A Client Confidentiality Checklist for Professionals — Herarx Blog

A Client Confidentiality Checklist for Professionals

Confidentiality fails in ordinary places: a wrong autocomplete, an open screen, a shared folder. A checklist covering people, devices, email, storage, sharing and disposal.

July 08, 2025
A Client Confidentiality Checklist for Professionals
Back to blog

Most confidentiality breaches in small practices are not hacks. They are an email sent to the wrong "Sarah" because of autocomplete, a file left in a folder the whole office can see, a phone call taken in a café. The checklist below targets those ordinary failures. Work through it once as an audit, then use it when onboarding staff.

People

  • Everyone who handles client material has signed a confidentiality undertaking, including contractors, temps and outsourced bookkeepers.
  • New staff are told, in writing, what counts as confidential. The answer is usually "everything about a client, including that they are a client".
  • Conflict checks are run before taking on a new matter, not after. See conflict-of-interest checks for small firms.
  • Access to a matter is limited to the people working on it, and removed when they stop.

Conversations

  • Client matters are not discussed in public places, lifts or shared transport.
  • Before discussing a matter on the phone, the caller's identity is confirmed, especially when they ask for information rather than give it.
  • Voicemails left for clients say who you are and ask them to call back, and nothing else.

Email

  • Recipients are checked before sending; autocomplete is the single most common cause of misdirected email.
  • Sensitive documents go by secure link with an expiry rather than as open attachments where possible.
  • A send delay of a minute or so is switched on, if your mail client offers one, so mistakes can be caught.
  • Client correspondence is filed to the matter, not left scattered across personal inboxes.

Devices and screens

  • Screens lock automatically after a short idle period.
  • Laptops and phones are encrypted and protected by a PIN or password.
  • Two-factor authentication is on for every system holding client data.
  • Personal devices used for work meet the same rules, or are not used.
  • Documents are not printed to shared printers and left in the tray.

Storage

  • Client files live in one known system, not across desktops, USB drives and personal cloud accounts.
  • Storage is encrypted at rest and data travels over encrypted connections. Encryption at rest vs in transit explains the difference.
  • Folders or records are organised per client or matter, so access can be granted per matter.
  • Paper files are locked away at the end of each day.

Sharing with others

  • Before sharing, confirm you have the client's authority to share with that recipient.
  • Share the specific documents needed, not the whole file.
  • Links expire. Access for experts, counsel or other advisers is removed when their part is done.
  • A record is kept of what was shared, with whom and when.

Disposal

  • Files are kept for a defined period after the matter closes, then disposed of on schedule.
  • Paper is shredded or destroyed by a contractor who provides a certificate.
  • Old devices are wiped or destroyed before disposal or resale.

When something goes wrong

  • Staff know that a mistake must be reported immediately, and that reporting it is not the career-ending event; hiding it is.
  • There is a written first-response plan: contain, assess, notify where required, record.
  • Each incident is logged, including near misses, and reviewed for a fix.

Check it regularly

Confidentiality drifts. People change roles, folders get shared "just this once", links pile up. Re-run the access part of this list at least quarterly; the method is in how to audit who has access to your files.