The duty follows the lawyer outside the office
The Florida Bar’s June 2026 ethics guidance explains that a lawyer’s confidentiality obligations under Rule 4-1.6 do not end when the lawyer travels. Lost devices, unsecured wireless networks, visual exposure, public conversations, and shared business services can expose information relating to a representation. The duty applies broadly and requires reasonable efforts to prevent unauthorized access or disclosure.
For Central Florida firms, mobile work can mean a courthouse, airport, hotel, client site, hurricane relocation, home office, or coffee shop. A practical policy should address the entire trip—from deciding what information must leave the office through reporting a lost device.
Minimize what travels
Begin by reducing the client information stored locally. Use a dedicated travel device for higher-risk trips when appropriate, and configure it with only the applications and files needed for the matter. Confirm that cloud access does not automatically synchronize broad client folders to the device.
Inventory phones, tablets, laptops, removable media, and authentication keys assigned to traveling personnel. Record who owns each device, whether encryption is enabled, and how access can be revoked.
Protect access and communications
Require strong device authentication and multifactor authentication for remote services. Keep devices under physical control, use privacy screens where shoulder surfing is possible, and avoid public printers or shared business-center computers. The Florida Bar advises using a secure VPN on public networks and notes that personal cellular data may be safer.
A VPN does not make every activity safe. Staff should still verify the destination service, install updates, use encrypted applications, and avoid unexpected login prompts. Disable automatic connection to remembered public networks.
Prepare for loss or compromise
Every traveler should know exactly how to report a missing or suspicious device. The response card should include a monitored telephone number, alternate contact, device identifier, carrier information, and steps for remote lock or wipe. Preserve the facts needed for counsel to evaluate client communication and breach-notification duties.
Do not wait for certainty before reporting. Fast notice gives the firm more options to revoke sessions, reset credentials, preserve logs, and determine what information was accessible.
Supervise vendors and AI tools
Florida Ethics Opinion 24-1 says lawyers using generative AI must protect client confidentiality and research a tool’s data-retention, data-sharing, and self-learning policies. The same vendor-governance discipline applies to transcription, document sharing, remote support, and cloud storage.
Before allowing client information into a service, document the approved use, contractual confidentiality obligations, security controls, retention behavior, breach notification terms, and exit procedure. Lawyers remain responsible for professional judgment and supervision.
Evidence checklist for the firm
1. Written mobile-work and travel rules approved by firm leadership.
2. Current device inventory with encryption and remote-management status.
3. MFA and secure remote-access configuration evidence.
4. Defined rules for public Wi-Fi, printers, screens, and conversations.
5. A tested lost-device reporting and session-revocation process.
6. Vendor reviews for cloud, AI, transcription, and support tools.
7. Training records and periodic scenario exercises.
8. A post-trip check for device, account, and client-data anomalies.
This article is educational and is not legal advice. Florida lawyers should consult applicable rules, ethics counsel, and qualified legal professionals for circumstances specific to their practice.

