Attorney ethical obligations for remote work don’t pause the moment a lawyer leaves the office — Florida Bar’s confidentiality and competence rules travel with every laptop, phone, and public Wi-Fi connection.
The flight is delayed two hours.
An attorney finds a seat near the gate, opens a laptop and connects to the airport’s free Wi-Fi.
There is a deposition summary to finish.
A privileged email thread to review.
A settlement demand to revise before tomorrow morning.
The Wi-Fi network is called “Airport_Free_WiFi.”
No password required.
That is convenient.
It is also exactly the kind of network security professionals warn people about, because anyone else on that same network, including someone with no legitimate business at the airport at all, may be able to see far more than they should.
The attorney is not being careless.
They are doing what thousands of professionals do every single day.
They are also, without necessarily realizing it, carrying their ethical obligations with them into an environment that was never designed to protect privileged information.
This is not a hypothetical concern reserved for large firms with sensitive government matters.
It applies to every attorney working outside the office, whether that means an airport, a hotel business center, a coffee shop or a family member’s home Wi-Fi network over a holiday weekend.
Ethical Duties Do Not Stay Behind at the Office
Attorneys often think about confidentiality obligations in terms of what happens inside the firm.
Locked file cabinets.
Access-controlled case management systems.
Staff training on client confidentiality.
Those protections matter enormously.
But the duty of confidentiality does not pause the moment an attorney leaves the building.
Florida Bar Rule 4-1.6 requires attorneys to maintain client confidentiality and to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.
That requirement travels.
It applies just as fully to a laptop open in an airport lounge as it does to a locked office door.
Working remotely does not create a exception to this duty.
It creates a different set of risks that the same duty still has to account for.
Technology Competence Is Now Part of Ethical Competence
Many attorneys still think of “competence” purely in terms of legal knowledge and skill.
That definition has expanded.
The comment to Florida Bar Rule 4-1.1, addressing competence, specifically states that a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
This means an attorney’s ethical competence now includes a baseline understanding of how the technology they use to practice law actually behaves, including where it introduces risk.
An attorney does not need to become an IT expert.
But an attorney who has never considered whether public Wi-Fi is safe for privileged communications, or whether a personal cloud storage account is an appropriate place for client documents, may be operating with an outdated understanding of what competence requires today.
What Actually Goes Wrong on Public Wi-Fi
Public wireless networks introduce several categories of real risk, not theoretical ones.
An open network with no password means data traveling across it may not be encrypted by the network itself, depending on which sites and services are being used.
A malicious actor on the same network can sometimes intercept unencrypted traffic, a technique often called a man-in-the-middle attack.
Rogue hotspots are another well-documented risk. An attacker can create a Wi-Fi network with a name deliberately similar to a legitimate one, such as “Airport-WiFi-Free” instead of “Airport_Free_WiFi,” hoping travelers will connect to the wrong one without noticing.
Once connected to an attacker-controlled network, all traffic passing through it can potentially be monitored.
CISA’s guidance on securing wireless networks and remote work specifically warns that public Wi-Fi networks should be treated as inherently untrusted, and recommends using a virtual private network or a trusted cellular connection rather than connecting sensitive work directly to open public networks.
None of this requires sophisticated hacking skills on the attacker’s part.
It requires an unencrypted connection and an unsuspecting user.
Shoulder Surfing Is a Real Risk, Not a Movie Cliché
Digital interception is not the only concern.
An attorney reviewing a settlement demand, a medical record or a confidential email thread on a laptop screen in a crowded airport gate area, hotel lobby or coffee shop is also exposing that information to anyone within eyeglass range.
This is sometimes dismissed as an unrealistic concern.
It is not.
Privacy screen filters exist specifically because this happens often enough to justify an entire product category.
A person seated in the row behind, in the next chair over or simply walking past can potentially see client names, case details, financial information or privileged communications displayed in plain view.
Combined with a phone call discussing case specifics within earshot of strangers, an attorney can inadvertently create exactly the kind of unauthorized disclosure that Rule 4-1.6 is designed to prevent, without any hacking or technology failure involved at all.
The Personal Device and Personal Cloud Problem
Remote work often blurs the line between personal and professional technology.
An attorney without immediate access to a firm laptop may use a personal computer instead.
A document may get saved to a personal cloud storage account for convenience, with every intention of moving it to the firm’s system later.
An email may get forwarded to a personal account so it can be reviewed on a personal phone.
Each of these choices feels minor in the moment.
Collectively, they can result in client information existing outside the firm’s actual security controls, in places the firm may not even be aware of.
If that personal device or personal account is ever compromised, lost or stolen, the firm may not immediately know that client information was exposed, because the information was never inside a system the firm was monitoring in the first place.
Florida Bar guidance and the broader trend in legal ethics opinions across the country increasingly emphasize that attorneys are responsible for understanding where client data actually resides, not simply assuming it is protected because it exists somewhere in the cloud. Our managed IT services help firms map exactly where client data lives across firm and personal systems.
What “Reasonable Efforts” Actually Looks Like
Rule 4-1.6 does not require perfection.
It requires reasonable efforts to prevent unauthorized disclosure or access.
That standard is not static. What counts as reasonable depends on the sensitivity of the information, the technology available and the circumstances of the representation.
For most firms, reasonable efforts around remote work should include several concrete practices.
Using a virtual private network whenever connecting to public or unfamiliar Wi-Fi networks, so that traffic is encrypted regardless of the underlying network’s security.
Using a personal cellular hotspot instead of public Wi-Fi when handling especially sensitive matters, since a cellular connection is generally more difficult for a nearby attacker to intercept than an open Wi-Fi network.
Using a privacy screen filter on laptops that will be used in public spaces.
Avoiding discussing specific case details on phone calls in public areas.
Keeping client documents within firm-managed systems rather than personal cloud storage accounts.
Using firm-issued devices with proper security configurations rather than personal devices whenever possible.
Enabling multifactor authentication on every account that can access firm systems remotely.
Ensuring firm devices are encrypted, so that a lost or stolen laptop does not automatically expose its contents.
None of these measures are exotic or prohibitively expensive.
They are baseline practices that any firm handling client confidences while working outside the office should have in place.
Hotels Introduce Their Own Risks
Hotel Wi-Fi networks deserve specific attention because attorneys often treat them as safer than a coffee shop network, without much basis for that assumption.
A hotel network is still typically shared among dozens or hundreds of guests at once.
Some hotel business center computers are shared machines that may retain files, browser history or cached documents from previous guests.
An attorney who prints a confidential document at a hotel business center, or works on one using a shared computer, may be leaving information behind in ways that are easy to overlook while traveling.
The safest approach treats hotel Wi-Fi with the same caution as any other public network: a VPN for any sensitive work, and firm-managed devices rather than shared hotel equipment for anything involving client information.
The Coffee Shop Problem Is Slightly Different, But Not Safer
Coffee shops present a variation on the same risk, with a few added wrinkles.
Unlike an airport gate, where people are generally moving through, a coffee shop often has the same small group of people sitting for extended periods, sometimes for hours at a time.
That means a person seated at a nearby table has considerably more time and opportunity to observe a laptop screen, overhear a phone call or notice patterns in what an attorney is working on.
Coffee shop Wi-Fi networks are also frequently named something generic and easily spoofed, such as the shop’s name followed by “Guest” or “Free,” making it simple for an attacker to set up a nearly identical rogue network nearby.
Background noise in a coffee shop can also create a false sense of privacy for phone calls.
An attorney may feel that ambient noise from espresso machines and conversation provides cover, when in reality a nearby table can often hear far more of a phone conversation than expected, particularly names, case numbers or specific factual details mentioned repeatedly.
The combination of extended dwell time, easily spoofed network names and a false sense of acoustic privacy makes coffee shops a genuinely underestimated risk environment, not a lower-risk alternative to an airport or hotel.
Video Calls in Public Spaces Add Another Layer
Remote work has also normalized taking video calls from public or semi-public spaces, including airport lounges, hotel lobbies and coffee shops.
A video call adds a visual dimension to the confidentiality risk that a phone call alone does not.
Anyone within view of the screen may be able to see the other participants, shared documents, case management software or email inboxes visible in the background or briefly shared on screen.
Virtual backgrounds and blurred backgrounds address part of this concern, but they do not address what happens when a document is shared on screen during the call itself.
Attorneys taking client or case-related video calls while traveling should treat screen sharing with the same caution as opening a sensitive document on a laptop in a crowded space, because functionally, it is the same exposure.
Most firms have never explicitly documented what attorneys should and should not do while working remotely.
That gap creates inconsistent practices across the firm.
One attorney may instinctively use a VPN without ever being told to.
Another may have no idea the firm expects one.
A written remote work and technology policy closes that gap.
At minimum, a policy should address which networks are acceptable for firm work, whether a VPN is required and under what circumstances, expectations around personal devices and cloud storage, requirements for multifactor authentication, and expectations for handling confidential conversations in public spaces.
The policy does not need to be lengthy.
It needs to exist, be communicated clearly and be followed consistently.
What Happens When This Goes Wrong
The consequences of an unauthorized disclosure extend beyond a single uncomfortable conversation with a client.
A breach of client confidentiality can result in a bar complaint, particularly if a client learns that their sensitive information was exposed through an easily preventable oversight.
It can create malpractice exposure, especially if the disclosed information caused demonstrable harm to the client’s matter.
It can damage the firm’s reputation among referral sources and existing clients who expect discretion as a baseline requirement of hiring an attorney.
And in matters involving particularly sensitive information, such as family law, criminal defense or business litigation involving trade secrets, the practical harm of an exposed communication can be significant and difficult to undo.
None of this requires a sophisticated cyberattack.
It can result from an unencrypted connection at an airport gate and an unlucky coincidence of timing.
This Applies to Paralegals and Staff Too
The discussion so far has focused on attorneys, but the same obligations extend to paralegals, legal assistants and any staff member who handles client information remotely.
A paralegal reviewing discovery documents from a hotel room the night before a hearing carries the same confidentiality exposure as the attorney arguing the motion.
A legal assistant checking client emails from a coffee shop between errands introduces the same risk profile as anyone else accessing firm systems from an unfamiliar network.
Firm policies and training on remote work security should apply firm-wide, not only to attorneys with client-facing responsibilities.
In many firms, staff members are actually more likely to be working remotely on a regular basis than partners, simply due to the nature of administrative and support work increasingly happening outside a fixed office setting.
A security policy that only addresses attorney behavior leaves a significant portion of the firm’s actual risk unaddressed.
Do our attorneys have access to a VPN, and is its use required for public or unfamiliar networks?
Are firm-issued devices encrypted by default?
Is multifactor authentication required for remote access to firm systems and email?
Do we have a written policy addressing remote work and public Wi-Fi use?
Are attorneys using personal cloud storage or personal email for any firm-related documents?
If a firm laptop were lost or stolen while an attorney was traveling, what would actually happen to the data on it?
If your IT provider cannot answer these clearly, that is a conversation worth having before the next flight delay, not after.
Working Remotely Should Not Mean Working Exposed
None of this means attorneys should stop working from airports, hotels or coffee shops.
Modern legal practice depends on flexibility, and clients often expect responsiveness regardless of where an attorney happens to be.
The goal is not to eliminate remote work.
It is to make sure the same ethical obligations that apply inside the office are actually being honored outside of it, through simple, consistent, reasonable safeguards.
A VPN, a privacy screen, a cellular hotspot for sensitive matters and a written firm policy address the overwhelming majority of the real-world risk, without requiring attorneys to change how or where they work.
ITva Technologies provides managed IT and cybersecurity services for law firms across Miami-Dade and Broward, with a focus on secure remote access, encrypted devices, VPN deployment and the technology competence obligations attorneys are increasingly expected to understand.
Our managed IT services help firms configure secure remote access so attorneys can work confidently from anywhere without exposing client confidences.
Our cybersecurity services layer encryption, multifactor authentication and monitoring around the devices and accounts attorneys rely on while traveling.
If your firm has never documented what attorneys should do while working outside the office, that is worth addressing before the next depositions require travel, not after.
Schedule a free technology and confidentiality assessment with ITva.
We will review your current remote access setup, device encryption, VPN availability and firm policies, then show you where risk may exist.
Because the obligation to protect client confidences does not stay behind at the office.
It boards the flight too.
Frequently Asked Questions
Is it ever acceptable for an attorney to use public Wi-Fi for firm work?
Public Wi-Fi can be used more safely when combined with a virtual private network, which encrypts traffic regardless of the underlying network’s security. Without a VPN, sensitive or privileged work should generally be avoided on open public networks.
Does Florida Bar Rule 4-1.6 specifically require a VPN?
The rule does not name specific technologies. It requires reasonable efforts to prevent unauthorized disclosure or access to client information, and what counts as reasonable depends on the sensitivity of the information and the tools reasonably available. A VPN is widely considered a reasonable and readily available safeguard for remote work.
Are hotel business center computers safe to use for legal work?
Generally, no, for anything involving confidential client information. Shared computers can retain cached files, browser history or printed documents from other guests, and hotel networks are typically shared among many guests at once.
What is technology competence under the Florida Bar rules?
The comment to Rule 4-1.1 states that competence includes keeping abreast of the benefits and risks associated with relevant technology. This means attorneys are expected to understand, at a reasonable level, how the technology they use affects the security of client information.
Can using personal cloud storage for client documents create an ethics problem?
It can, particularly if the firm has no visibility into or control over that storage account’s security settings. Client information stored outside firm-managed systems may not receive the same protections, monitoring or backup procedures the firm has established.
What is the single most effective step a firm can take to reduce this risk?
Deploying a VPN for all attorneys and requiring its use on public or unfamiliar networks addresses the majority of the technical risk. Pairing that with a clear written remote work policy addresses the behavioral gaps that technology alone cannot solve.