Speak With An IT Professional Immediately. Call (312) 922-8600

Law Firm Data Security in Chicago: What Illinois Attorneys Are Legally Required to Do About Client Data

20+ Years in Business Years in Business
100% HIPAA Certified Staff HIPAA Certified Staff
Microsoft Certified Partner Microsoft Certified Partner
98.2% Client Retention Rate Client Retention Rate

A Chicago litigation firm gets a call from opposing counsel referencing a document that was never produced in discovery. It turns out an associate’s laptop was compromised three weeks earlier by a phishing email, and nobody noticed until stolen files started showing up where they shouldn’t. The firm now has two problems: a security incident, and a set of legal obligations under Illinois law that most partners have never actually read.

This article focuses on the second problem. Illinois law firms can’t treat client data protection as a best practice. It’s a legal requirement that runs through professional conduct rules, a state breach notification statute, and the vendor contracts firms sign without reading closely. Each obligation translates directly into how a firm’s IT environment must be built. This is what that translation actually looks like.

The Ethics Rule Sets the Bar, But It’s Not the Only Law in Play

Most Chicago attorneys know Rule 1.6 of the Illinois Rules of Professional Conduct requires “reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.” Paired with Rule 1.1’s competence requirement, which the Illinois Supreme Court Commission on Professionalism has confirmed extends to understanding relevant technology, this is the ethical foundation for data protection at every Illinois firm. We’ve covered what “reasonable efforts” means under Rule 1.6 in detail in our guide to ABA Rule 1.6 for Chicago law firms, so this piece won’t repeat that ground.

What often gets missed is that Rule 1.6 is a professional conduct standard, enforced by the ARDC. It isn’t a data breach law. Illinois has a separate statute that governs what happens after something goes wrong, and it applies to every business that holds Illinois residents’ personal information, not just law firms. Attorneys who think their ethical obligations end with client confidentiality are seeing only half the picture.

Hear From Our
Happy Clients

Read Our Reviews

Illinois Has Its Own Breach Notification Law, and the Clock Starts the Moment You Discover a Problem

The Illinois Personal Information Protection Act, codified at 815 ILCS 530, requires any organization that handles, collects, or disseminates Illinois residents’ personal information to disclose a breach in the most expedient time possible, without unreasonable delay. That covers essentially every law firm in the state regardless of practice area.

The Act doesn’t stop at notifying clients. If a breach affects more than 500 Illinois residents, the firm must also notify the Illinois Attorney General’s office. Beyond the notification trigger, PIPA requires covered organizations to implement and maintain reasonable security measures to protect data from unauthorized access, destruction, use, or disclosure. That “reasonable security measures” language is doing a lot of work, and it’s the same phrase that shows up under Rule 1.6, which means Illinois attorneys are effectively held to a consistent security standard whether the question comes from the ARDC or the Attorney General’s office.

There’s a provision in PIPA that catches most firms off guard. The statute requires any contract under which one company transmits personal information to another to include language requiring the recipient to maintain reasonable security measures of its own. For a law firm, that means the contract with your document management system vendor, your e-discovery platform, and your cloud storage provider all need this language addressed directly. Most firms have never checked.

Competence Now Means Knowing Where the Data Actually Lives

Rule 1.1’s technology competence requirement isn’t abstract. It means a managing partner should be able to answer specific questions: Where does client file data physically reside? Who at the firm can access a given matter’s documents, and is that access reviewed when someone changes roles or leaves? What happens to a departing associate’s email access and file permissions on their last day, not their last week?

Firms using document management systems like iManage or NetDocuments often assume the platform’s built-in security handles this automatically. It doesn’t, not without configuration. Permission structures, retention policies, and audit logging all have to be set up deliberately and reviewed periodically. An IT provider without legal industry experience will get the software installed and functioning. Getting the access controls aligned with confidentiality obligations and matter-level ethical walls is a different task, and it’s the reason our managed IT services for law firms in Chicago are built specifically around legal workflows rather than adapted from generic small business support.

What “Reasonable Security Measures” Looks Like on a Network, Not on Paper

Neither PIPA nor Rule 1.6 publishes a technical checklist, which is part of what makes this hard for firms to self-assess. Based on ABA guidance, ISBA commentary, and what actually holds up under scrutiny after an incident, a defensible security posture for an Illinois firm in 2026 includes a specific set of controls, not a general commitment to “taking security seriously.”

Multi-factor authentication needs to cover every system that touches client data: email, the document management platform, practice management software, remote access, and billing systems. A firm that enforces MFA on email but not on its DMS has a gap that an auditor, an insurer, or opposing counsel in a malpractice claim will find.

Least-privilege access means staff can reach only the matters and systems their role requires, and that access is reviewed on a schedule rather than left in place indefinitely. Endpoint detection and response, not legacy antivirus, needs to sit on every device that connects to firm systems, including partner laptops used at home.

Backups need to be isolated from the primary network and tested for actual recoverability, not just confirmed as “running.” A backup nobody has restored from is a backup you don’t actually have. And there needs to be a written incident response plan that names who does what in the first 24 hours after a suspected breach, because PIPA’s “most expedient time possible” standard leaves no room for a firm to spend a week deciding who’s in charge.

The ABA’s 2024 Legal Technology Survey Report found that 60% of firms have implemented formal cybersecurity policies, which means a meaningful share of firms, including some in Chicago, still haven’t. If your firm falls into that gap, it’s a documented exposure the moment a regulator or an insurer asks to see it.

The Vendor Contract Clause Almost No Firm Reads Before Signing

Because PIPA requires reasonable security provisions to flow down through vendor contracts, every third-party platform touching client data deserves a second look: the cloud-based DMS, the e-discovery vendor, the outsourced court reporting service, even the IT provider itself. If that language isn’t in the contract, the firm hasn’t actually satisfied the statute’s requirement, regardless of how secure the vendor’s platform happens to be in practice.

This is also where cyber insurance intersects with the same obligations. Carriers increasingly require documented evidence of the same controls PIPA and Rule 1.6 point toward, and a firm that can’t produce that documentation risks a denied claim on top of a breach. We’ve written separately about how cyber insurance claims get denied for Chicago law firms when this documentation doesn’t exist.

Where Chicago Firms Consistently Get This Wrong

Three patterns show up repeatedly in onboarding assessments at firms that assumed they were covered. Firms treat their general IT provider’s word that “we’re secure” as sufficient documentation, when neither the ARDC nor the Attorney General’s office accepts a verbal assurance as evidence of reasonable measures. Firms configure Microsoft 365 with default settings rather than the hardened configuration legal data actually requires, a gap we detail in our breakdown of Microsoft 365 security features Chicago law firms need to check. And firms conduct a security review once, at onboarding with a new IT provider, and never again, despite the standard for “reasonable” shifting every year as threats and expectations evolve.

The fix for all three starts with an honest look at the current environment against what the law actually requires, not against what feels sufficient. Our risk assessment process in Chicago is built around exactly that gap analysis, and our full Chicago law firm IT guide walks through the broader environment beyond security alone.

Client Data Protection Is a Legal Obligation With a Technical Answer

Illinois law firms are operating under overlapping duties: an ethics rule that requires reasonable efforts to protect confidentiality, a state statute that mandates specific security measures and notification timelines, and vendor contract requirements most firms have never verified. None of these obligations get satisfied by good intentions or a general sense that the firm’s IT setup is fine. They get satisfied by specific, documented, and periodically reviewed technical controls.

For more on how we approach data security for legal clients specifically, see our cybersecurity consulting services in Chicago or our IT consulting services for law firms throughout Illinois. If your firm hasn’t had its environment reviewed against these standards in the last year, that’s the conversation worth having before an incident forces it.

Share This Story, Choose Your Platform!
no-photo

Aaron Kane

CEO of CTI Technology
Aaron Kane is the CEO of CTI Technology, a Chicago-based IT services provider helping businesses navigate technology with confidence. With expertise in IT strategy, infrastructure, cloud solutions, and voice technologies, Aaron focuses on helping organizations improve efficiency, strengthen operations, and make smarter technology decisions. Under his leadership, CTI Technology has continued to grow while maintaining a strong focus on service and long-term client relationships.
Connect with Aaron on Linkedin

Why Is CTI Technology The Best Choice For IT Services In The Chicagoland Region?

quotes
“Great pricing, even better service. Highly recommended!”
Great pricing, even better service. Highly recommended!”
Guido Arquilla
stars
quotes
“Great IT company for our business! Highly recommended.”
“Great IT company for our business! Highly recommended.”
Brian Coli
stars
quotes
“CTI is a great company and I would not trust my IT services to anyone else.”
CTI is a great company and I would not trust my IT services to anyone else.
Jenny Wagner
stars

CTI Technology Tips & Articles

Check Out Our Technology Insights
Call Now Button