Services such as Dropbox or OneDrive are very handy and can be quite popular with lawyers because they can enable having documents available on multiple devices and available nearly anywhere, anytime.
However, there can be serious implications of using such services, and I would refer back to the requirements of Rule 3-100 of the Rules of Professional Conduct of the California State Bar which deal with confidentiality. Depending on the type of information, there may be other regulations in effect, including HIPAA, California SB 1386 (now civil code sections 1798.29, 1798.82 and 1798.84), and others.
One major issue with programs like Dropbox is that if they are replicating files to computers, phones, or tablets taken outside of the office, and if someone loses one of those devices, anyone that finds that device may very well be able to access the data. Don’t think it will happen to you? Laptops and cell phones are often lost or stolen, and tons of people leave iPads in seatbacks on airplanes, never to see them again.
Another issue is that if a device gets infected with ransomware, the files from Dropbox may very well be replicated back to Dropbox and every other device that has been configured for replication. That means that all of the GOOD copies are gone, replaced by the damaged copies.
Do Dropbox employees or those of similar services have any possible access to your documents? You may not think so, but they very well may. Remember, your files are being stored on THEIR servers.
Can those files be hacked? Despite all of the assurances that companies like Dropbox are hack-proof, the reality and history are far different. Dropbox themselves were hacked more than once, as reported by multiple news outlets.
There is also the issue of who has access to what. It is not uncommon for law firms – particularly smaller ones – to simply allow access to everything to everyone. However, not everyone SHOULD have access to everything. Some services allow setting up specific rights as to who has access to what, but this is useful only if it is properly implemented and managed.
Encryption of all files can help because in the event that a device is lost or stolen, the files will be unusable and unreadable to anyone. Of course, if encryption passwords are also stored on the device, or worse, stuck on the bottom with a Post-It, the encryption is worthless.
In summary, services such as Dropbox, OneDrive, Box, and others can be very useful, but care must be taken and the proper planning done both before implementation and on an ongoing basis.


