HackFirstAidLaw Firms
HomePlaybooksServicesRegulationsAboutContact
← Playbooks · Vendors & third parties

Practice-management or document-management vendor compromise

Clio, NetDocuments, iManage, or your DMS vendor has the incident. The firm is still responsible to the client.

When the vendor — Clio, MyCase, PracticePanther, Smokeball, CosmoLex, NetDocuments, iManage, Worldox, ProLaw, Tabs3-class — is breached, what the firm does operationally and what it does ethically. The firm is still responsible to the client for safeguarding the data even when the vendor had the incident.

The first hour

What to do, in order.

  1. 01

    Pull the vendor's incident notice, status page, and customer security bulletin. Save copies.

  2. 02

    Open a ticket and request: confirmation of whether the firm's tenant was in scope, what data classes were affected, and the vendor's forensic timeline.

  3. 03

    Identify which clients' matters live in the affected system; do not notify yet — facts first.

  4. 04

    Trigger the firm's own incident response process even though the vendor is doing theirs.

Key decisions

The questions you'll be asked.

Is the vendor's notice sufficient for the firm's own clients?
Almost never. The vendor notifies the firm; the firm notifies the client. The Opinion 483 duty is the firm's, not the vendor's.

Regulatory & ethical hooks

What the rules say.

  • ABA Formal Opinion 483
  • ABA Model Rule 5.3 — Responsibilities regarding non-lawyer assistance (incl. vendors)
  • State data-breach notification laws
  • HIPAA Business Associate rules (if the firm is a BA)

Cited for orientation, not as legal advice. Your firm's ethics counsel and LPL carrier should be consulted on every specific incident.

Related playbooks

  • Vendors & third parties

    Co-counsel, e-discovery, or vendor breach

  • Operations

    Ransomware mid-litigation

HackFirstAid for Law Firms

The first hour after an incident decides whether your firm keeps the client's money, the client's secrets, and the client's trust. We walk firms through it in plain language.

Advisory, training, and incident response — not legal advice. Reading this site creates no attorney-client relationship.

The site

  • Home
  • Playbooks
  • Services
  • Regulations
  • About
  • Contact

Family

  • hackfirstaid.com
    Free for your household
  • business.hackfirstaid.com
  • municipal.hackfirstaid.com
  • education.hackfirstaid.com
  • medical.hackfirstaid.com
    HIPAA Business Associate overlay
  • boards.hackfirstaid.com
  • leadership.hackfirstaid.com
  • it.hackfirstaid.com
© 2026 HackFirstAid. All rights reserved.Scope of Use·lawfirm.hackfirstaid.com