Back to blog
Email
Most confidentiality breaches in small practices are not hacks. They are an email sent to the wrong "Sarah" because of autocomplete, a file left in a folder the whole office can see, a phone call taken in a café. The checklist below targets those ordinary failures. Work through it once as an audit, then use it when onboarding staff.
People
- Everyone who handles client material has signed a confidentiality undertaking, including contractors, temps and outsourced bookkeepers.
- New staff are told, in writing, what counts as confidential. The answer is usually "everything about a client, including that they are a client".
- Conflict checks are run before taking on a new matter, not after. See conflict-of-interest checks for small firms.
- Access to a matter is limited to the people working on it, and removed when they stop.
Conversations
- Client matters are not discussed in public places, lifts or shared transport.
- Before discussing a matter on the phone, the caller's identity is confirmed, especially when they ask for information rather than give it.
- Voicemails left for clients say who you are and ask them to call back, and nothing else.
- Recipients are checked before sending; autocomplete is the single most common cause of misdirected email.
- Sensitive documents go by secure link with an expiry rather than as open attachments where possible.
- A send delay of a minute or so is switched on, if your mail client offers one, so mistakes can be caught.
- Client correspondence is filed to the matter, not left scattered across personal inboxes.
Devices and screens
- Screens lock automatically after a short idle period.
- Laptops and phones are encrypted and protected by a PIN or password.
- Two-factor authentication is on for every system holding client data.
- Personal devices used for work meet the same rules, or are not used.
- Documents are not printed to shared printers and left in the tray.
Storage
- Client files live in one known system, not across desktops, USB drives and personal cloud accounts.
- Storage is encrypted at rest and data travels over encrypted connections. Encryption at rest vs in transit explains the difference.
- Folders or records are organised per client or matter, so access can be granted per matter.
- Paper files are locked away at the end of each day.
Sharing with others
- Before sharing, confirm you have the client's authority to share with that recipient.
- Share the specific documents needed, not the whole file.
- Links expire. Access for experts, counsel or other advisers is removed when their part is done.
- A record is kept of what was shared, with whom and when.
Disposal
- Files are kept for a defined period after the matter closes, then disposed of on schedule.
- Paper is shredded or destroyed by a contractor who provides a certificate.
- Old devices are wiped or destroyed before disposal or resale.
When something goes wrong
- Staff know that a mistake must be reported immediately, and that reporting it is not the career-ending event; hiding it is.
- There is a written first-response plan: contain, assess, notify where required, record.
- Each incident is logged, including near misses, and reviewed for a fix.
Check it regularly
Confidentiality drifts. People change roles, folders get shared "just this once", links pile up. Re-run the access part of this list at least quarterly; the method is in how to audit who has access to your files.