Home network security for lawyers: an ABA Opinion 498 checklist

A lawyer reviewing client files on his laptop at a dining table, with the family TV, tablet and toys in the living room behind him.

Updated October 8, 2026.

The short answer

ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to keep client information safe, and ABA Formal Opinion 498 says lawyers working remotely should make sure their routers are secure and consider a VPN. At home, that means locking down the router, giving client work its own network and silencing smart speakers during client calls.

Key takeaways
  • The duty is "reasonable efforts," and it follows you into the home office.
  • Opinion 498 names routers, VPNs and smart speakers specifically.
  • Client work shouldn't share Wi-Fi with the kids' games and gadgets.
  • After a breach, Opinion 483 says tell affected current clients.

Do ethics rules cover a lawyer's home Wi-Fi?

Yes. ABA Model Rule 1.6(c) says a lawyer "shall make reasonable efforts" to prevent unauthorized access to client information.1 The rule doesn't care where you work. A laptop on the dining table carries the same duty as one in a downtown office.

What counts as reasonable depends on the facts. Comment 18 to the rule weighs how sensitive the information is, how likely a leak is without more safeguards, and what those safeguards cost and disrupt.1 A cheap, easy step that blocks a real risk is hard to skip.

Competence matters too. 40 states, plus D.C. and Puerto Rico, have adopted the comment to Model Rule 1.1 that asks lawyers to understand the risks of the technology they use.2

29% of lawyers said their firm had experienced a security breach. Another 19% didn't know. ABA 2023 Cybersecurity TechReport3

What do ABA Opinions 477R, 483 and 498 say?

Three ABA formal opinions shape how lawyers handle technology. Here's what each means for a home office:

Opinion Topic For your home office
477R (2017) Sending client information online Fine over the internet with reasonable efforts. Highly sensitive matters may need stronger measures, like encryption.4
483 (2018) Data breaches Monitor for breaches, act fast, and tell current clients when their information is likely involved.5
498 (2021) Virtual practice Make sure routers are secure, consider a VPN, use strong passwords and updates, and silence listening devices.6

Opinion 498 is the most direct. It says that when connecting over Wi-Fi, "lawyers should ensure that the routers are secure."6 Its sample device policy adds that client information shouldn't be reachable by family members or others.

These are ABA model opinions, not binding law everywhere. Your state bar may have its own rules or opinions, so check them too.

A home network checklist for lawyers

Work through this list once, then recheck it every few months. Most steps come straight from Opinion 498 or federal home network guidance.

  1. Change the router's admin password. Default passwords are easy to find online. Use a long, unique one.6, 7
  2. Use strong Wi-Fi encryption. Choose WPA3 Personal or WPA2 Personal in your router settings.7
  3. Update the router. Turn on automatic updates, or check the maker's site often.7, 8
  4. Give client work its own network. Your work laptop, desktop and printer shouldn't share Wi-Fi with game consoles, tablets and smart gadgets.8
  5. Put visitors on a guest network. Clients, contractors and friends never need your work network.7
  6. Turn off features you don't use, like remote management, WPS and UPnP.7
  7. Turn on two-step login for email, practice software and cloud storage, and use a password manager.6
  8. Keep devices updated and run antivirus software on every device that holds client files.6
  9. Silence smart speakers during client calls and meetings.6
  10. Use a VPN on public Wi-Fi. If your firm provides one, follow its rules.6, 8
  11. Write it down. A one-page note of what you did, and when, helps show your efforts were reasonable.

For the full home office setup, see our guide to securing your home office Wi-Fi. If the house is full of connected gadgets, read why smart devices belong on a separate network.

Should lawyers turn off Alexa during client calls?

Yes, unless the device is helping your practice. Opinion 498 says lawyers should disable the listening feature of smart speakers and virtual assistants while discussing client matters.6 Otherwise you expose client information to third parties and raise the risk of hacking.

The simplest fix is the mute button. Better still, keep smart speakers out of the room where you take client calls, and on a different network from your work devices.

Do lawyers need a VPN at home?

Opinion 498 says lawyers "should consider" a VPN, not that they must use one.6 A VPN encrypts traffic between your device and the VPN server. That helps most on public Wi-Fi in hotels, airports and courthouses.

A VPN doesn't fix a weak router password or a work laptop sitting next to a vulnerable gadget. Lock down the home network first, then add a VPN. If your firm gives you one, use it, and ask before adding another.

What if your home network is breached?

Opinion 483 sets out the steps: stop the breach, find out what happened, restore systems, and tell current clients whose information was, or likely was, exposed.5 State breach laws can add their own notice rules.

19% of solo lawyers have an incident response plan. ABA 2023 Cybersecurity TechReport3

A plan doesn't need to be long. Write down who you'd call (your IT help, your malpractice carrier, your bar's ethics hotline), where your client list lives, and how you'd reach clients if email went down.

Where Rio fits. Rio is a router that walls off your practice in its own SecureRoom, holds every new device for your OK and puts visitors on guest Wi-Fi. It handles the network part of reasonable efforts. It isn't legal advice and doesn't make any firm compliant with an ethics rule. See the Rio setup for law firms.

Your client files shouldn't share Wi-Fi with a game console.

Rio walls off your practice in a room of its own, holds every new device for your OK and keeps visitors on guest Wi-Fi.

See a law office setup

Frequently asked questions

Are lawyers required to use a VPN?

Not under the ABA model rules. Opinion 498 says lawyers should consider a VPN when working remotely, as part of reasonable efforts under Rule 1.6(c). Whether you need one depends on where you work and how sensitive your matters are. Some firms and clients require one, and some state bars add guidance.

Can lawyers use public Wi-Fi for client work?

It's risky without protection. On public Wi-Fi in a hotel, airport or courthouse, use a VPN or your phone's hotspot, and avoid opening sensitive files where others can see your screen. Opinion 498 asks lawyers to secure every connection they use.

Does the ABA require encrypted email?

Not for routine matters. Opinion 477R says unencrypted email is generally acceptable for normal communication when you've made reasonable efforts to protect it. For highly sensitive information, or when a client or the law requires it, stronger measures like encryption may be necessary.

Do lawyers have to tell clients about a data breach?

Under ABA Opinion 483, yes for current clients: if a breach involves, or likely involves, their confidential information, you must tell them. State data breach laws may require more, including notice to former clients or regulators. Check your state's rules and talk to your malpractice carrier.

Sources

  1. American Bar Association, Model Rule 1.6, Confidentiality of Information, with comments. americanbar.org
  2. LawSites, Tech Competence: states that have adopted the duty, 2025. lawnext.com
  3. American Bar Association, 2023 Cybersecurity TechReport. americanbar.org
  4. ABA Formal Opinion 477R, Securing Communication of Protected Client Information, May 2017. americanbar.org (PDF)
  5. ABA Formal Opinion 483, Lawyers' Obligations After an Electronic Data Breach or Cyberattack, October 2018. americanbar.org (PDF)
  6. ABA Formal Opinion 498, Virtual Practice, March 10, 2021. americanbar.org (PDF)
  7. Federal Trade Commission, How To Secure Your Home Wi-Fi Network. ftc.gov
  8. National Security Agency, Best Practices for Securing Your Home Network, February 2023. defense.gov (PDF)
Share: Twitter Facebook LinkedIn Email