This material is general public information for educational purposes only. It should not be used as legal, financial, or tax advice, and no attorney-client relationship is created by reading it. Federal, state, and local rules may vary and may change over time. A qualified professional can review specific circumstances.
Key Facts
- National overview: ABA Formal Opinion 11-459 says a lawyer ordinarily must warn a client about the risk of third-party access when sending or receiving substantive communications by email or other electronic means.
- National overview: ABA Formal Opinion 11-459 identifies an ethical obligation at the very least when the lawyer knows or reasonably should know the client will use a business device or system with significant risk that an employer or another third party will read the communications.
- National overview: ABA Model Rule 1.6 generally prohibits revealing information relating to the representation unless the client gives informed consent or another permitted authorization or exception applies.
- National overview: ABA Model Rule 1.6 requires reasonable efforts to prevent inadvertent or unauthorized disclosure or unauthorized access of information relating to the representation.
- National overview: The ABA Model Rule 1.6 comment states that when transmitting a communication that includes representation information, a lawyer must take reasonable precautions to prevent it reaching unintended recipients.
- State level: New Hampshire Rule 1.6 requires reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation.
- State level: New Hampshire’s Rule 1.6 comment states the lawyer is responsible for reasonably ensuring adequate protection of client confidences in data held or stored by others, including cloud storage.
- Federal level: HIPAA’s Security Rule at 45 CFR 164.306 requires covered entities and business associates to protect electronic protected health information against reasonably anticipated threats or hazards.
Email communication can raise confidentiality questions when workplace systems allow an employer or another third party to read messages, which is the risk framework ABA Formal Opinion 11-459 addresses; background on confidentiality and privilege concepts can also help readers understand why these topics get mixed up, see attorney-client privilege basics.
- What ABA Formal Opinion 11 459 targets in email confidentiality
- Model Rule 1.6 provides the confidentiality backbone
- The Rule 1.6 comment connects confidentiality to transmission risk
- Competence under Model Rule 1.1 links confidentiality to technology
- Employer access, subpoenas, and the staying power of email
- State ethics rules can address electronic confidentiality in different ways
- Federal security laws are separate HIPAA as a federal example
- Where the Formal Opinion sits in the larger ethics record
- Sources
ABA Formal Opinion 11-459 also points to email’s practical staying power: it explains that, unlike conversations and written communications, e-mail communications may be permanently available once they are created; broader context on technology and privacy can help connect that risk to modern workflows, see technology and privacy concerns.
What ABA Formal Opinion 11 459 targets in email confidentiality
ABA Formal Opinion 11-459 (dated August 4, 2011) addresses lawyers’ ethical duties when communicating electronically with a client. It explains that, when a lawyer sends or receives substantive communications via email or other electronic means, confidentiality concerns arise from the “risk of sending or receiving electronic communications…where there is a significant risk that a third party may gain access.”
Formal Opinion 11-459 also focuses on a workplace scenario: it describes that the obligation arises “at the very least” when the lawyer knows or reasonably should know the client is likely to send or receive substantive client-lawyer communications through a business device or system under circumstances with significant risk the communications will be read by the employer or another third party.
Model Rule 1.6 provides the confidentiality backbone
ABA Model Rule 1.6—Confidentiality of Information—frames confidentiality as a rule that regulates disclosure of “information relating to the representation of a client.” Under the rule text, a lawyer “shall not reveal” such information unless the client gives informed consent or a permitted authorization or exception applies.
ABA Model Rule 1.6 also contains a risk-reduction duty: it requires “reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to” information relating to the representation.
The Rule 1.6 comment connects confidentiality to transmission risk
Model Rule 1.6’s comment adds an expectation about how confidentiality is handled during transmission. It states that, “[w]hen transmitting a communication that includes information relating to the representation of a client,” the lawyer must take “reasonable precautions” to prevent the information from reaching “unintended recipients.”
Rule 1.6 comment language helps explain why ABA Formal Opinion 11-459 focuses on email and other electronic communications where unintended access can occur through third-party-controlled systems.
Competence under Model Rule 1.1 links confidentiality to technology
ABA Model Rule 1.1—Competence—sets a separate but related floor for legal ethics. The rule provides that a lawyer must provide competent representation, including knowledge and preparation reasonably necessary.
ABA Model Rule 1.1 and its comment connect competence to understanding the “benefits and risks associated with relevant technology.”
In the email context, that competence idea matters because the confidentiality risk can arise from system design and access controls rather than from the lawyer’s or client’s intent. The Model Rule comment reinforces the same general point: staying current on technology risks helps support appropriate handling of client information, including when communications travel through third-party systems.
Rule 1.1 comment supports that technology-and-risk connection directly.
Employer access, subpoenas, and the staying power of email
ABA Formal Opinion 11-459 explains why the workplace can create heightened confidentiality risks for client-lawyer communication. It describes that employers often reserve rights to access employee email correspondence through the employer’s email account.
The opinion also discusses indirect access: it states that “other third parties may be able to obtain access to an employee’s electronic communications by issuing a subpoena to the employer.”
Finally, the opinion highlights why email is different from some other forms of communication: it says that, “unlike conversations and written communications, e-mail communications may be permanently available once they are created.”
State ethics rules can address electronic confidentiality in different ways
ABA Formal Opinion 11-459 also warns that it does not replace jurisdiction-specific control. It states that the “laws, court rules, regulations, rules of professional conduct, and opinions promulgated in individual jurisdictions are controlling.”
That means state-specific ethics rules and state authorities can set the practical governing duties for lawyers, even if ABA model guidance is useful as a baseline conceptual framework.
New Hampshire offers an example of a state rule that explicitly addresses modern data-handling concerns. New Hampshire Rule 1.6 requires reasonable efforts to prevent “the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation.”
New Hampshire Rule 1.6 includes comment language stating that the lawyer is responsible for reasonably ensuring “adequate protection of client confidences” in data held or stored by others, including “cloud” storage.
Federal security laws are separate HIPAA as a federal example
Not every “confidentiality” or “security” duty for electronic information is the same kind of authority as lawyer professional responsibility rules. HIPAA’s Security Rule is an example of a federal regulation that imposes concrete safeguards, but it applies to particular covered entities and business associates.
45 CFR 164.306 requires covered entities and business associates to ensure confidentiality, integrity, and availability of electronic protected health information and to protect against “reasonably anticipated threats or hazards.”
A compact comparison helps keep the authorities straight:
| Topic | What authority focuses on | Who it regulates |
|---|---|---|
| ABA professional responsibility (Model Rules and Formal Opinion 11-459) | Confidentiality of information relating to the representation and reasonable precautions to prevent unintended recipient access | Lawyers under applicable jurisdiction rules of professional conduct |
| HIPAA Security Rule (45 CFR 164.306) | Security safeguards for electronic protected health information, including protection against reasonably anticipated threats or hazards | Covered entities and business associates |
HIPAA’s scope is tied to its regulated healthcare context, while lawyer confidentiality duties come from the professional responsibility framework applicable in the lawyer’s jurisdiction.
Where the Formal Opinion sits in the larger ethics record
Formal Opinion 11-459 is one item in the ABA’s published ethics opinions. The ABA maintains an archive that lists formal opinions by issue date.
ABA formal ethics opinions archive helps readers locate the opinion itself, but it does not change the opinion’s stated emphasis that jurisdiction-specific ethics rules and opinions control the governing professional responsibility framework.
In short, ABA Formal Opinion 11-459 uses the email context to illustrate confidentiality risk and reasonable precautions when third parties may gain access through workplace systems, employer access policies, subpoenas, or the permanent availability of stored messages, with the Model Rules providing the underlying confidentiality and competence structure.