.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Even So, Mix It Up.</span></span></span></span></em> <span><span><span><span>Many users make it easier on themselves (and hackers) by placing their capital letter at the beginning and the number and/or special character at the end. Your password will be far stronger if capital letters, lower case letters, numbers and special characters are not bunched together. Mixing it up also means that you avoid easily predictable keyboard patterns such as qwerty or 1qaz@wsx.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Don&rsquo;t Change So Often.</span></span></span></span></em> &nbsp;<span><span><span><span>For some of us, frequent change is required by the IT department. If you have a choice, though, it is generally a better policy to create a strong password and keep it for a longer period of time. While this may seem counterintuitive, frequently changing a password makes it tougher for the user to remember, which makes the user more likely to create easily recalled passwords or to simply incrementally increase the number at the end each time a change is required.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Use a Password Manager.</span></span></span></span></em> <span><span><span><span>If you have a unique password for each site you visit, you have far too many passwords to remember which password is connected to which site. You probably are also frequently locked out of accounts or having to reset your passwords. Good news &ndash; there&rsquo;s an app for that! Password managers create and store credentials for each site you use and log you in automatically. Your database of passwords is encrypted with a master password. The benefit of a password manager is that you will have unique and strong passwords for all of your online accounts. The downside is that you absolutely must remember your master password. There are numerous excellent password managers. Dashlane, KeePassX, Password Boss, and LastPass are just a few of the many options and most have both free and paid versions.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><em><span><span><span><span>Use Two-Factor Authentication.</span></span></span></span></em> <span><span><span><span>While these password tips provide a good start to better online security, you should also enable two-factor authentication for any account that offers that option. Two-factor authentication will require that you enter a temporary code sent to your phone along with your regular password. This additional layer can help protect you from attack if your passwords are compromised. This is a particularly good idea for online banking and eCommerce accounts. You can often designate your own personal computer and phone as trusted once it is set up and can avoid the bother of having to enter a code each time you access your account from those devices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Whether you are technologically savvy or not, these tips provide easily achievable steps to better secure your online presence. Resolve to make your 2017 more secure by putting these password systems into practice.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><strong><span><span><span><span>Endnote</span></span></span></span></strong></span></span></span></span></span></p><p>&emsp;<span><span><span><span><span><span><span><span><span>1 Cindy Neagle is Law Practice Management Attorney for The Missouri Bar.</span></span></span></span></span></span></span></span></span></p>]]></description><category><![CDATA[LPMProtect,PracticeManagement,Archive,LPMCyber]]></category>
            <pubDate>Thu, 19 Jan 2017 12:11:00 -0600</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_journallogo1.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_journallogo1.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/journallogo1.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Journal Logo(1)]]></pp:imageTitle></item><item>
                        <title>Every breath you take: Data privacy and your wearable fitness device</title>
                        <link>https://news.mobar.org/every-breath-you-take-data-privacy-and-your-wearable-fitness-device/</link>
                        <guid>https://news.mobar.org/every-breath-you-take-data-privacy-and-your-wearable-fitness-device/</guid><pp:caseid>444082</pp:caseid><pp:subtitle>Vol. 72, No. 2 / March-April 2016</pp:subtitle><description><![CDATA[<p><span><span><span><span><span><span><span><span><span>Not so very long ago, the only way to track your blood pressure, glucose levels, heart rate, and sleep patterns was to visit a doctor&rsquo;s office where a physician would employ state-of-the-art medical instruments and then offer a diagnosis based on the results. Today, you need look no further than your smartphone.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The advent of health-surveillance tools and mobile fitness applications has ushered in a new era of consumer health care that holds enormous promise. Individuals are more empowered than ever to take control of their health, and it is possible to provide real-time tracking and reporting of critical information about fitness to physicians, swiftly and across vast distances.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Yet all this potential poses a challenge in terms of health data privacy and security that rivals &ndash; if not surpasses &ndash; the threats associated with financial data. For more than a decade, consumers have battled the prying eyes of data brokers and hackers to protect their financial information. Now, the battlefront has shifted to include health and lifestyle information that could prove even more sensitive and consequential if hacked.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Health data is more vulnerable in general as a data set than financial data because you can&rsquo;t replace it like you can a credit card,&rdquo; says Michelle De Mooy, deputy director of the Consumer Privacy Project at the Center for Democracy & Technology, a Washington, D.C.-based nonprofit that advocates for civil liberties and human rights on the Internet. &ldquo;When you have a diagnosis, it&rsquo;s something that&rsquo;s a part of your medical history for life. When people are victims of medical identity theft or their medical records have been hacked, there are very few good remedies for those situations. They are unprotected, and sometimes their whole families are unprotected.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>That matters, De Mooy says, because wearables such as fitness wristbands and monitors have become so sophisticated, designed to track user activity and share their data with a multitude of applications and devices, with few if any restrictions. These tools are capable of measuring brain activity, calorie intake, miles walked and run, swimming strokes, blood oxygen and blood sugar levels, and heart rates. They are both fitness coach and a proverbial &ldquo;black box&rdquo; for a consumer&rsquo;s health. They also are a gateway to the lives of their users.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Up to now, informed consumers have been willing to sacrifice a little privacy to gain the benefits associated with fitness trackers and smartwatches: improved wellness, vanquishing unhealthy eating habits, and feeling more liberated to manage their health care. No question these are worthy goals, but legal experts believe Americans may be reaching a critical juncture on health and fitness data because now it is under more threat than ever. Where it was once both taboo and illegal for hackers and corporations to poke around in certain types of health records, this data is being viewed by some as the missing piece in consumer profiles.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>A Federal Trade Commission (FTC) study released in May 2014 revealed that 12 mobile health applications and devices transmitted information to 76 different third parties, and some of the data could be linked back to specific users. In addition, 18 third parties received device-specific identifiers, 14 received consumer-specific identifiers, and 22 received other key health information.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;What we have is this vast amount of information that is being created, and, as the Federal Trade Commission has found, not a lot of attention yet being paid by consumers to how it&rsquo;s being used and shared,&rdquo; says Kristi Wolff, special counsel at Kelley Drye & Warren, LLP. &ldquo;A lot of companies are coming out with innovative products, but they&rsquo;re new and not taking some of the necessary precautions that more established companies would take in terms of data privacy and security.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>With so much at stake, privacy advocates are debating how best to protect consumer wellness and fitness information. Medical or health data generated by doctors, hospitals, and other clinicians is covered by the Health Insurance Portability and Accountability Act (HIPAA), which limits access to patient health records and punishes those who violate the protections. But the information generated through fitness trackers, smartphones, and mobile applications is generally not covered by HIPAA regulations.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Industry officials argue that additional government regulation, if it comes, would be slow and stifling to an enterprise that relies on innovation at the speed of light. Likely, rules would be outdated the moment they are adopted, and they would be solving yesterday&rsquo;s problems rather than forecasting the privacy concerns of tomorrow&rsquo;s devices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Many believe the best way forward is to encourage companies to adopt a best-practice model on data privacy for fitness trackers and applications. Best practices in privacy policies might focus on keeping health data on the device rather than in the cloud, letting the user choose with which applications to share their information, and prohibiting the stats from being sold to data aggregators for behavioral advertising.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>What is indisputable is that there is a great deal of flux and uncertainty in how consumers and technology companies operate within the new digital economy and digital ecology, suggests Jennifer S. Geetter, a partner at McDermott Will & Emery, LLP. Businesses, consumers, lawyers, regulators, policymakers, and investors are not only operating under a different set of rules, but also a different set of possibilities.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;We are in the midst of an important dialogue about our digital world, and one vitally important piece of that is our digital health world,&rdquo; Geetter says. &ldquo;I expect we&rsquo;re going to continue to see volatility and flexibility because the technologies are changing. People always talk about innovation on the technology side, but we&rsquo;re going to have to be legal innovators as well.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>Small Devices, Big Business</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Most consumers are familiar with wearable devices, if they&rsquo;re not wearing one now. Many look like space-age watches and have the functionality of desktop computers. They are a part of the Zeitgeist where people compare the number of steps they&rsquo;ve taken or flights of stairs climbed around the &ldquo;water cooler&rdquo; or on Facebook. Many predict that one day these devices will be as ubiquitous as cell phones.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Among wearable devices, Fitbit captured the public&rsquo;s imagination first and to the greatest extent with its trim, multi-colored plastic wristbands that resembled the Livestrong yellow bracelets, but without the controversy. What began as a homely, hyped-up pedometer in 2007 has turned into a handsome tracking device, monitoring sleep habits, blood glucose levels, calories, heart rate, distances traveled, and routes used.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>But Fitbit isn&rsquo;t alone in the vast frontier of health-tracking tools. Today there is a long list of competitors producing nearly identical lollipop-colored wristbands and mind-boggling applications. Its rivals range from Garmin to Jawbone, Under Armour to Google, and Xiaomi to Misfit. Even jewelry company Swarovski has entered the fray with its bejeweled Shine. Of course, casting a long shadow over the entire category is the Apple Watch, part designer adornment, part lifestyle computer. The Apple Watch, like most Apple products, became a wearable industry leader even before it was shipped to stores in April 2015.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Sales of wearable gadgets &ndash; smartwatches, smart eyewear, and fitness-tracking devices &ndash; have exploded in popularity in recent years, and they are expected to register some 30.9 million units in sales in 2015, according to the U.S. Consumer Electronics Sales and Forecasts, the semiannual industry report of the Consumer Electronics Association (CEA). The forecast, which was released in January 2015 and updated in July, estimated that health and fitness trackers would lead sales among wearable devices with projected sales of 20 million units, and revenues reaching $1.8 billion in 2015, an 18 percent increase over [2014].</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>International Data Corporation (IDC), a global marketing research firm, reported that consumer spending on wearable devices tripled in 2014 compared to 2013. IDC predicts that production of health trackers will jump from 20 million units in 2014 to more than 120 million units in 2019. Meanwhile, the NPD Group, a sales tracking company, reported that more than 25 percent of U.S. consumers already use fitness apps.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Observers believe wearable tech sales will remain robust as long as the applications market follows suit. The availability of applications from third-party developers will ensure the long-term growth of the tracker and smartwatch markets, but it also creates a tsunami of new health information and privacy concerns.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Applications such as Runkeeper, Fit-Star Personal Trainer, Nike+ Training Club, and Fitnet allow consumers to use their smartphones to set their physical regimen and monitor their fitness goals. (Fitnet even uses a smartphone&rsquo;s camera to evaluate whether users are exercising the right way.) A 2014 report released by ACT: The App Association, an industry group for application makers, shows that the number of health and medical apps doubled between 2012 and 2014, and analysts are expecting revenues to reach $26 billion by 2017.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;It&rsquo;s one of those odd confluences in that everyone is interested in the same thing, which is improved patient outcomes,&rdquo; says Morgan Reed, executive director of ACT. &ldquo;What we&rsquo;re really trying to do is have healthier and more able people to be in charge of their own lives and be able to connect to a doctor when they want.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Connecting to doctors presents another series of opportunities and hurdles. Nearly 100 million wearable remote patient monitoring (RPM) devices &ndash; such as pulse oximeters, blood pressure cuffs, ECG monitors, and continuous glucose monitoring tools &ndash; are expected to be produced over the next four years, according to ABI Research, which follows global connectivity and emerging tech trends. Already, Apple, Google, and Samsung have signaled that they plan to produce RPM devices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>RPM devices, most often recommended by physicians and covered under HIPAA, are transitioning some health care activities away from the doctor&rsquo;s office into people&rsquo;s homes. By collecting data from a variety of devices and applications, and sharing it securely over the Internet, patients and physicians can be more closely connected in designing treatments, experts say. They also can provide even broader community benefits.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>One such device is Propeller Health&rsquo;s inhaler, which has built-in sensors, connects through Bluetooth to smartphones, and lets individuals respond to asthma attacks while also tracking where those attacks occur. Working with Propeller Health, the city of Louisville, Kentucky, is moving beyond the individual to the community to find asthma hotspots. Launched back in 2012, Louisville deployed a network of air sensors, along with giving away 500 inhalers, to map out areas that coincided with individual asthma attacks. The data was used to monitor air pollution and then devise treatment plans for local asthma sufferers.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The whiz-bang qualities of these devices are many, but they still suffer the fair-weather nature of consumers. Much like other once-popular tech gadgets, 3D glasses and PDAs among them, fitness trackers are plagued by the same problems as other smart devices: the short attention span of consumers. The NPD Group reports that 40 percent of activity-tracker owners stop using the devices within six months of purchasing them. That may account for forecasts that smartwatch sales could eventually overtake fitness tracker sales, as it is easier to remain loyal to a watch than to a monitor, the sole purpose of which is to remind consumers to keep their New Year&rsquo;s resolutions.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>The Internet of Things</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Fitness-tracking devices live in a much larger world of technology than health care, one that technologists have described as The Internet of Things (IoT). The IoT is a place where devices are linked and communicate with each other, an amalgam of sensors, programs, and connectivity. It is a universe where physical objects, from coffee pots to furnaces to automobiles, come to life at their owners&rsquo; bidding. The FTC estimates that some 25 billion connected objects and devices will be online in 2015.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Last January, FTC Chair Edith Ramirez expressed concerns about the privacy risks posed by the IoT, and she encouraged the tech industry to address those concerns or risk losing the confidence of consumers and the full adoption of IoT&rsquo;s promise. &ldquo;IoT has the potential to provide enormous benefits for consumers, but it also has significant privacy and security implications,&rdquo; warned Ramirez in her remarks at the 2015 Consumer Electronics Show, which has become an annual pilgrimage for tech geeks.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Connected devices that provide increased convenience and improve health services are also collecting, transmitting, storing, and often sharing vast amounts of consumer data, some of it highly personal, thereby creating a number of privacy risks,&rdquo; Ramirez added.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Attorneys believe that the three primary privacy challenges for the IoT, which includes health tracking devices, are the ubiquitous data collection that exposes a deep well of personal information; the potential for unexpected uses of consumer data by everyone, from employers to insurance companies, and the adverse consequences that could arise from those uses; and heightened security risks from hackers who may be tempted to commit larceny by the sheer volume of data.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;It&rsquo;s inevitable that we move to an Internet of Things approach,&rdquo; says Elliot Golding, counsel at Crowell & Moring LLP. &ldquo;It&rsquo;s hard to see how a washer talking to a refrigerator becomes an application that excites us, but there is a place where integrated and automated devices will improve the quality of life. But when you have all these devices talking to each other, the least secure device becomes the security level for all your devices.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Given that reality, FTC&rsquo;s Ramirez encourages companies to &ldquo;bake&rdquo; privacy into their devices or applications from the start. The strategy would be to push companies to build devices with privacy elements such as additional sets of passwords and encryption; to reduce the amount of data that devices collect and store; to make data as anonymous as possible; and to increase company transparency with additional consumer notices on devices &ndash; particularly if companies plan to share the data with third parties &ndash; and the ability to consent or not to data collection.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;In my mind, the question is not whether consumers should be given a say over unexpected uses of their data; rather, the question is how to provide simplified notice and choice,&rdquo; Ramirez said.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>Privacy of What?</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Observers say that what constitutes health data these days changes as quickly as the technology that creates it, which makes it hard to figure out what to do with that data and whether it needs to be protected. After all, the number of steps a person takes daily isn&rsquo;t the same data as one&rsquo;s white blood cell count, or is it?</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The answer to that question will be an important factor in deciding where to draw the line on privacy with newly generated information from fitness trackers, mobile apps, and smartwatches. It&rsquo;s a question government regulators are already trying to answer. Industry is also wrestling with its desire to avoid tough privacy regulations while touting the health benefits of their applications.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Most people can agree that information collected about patients by health care providers &ndash; doctors, hospitals, or health clinics, to name a few &ndash; to guide medical treatment decisions and care qualifies as health data. And that information is and should be protected under HIPAA and HITECH, the Health Information Technology for Economic and Clinical Health Act, which was enacted to promote the adoption and use of health-information technologies. But can consumers really expect privacy when their tracker sends off their GPS coordinates at the same time as it shares their steps in the cloud?</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The jury&rsquo;s out on whether a person&rsquo;s stair or step count could be included under HIPAA or state regulations governing health privacy or security breaches. Part of the problem for government and industry has been balancing the benefits of these gadgets with the myriad of ways user information is being collected and shared with third parties, such as advertising firms and app developers.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;In most cases, HIPAA is not going to apply to the devices or the information,&rdquo; Crowell&rsquo;s Golding says. &ldquo;What rules are going to govern how we handle very sensitive information is an issue that we&rsquo;ll need to carefully think about. How do you protect privacy and security in a smart way, both at the outset of creating a device and on an ongoing basis?&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Because privacy and security policies tend to be reactive, their use will likely depend on the evolution of how the public defines health information over the next few years. An individual&rsquo;s heart rate or blood glucose levels certainly seem to qualify as health data, but are they exempt from health privacy regulations because people create that data on their smartphones? It is a muddle.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;There&rsquo;s a huge debate right now about what to do with all this health care information that&rsquo;s being gathered outside of the existing HIPAA regulatory structure,&rdquo; says Kirk Nahra, a partner at Wiley Rein LLP. &ldquo;There&rsquo;s an increasing consensus that we do something and no consensus on what we do.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Information we would normally think of as health information is getting collected and analyzed outside the normal hospital and doctor&rsquo;s office settings,&rdquo; Nahra adds. &ldquo;It doesn&rsquo;t necessarily mean the companies in this business are doing bad things with the data, but they could.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>At the moment, however, the majority of consumers seems largely disconnected from and unfazed by health privacy concerns. No horrendous breach of consumer-generated health data has captured the public&rsquo;s attention. In fact, consumers are more likely to marvel at the cool devices or the space-age apps than be creeped out by the thought of some unseen data broker collecting their information and selling it.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Legal experts say the disconnect reflects a common pattern in public discussions about privacy over the last few decades, and especially during the Internet era. It is always an evolving process as society comes to better understand what are reasonable expectations of privacy for consumers, and how those match with the public&rsquo;s interest in accessing these devices.</span></span></span></span></span></span></span></span></span></p><p>"<span><span><span><span><span><span><span><span><span>I think people really do care about privacy, but they don&rsquo;t really know what to do about it,&rdquo; says De Mooy of the Center for Democracy &Technology. &ldquo;The data sharing that&rsquo;s happening isn&rsquo;t visible to them. There&rsquo;s a lot of backend to these technologies that people don&rsquo;t know about. Companies need to be educated on how to be transparent, and people need to be educated on who they can and should trust.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Expectations of privacy tend to evolve over time, and they are definitely being transformed with these new technologies, likely faster than the public knows. There are innumerable societal factors at play here because the devices serve multiple roles for many different people, and their expectations about the applications are countless.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Partly there is a generational divide, where Millennials may feel perfectly comfortable sharing health data while the stodgy Baby Boomers fear the specter of Big Brother over their shoulder. There&rsquo;s also the reasoning of some that people who don&rsquo;t have anything to hide can ignore the potential of privacy breaches. After all, they&rsquo;re healthy, active, and trim, so what would it matter if an insurance company or their employer acquired their fitness records?</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Partly the situation may be the result of ignorance. It is unclear whether people understand how their data is used and how it moves between fitness trackers to the Internet and beyond. For example, few consumers know that hidden deep within most privacy policies is a clause that allows companies to turn over data to the government for valid law enforcement queries and other legal requests.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Most consumers also feel somewhat protected by the privacy policy check-off boxes on registration pages, mobile apps, or desktop interfaces, even though those sign-offs are so breezily automatic these days it would be nearly impossible to find anyone who has scrolled down and read the entire policy before checking the agreement box.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Attorneys say privacy policies are useless in the face of nefarious hackers, which is why there is so much emphasis on building stronger hardware and software security functions into devices and the systems that govern them. Privacy policies only come into force when dealing with a company&rsquo;s choices about collecting and sharing consumer data.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The marketplace for data is a fierce one, and data brokers buy information as quickly as it is created. They in turn sell it to any number of companies, from insurers looking to determine premiums or sell policies to employers doing background checks on new hires. Consumer expectations of privacy cannot keep pace with this kind of technology, experts say, and that could pose some real problems for health and fitness data generated by and about them.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;This is an area that is simultaneously extremely exciting and kind of scary,&rdquo; Golding says. &ldquo;In my view, wearables have the potential to be a truly disruptive technology that can help society and help people. Yet, there&rsquo;s so much danger with them in dealing with the potentially sensitive information they create.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>Corporate Best Practices</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Industry officials acknowledge the dangers of unrestricted disclosures of fitness and well-being information, but they fear that an aggressive approach by government to limit the collection and sharing of data could prove a wet blanket on innovation. It could thwart industry and consumers from realizing the benefits of the IoT, especially the potential of health-monitoring devices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;One reason that we&rsquo;re where we are with these new technologies is they&rsquo;ve grown out of an open environment,&rdquo; says Anna L. Spencer, a partner at Sidley Austin LLP. &ldquo;I&rsquo;m very hesitant to say and impose requirements on a technology that is nascent and that could really transform health care, which desperately needs transforming.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>While the FTC&rsquo;s Ramirez appreciates the importance of keeping the door open for innovation to advance technology and the U.S. economy, she seems particularly unwilling to give the industry a fully open field in which to operate. &ldquo;I question the notion that we must put sensitive consumer data at risk on the off chance a company might someday discover a valuable use for the information,&rdquo; she noted.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Industry has responded in the past year by pressing for a corporate best-practices model in addressing privacy concerns, hoping to avoid the heavy hand of federal and state regulation. Corporations already have adopted policies that better communicate privacy information to consumers, that focus on more thoughtful approaches to the security architecture and data discipline, and that vow not to sell or share data with third parties. And app makers have begun to offer free and paid versions of apps where consumers can get more privacy restrictions if they want to pay for them.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The best-practices approach received its heartiest endorsement in September 2014, when Apple Chief Executive Officer Tim Cook wrote an open letter to consumers that effectively set the standard for corporate transparency on privacy, data collection, and data sharing. Cook&rsquo;s letter &ndash; and Apple&rsquo;s accompanying consumer privacy Web site &ndash; was a response to the hacking of iCloud accounts and complaints that Apple hadn&rsquo;t done enough to protect customer data.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Our business model is very straightforward: We sell great products,&rdquo; Cook wrote. &ldquo;We don&rsquo;t build a profile based on your email content or web browsing habits to sell to advertisers. We don&rsquo;t &lsquo;monetize&rsquo; the information you store on your iPhone or in iCloud. And we don&rsquo;t read your email or your messages to get information to market to you.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Legal experts believe that corporations such as Apple, Microsoft, and dozens of other top-line technology companies are defining best practices with their very public privacy policies, and they believe it is the best way forward to guard consumer privacy while balancing the desire to pursue innovation.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;The leaders in the industry are going to look to the importance of their brand,&rdquo; Kelley Drye&rsquo;s Wolff says. &ldquo;Consumers have impressions of brands, and they ask themselves whether they can trust a company. They recognize there are always going to be risks, but I think there is value in the consumer mind and the company mind in terms of offering a good product with robust consumer protections.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Adopting a regulatory scheme that relies on industry best practices also has the advantage of timeliness. &ldquo;Nobody wants technology at the speed of government,&rdquo; ACT&rsquo;s Reed says. &ldquo;That is especially true here in the personal health information space. I think that industry best practices are going to be the first step for highlighting and clarifying for consumers what&rsquo;s going on.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>While the FTC has provided some guidance for companies, outside groups are also stepping in to offer up sample privacy foundations. In August 2015, the Online Trust Alliance (OTA), a nonprofit think tank, issued a privacy and security framework that companies could adopt for IoT devices, although it initially focused on home automation and health-wearable technologies. The principles underlying the recommendations are transparency and data security, which are based on the Fair Information Practice Principles (FIPPs), the FTC&rsquo;s widely accepted guidelines for privacy-focused data collection practices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Security and privacy by design must be a priority from the onset of product development and be addressed holistically,&rdquo; the OTA noted in releasing the framework, which covers everything from consumer access to privacy policies to breach response and consumer notification plans. &ldquo;It must be a forethought versus an afterthought, focusing on end-to-end security and privacy.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>A Role for Government</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The push for a best-practices approach to privacy protections has won wide support within the industry, and even some privacy advocates say there are good reasons to give companies a chance to solve the most egregious problems with tighter internal controls over information. There is a general fear that an aggressive regulatory scheme is the last thing these technologies need to grow.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Yet, technological innovation is always going to force a conversation about what is reasonable expectation of privacy for consumers, especially in a fast-changing technological age, and that may be a question that is best resolved by government, some say. While personal-generated health information may not rise to the level of HIPAA, it is closely watched by government agencies, from the FTC to the U.S. Food and Drug Administration (FDA) to the U.S. Department of Health and Human Services (HHS) and its agencies to state regulatory bodies.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>For some attorneys, the fuss about adding new privacy restrictions on device usage and information sharing is little more than window dressing. They believe there are enough statutes and regulations on the books today to successfully enforce privacy rights and protections in the United States.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;It&rsquo;s not that there is a complete absence of law,&rdquo; says Sidley&rsquo;s Spencer. &ldquo;Just because HIPAA doesn&rsquo;t apply, that doesn&rsquo;t mean it is a free-for-all. It&rsquo;s not. There are restrictions such as enforcement of the FTC Act, which prohibits unfair and deceptive trade practices. The FTC has, through its enforcement, focused on privacy and ensuring companies comply with their privacy notices. There are a myriad of unfair and deceptive practice statutes that state attorneys general use all the time to fight businesses engaging in practices that harm consumers.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Still, for some, the best solution is a government one. &ldquo;If companies of fitness devices have the ability to sell personal health data to insurers, employers, and others, users should be alerted and given the opportunity to decline. The FTC should require fitness devices and app companies to adopt new privacy measures that will help conceal the identity of individuals and develop policies to protect consumer information in the event of a security breach,&rdquo; said U.S. Senator Charles Schumer (D&ndash;N.Y.) in a written statement in August 2014.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Many observers believe the FTC does a pretty good job of using the tools at hand to monitor and enforce consumer privacy protections guarded by the FTC Act. It regularly brings legal actions against companies that violate privacy rights or fail to maintain security. And it frequently applies section 5 of the Act to ensure companies are not employing unfair and deceptive practices in their dealings. Even friends of the FTC say that its approach to regulation could be strengthened, as could its penalties, to send a more forceful message to tech companies about the importance of privacy.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>In January 2015 the FDA issued a draft guidance paper, titled &ldquo;General Wellness: Policy for Low Risk Devices,&rdquo; noting that it doesn&rsquo;t plan to regulate &ldquo;low risk general wellness products&rdquo; that are being described by retailers and manufacturers as &ldquo;medical devices&rdquo; under the Federal Food, Drug, and Cosmetic Act. Many expect the FDA, however, to keep an eye on the growth of these devices and their health claims.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Some have suggested that the privacy of new data being created could be addressed by expanding HIPAA to cover consumer-generated health and fitness information. It would have the benefit of not creating an entirely new statute, and it would stake out clearly the parameters of what &ldquo;health data&rdquo; means today.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;When we wrote the HIPAA rules, we defined the health care industry by law in a certain way that most accurately reflected it at the time. It has become less accurate over time,&rdquo; Wiley Rein&rsquo;s Nahra says. &ldquo;You could change HIPAA to have it cover all health information regardless of where it&rsquo;s coming from. Right now, it has to come from the right place for it to be health information and protected.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>HHS has already proven that it is open to changing what constitutes a covered entity under HIPAA. In January 2013 it issued new rules under HIPAA and HITECH that included &ldquo;business associates,&rdquo; or contractors or subcontractors for covered companies, to capture the increasing use of third-party cloud companies for storage of protected medical information. The same could be done for consumer-generated devices and their corporate developers.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Regulating the devices and applications more broadly would likely prove complex, however. Small changes in functionalities or how the product is offered can shift the regulatory location from the FTC to the FDA, and that can add to consumer confusion as to expectations of privacy. It can also be difficult for innovators who are trying to invent new devices but aren&rsquo;t sure where to look for guidance on how best to protect consumers in the process.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;I think the FTC will have to decide for itself what it feels is the best way to convey to the commercial community what its regulatory expectations are and a way to communicate to consumers what their reasonable expectations of privacy can be,&rdquo; McDermott&rsquo;s Geetter says.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Meanwhile, there has been interest at the state level to adopt new regulations for health-tracking devices. Already, 47 states have separate data breach notification statutes, and California, Florida, and Texas have expanded their laws recently to widen the scope of information that qualifies as personal, such as medical history, treatment, or condition. In Texas, the Texas Medical Records Privacy Act covers any person who comes into possession of personal health data, and it bans the sale of that information without authorization.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Not surprisingly, industry leaders are loathe to face a medley of new state regulations governing the privacy of wearable devices and imposing new limits on how consumer-generated information can be shared. &ldquo;The problem is when you end up with a patchwork of state regulation . . . you end up with harm to smaller, innovative companies that are trying to do something innovative in the market,&rdquo; ACT&rsquo;s Reed says.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>The FTC dipped back into the public debate at its November 2015 workshop examining the privacy issues that arise with advertising and marketing, and the tracking of consumer activities across different devices. Some of the trouble stems from consumers who end up interacting with various platforms, applications, and software when using their smartphones and wearable devices.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;More consumers are connecting with the Internet in different ways, and industry has responded by coming up with additional tools to track their behavior,&rdquo; said Jessica Rich, director of the FTC&rsquo;s Bureau of Consumer Protection, in a statement. &ldquo;With the advent of new tracking methods, though, it&rsquo;s important to ensure that consumers&rsquo; privacy remains protected as businesses seek to target them across multiple devices.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><b><span><span><span><span>Privacy as Collateral Damage</span></span></span></span></b></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Talk to most attorneys about the IoT or wearable devices, and there is a sense of inevitability that these remarkable technological devices will eventually fail in protecting consumer privacy and all this newly generated information. This brave, new world of technology is unforgiving when it comes to data because data is its currency.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;A few years ago, users of Internet services began to realize that when an online service is free, you&rsquo;re not the customer,&rdquo; wrote Cook in his famous letter last year. &ldquo;You&rsquo;re the product.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Certainly, attorneys, privacy advocates, and government officials believe that best practices can go a long way toward protecting data. They all are reluctant to engage the full force of government on the problem because it will always come at a cost. Most likely the price will be paid in innovation, as privacy requirements limit the choices of designers and developers looking to create that next generation of application or device.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Privacy protections are about choices; as you add privacy protections you, by definition, restrict how data is used and disclosed,&rdquo; Geetter says. &ldquo;Finding the right balance between what we want to do, who we want to share the data with, and how to protect it is the exciting challenge.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;We don&rsquo;t know what we&rsquo;re going to invent tomorrow,&rdquo; Geetter adds. &ldquo;We know we&rsquo;re going to invent something. The challenge for our privacy regulation landscape is to try to accept that we need a model that can spring into action as innovation occurs. We cannot afford to develop a privacy and security framework that works only for today and is out of date tomorrow.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>All this effort by tech companies and government is designed to protect consumers, in part, from themselves. Everyone loves these new technological devices and the free tools found in applications. The public has grown accustomed to tools like Gmail and Yahoo arriving on their virtual doorstep for free. In fact, some would argue that it has made individual consumers particularly lazy in being advocates for their own privacy, and it has made it very easy to discard those hard-won protections.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>Last year a Canadian court became one of the first courts worldwide to accept data from a Fitbit as evidence in a personal injury case. The plaintiff was injured five years ago, and once the case goes to trial, her lawyer plans to analyze the data from the Fitbit to prove her daily activity levels were below those of someone her age and profession. She was a personal trainer.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>While it is certain fitness trackers will end up as part of litigation below the border, it is not clear whether they will help or hurt a case. A lack of standardization, users&rsquo; failure to wear, charge, or sync their devices, and the unreliability of logged activity, which could be generated with a wave of the hand, make wearable devices unreliable witnesses.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>What&rsquo;s important here, observers say, is not the reliability of the device to be used in court as much as consumers&rsquo; decisions to give up their privacy protections for convenience. Many individuals are more than willing to open up their lives for expediency in court, or in their workplace when offered bonuses or discounts from employers for wearing health trackers, or with life insurance companies that reduce premiums for customers who wear smart watches.</span></span></span></span></span></span></span></span></span></p><p><span><span><span><span><span><span><span><span><span>&ldquo;Our longing for convenience means we&rsquo;ve created a matrix that can and will be used against us,&rdquo; wrote software analyst R. &ldquo;Ray&rdquo; Wang in his <i>Harvard Business Review</i> article, &ldquo;Beware Trading Privacy for Convenience,&rdquo; in June 2013. &ldquo;Most of us just don&rsquo;t know it yet.&rdquo;</span></span></span></span></span></span></span></span></span></p><p><span><span><span><i><span><span><span><span>This article appeared in the December 2015 issue of</span></span></span></span></i> <span><span><span><span>Washington Lawyer<i>, the official publication of the District of Columbia Bar, and is reprinted with permission.</i></span></span></span></span></span></span></span></p>]]></description><category><![CDATA[LPMProtect,PracticeManagement,Archive]]></category>
            <pubDate>Tue, 19 Apr 2016 11:53:00 -0500</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2361/500_journallogo1.png?10000" length="0" type="image/png" />
                <pp:image>https://content.presspage.com/uploads/2361/500_journallogo1.png?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2361/journallogo1.png?10000</pp:imageOriginal><pp:imageTitle><![CDATA[Journal Logo(1)]]></pp:imageTitle></item></channel>
                    </rss>