Industries — Legal
IT for firms where confidentiality isn't optional.
Client confidentiality isn't just good practice — it's an ethical obligation under California's Rules of Professional Conduct, enforced by the State Bar, the courts, and your malpractice carrier. We build your IT around that standard, not around a generic best-practices checklist.
What it is
Legal-centric IT, not generic IT with a law firm client
Running a law firm means matter deadlines that don't move, client expectations of absolute discretion, and a legal software stack that a generalist IT provider often doesn't understand. We design support around how firms actually operate — matters, deadlines, confidentiality, and the platforms your practice runs on.
Model Rule 1.6 requires reasonable precautions against unauthorized disclosure of client information, and courts and malpractice carriers are paying closer attention to what "reasonable" means in a technology context. We build that standard in from day one.
Since 2021, California's Rule of Professional Conduct 1.1 has made this explicit: the duty of competence includes staying current on "the benefits and risks associated with relevant technology" — and the rule itself says a lawyer satisfies that duty by retaining someone competent to handle it, not by becoming a security expert personally. That's the job we do. We're not your ethics counsel and we won't tell you how to interpret the rule — we're the technology side of meeting it.
Built for how firms run
Six things every legal client gets
Encryption and MFA by default
Not an upsell — standard on every account, protecting client communications and files at rest.
Practice-software-aware support
We work with the case management and document platforms your firm already runs on — Clio, MyCase, Prevail, and Time Matters for case and practice management, plus Lexis+ and CaseMap+ AI for research and litigation analysis.
Documented security posture
Clear, current documentation you can hand to a malpractice carrier or a client's IT audit.
E-discovery-ready infrastructure
Storage and access controls sized for large document productions, not just everyday email.
Deadline-aware support hours
Filing deadlines and trial dates don't wait for business hours — we plan for that.
Confidential-by-design file sharing
Client and opposing-counsel document exchange handled without email attachments as the default.
Why it matters
Confidentiality is an ethical duty, not a nice-to-have
Bar associations and malpractice carriers are asking harder questions about firm technology than they used to.
Model Rule 1.6 is enforceable
"Reasonable precautions" against disclosure isn't a suggestion — it's a professional obligation with real consequences.
Carriers are asking harder questions
Malpractice insurers increasingly want specifics about encryption, backups, and access control before they'll write a policy.
Matters don't pause for IT problems
A filing deadline doesn't move because your network went down the night before.
Generalist IT misses the legal stack
Case management, document assembly, and e-discovery tools need a provider who's actually used them — Clio, MyCase, Prevail, and Time Matters for case files, Lexis+ and CaseMap+ AI for research and litigation analysis — not one that treats your practice software as "just another app" the help desk has never opened.
A specific note for disability, injury & workers' comp practices
If your firm runs Prevail, files through the SSA, or lives inside medical records all day, your IT needs aren't the same as a general litigation firm's.
Social Security disability, workers' compensation, and personal injury practices aren't just "law firms with more paperwork." They run on a federally-mandated electronic filing system, carry an unusually high volume of third-party medical records inside otherwise-privileged case files, and depend on case and litigation-analysis software — we support Prevail, Clio, MyCase, Time Matters, Lexis+, and CaseMap+ AI — built for exactly this kind of practice. This isn't a generic pitch: it's hands-on experience, not a category we're guessing applies to you.
The SSA's e-filing mandate isn't optional
Since November 2020, representatives who take direct fee payment — the norm in contingency-fee SSDI/SSI practice — must submit evidence electronically through the SSA's Electronic Records Express or Appointed Representative Services. That's federal rule, not a firm's preference. We keep the systems that requirement depends on — your internet, your browser security, your staff's access — actually working.
Medical records inside a privileged file are a different security problem
Disability and injury cases run on evidence that's substantially a third party's protected health information, layered inside your own attorney work product. Whether that specific arrangement makes your firm a HIPAA business associate is a fact-specific legal question for your own counsel — but either way, those records get the same encryption and access control as everything else in your firm, by default.
We already run Prevail — not just "legal software" in general
Prevail is built specifically for Social Security disability, workers' comp, and personal injury practices, not general case management, and it's one of the platforms our team has actual hands-on experience supporting today.
Our platform experience clusters where these cases actually live: in the evidence
We also support CaseMap+ AI, LexisNexis's litigation fact-and-evidence-analysis platform — the same kind of work SSDI, workers' comp, and PI cases are built on: organizing medical records, depositions, and case facts into something usable under a deadline. That's not a coincidental overlap in a long tool list — it's the same skill applied to the same kind of case.
The Good Hunter difference
Security built for how firms actually get sued for losing it
We know your case management software
Support that starts from how your firm already works, not a generic ticket queue.
Encryption as the default
You don't have to ask for the secure option — it's the only option.
Documentation your carrier will accept
Clear, current answers ready before your malpractice renewal questionnaire lands in your inbox.
Questions we hear a lot
Legal IT, plainly explained
Do you support legal practice management software?
Yes — we have hands-on experience with Clio, MyCase, Prevail, and Time Matters for case and practice management, and with Lexis+ and CaseMap+ AI for research and litigation analysis. Those are two genuinely different kinds of support, and we'll say so plainly: for an installed, firm-managed system like Time Matters or Prevail, we're deep in the network, backup, and access controls around it. For a hosted platform like Lexis+, our role is mostly making sure the right people have secure access — single sign-on, account provisioning, MFA — not managing infrastructure that isn't ours to manage. Either way, whatever your firm runs holds up to the standard your malpractice carrier expects. (If your firm runs Prevail specifically, see the dedicated section below — Prevail is built for disability, workers' comp, and personal injury practices, not general case management, and we treat it that way.)
What does "reasonable" security actually mean under California's rules?
California's confidentiality rule doesn't hand you a checklist — it asks whether your safeguards are "reasonable" given the sensitivity of the information, the real risk of disclosure, and the cost and difficulty of the safeguard. That's actually good news for a small firm: the standard scales with you. It doesn't mean a 4-attorney firm needs the same security budget as a 200-attorney firm — it means your safeguards need to genuinely fit the risk you're carrying, and we can walk through what that looks like for your practice specifically.
Does hiring an IT provider satisfy our ethical duty to "keep abreast of" technology?
California's own rule (Rule of Professional Conduct 1.1, Comment 1, added in 2021) says yes — a lawyer doesn't have to become a technology expert personally; retaining someone competent to handle it is how the rule expects most firms to meet the standard. We're not your ethics counsel, and we won't tell you how a bar investigator would read a specific fact pattern — that's a question for your own counsel. What we do is give you the actual technical competence the rule assumes you're retaining.
Can you help us respond to our malpractice insurer's security questionnaire?
Yes. Carriers are asking sharper, more specific questions than they used to — not "do you have a security policy" but proof: MFA status across every system that touches client data, endpoint detection and response reports, documented and restore-tested backups, patch records, and an incident response plan. We keep that documentation current year-round, so answering a renewal questionnaire is pulling a report, not scrambling to reconstruct what your setup actually does. We're not your broker and can't guarantee a carrier's decision — we make sure the honest answer to every question on the form is "yes, and here's the record."
What happens if we answer "yes" on a questionnaire and it isn't actually true?
That's the real exposure — a carrier can deny a claim after a breach if it finds the renewal application overstated your actual controls. This is exactly why we recommend reviewing the questionnaire against your real setup before it's submitted, not after an incident forces the question.
How do you handle confidential client communications?
Encryption and multi-factor authentication are standard on every account, not an add-on. Client data is protected the same way whether it's a routine matter or a high-stakes case — and the same standard applies whether your team is in the office or working from home, consistent with the ABA's own guidance on virtual practice (secure connections, current patching, encryption, and care around what's said near always-listening smart speakers during a privileged call).
Our attorneys work from home sometimes — does that create a confidentiality problem?
Not if it's set up right, but "right" is specific: a secured connection (not whatever the coffee shop or home router happens to offer), current security patches, encryption, and multi-factor authentication on anything that touches a client matter. We configure remote access to meet that bar by default, so "working from home" doesn't mean "working around your security."
What about e-discovery and large document productions?
We make sure your infrastructure — storage, bandwidth, and access controls — can handle large productions without becoming the bottleneck on a deadline.
When opposing counsel sends a litigation hold notice, what's on IT's plate vs. yours?
The legal judgment — when a hold is required, how broad it should be, which custodians and matters it covers — is yours, often with your own litigation or ethics counsel weighing in. Once you've made that call, our job is execution: we suspend the relevant auto-delete or retention policy on the specific mailboxes and files you name, and we confirm, with a timestamp, that it's done. We don't decide when a hold applies — we make sure the one you issue actually holds.
How long should we actually keep closed client files?
There's no single California statute that sets one retention period for every closed matter — it depends on your malpractice carrier's guidance, your engagement letter terms, and in some matters, bar-specific guidance for that practice area. That's a policy decision for you (often with your carrier or counsel), not something we set for you. What we do is make whatever period you land on actually enforceable in your systems — automated archiving and deletion on the schedule you decide, not a manual process someone forgets to run.
Does the California Consumer Privacy Act (CCPA/CPRA) apply to a firm our size?
It depends on your data volume, not your headcount — coverage kicks in if you meet any one of a few thresholds (roughly: $25M+ in annual revenue, or handling personal information for 100,000+ California consumers/households a year, among others), and most small local firms genuinely don't clear that bar on their own client data alone. Whether you're a "covered business" is a legal/accounting question for your own counsel — what we can tell you plainly is that the infrastructure a CCPA/CPRA compliance program actually depends on (access controls, encryption, logging who touched what, and being able to respond to a request quickly) is exactly what we already build in by default, whether or not the statute technically applies to you.
What happens to a filing deadline if our internet is down the night before?
Fresno County Superior Court requires e-filing for civil, family law, probate, small claims, and mental health matters through the Odyssey eFileCA system, available 24/7 — which means your ability to file at 11:45pm the night something's due depends entirely on your own internet and document systems being up, not just the court's. That's exactly what our 24/7 monitoring and uptime commitment exist for. We can't control the court's e-filing system or guarantee a filing succeeds — formatting and court-side issues are outside IT's reach — but the parts that are ours to control (your network, your document access) aren't going to be the reason you missed it.
Can you support us during trial prep or after hours?
Yes. Matter deadlines don't run on business hours, and neither does our support when a filing deadline or trial date is on the line.
A paralegal or associate is leaving the firm — how fast can their access be shut off?
Same day, and the moment you tell us to. Departing-staff access to case files, email, and practice-management systems is one of the more common ways client data walks out the door without anyone intending it to — we treat offboarding as a standard, documented step, not an afterthought that happens whenever IT gets to it.
Can our attorneys use tools like ChatGPT or Copilot on client matters?
Yes, with the right configuration — and that configuration is something we already do for clients today. Consumer-tier AI tools can retain or train on whatever you type into them, which is a real confidentiality risk with privileged or client-identifying information. We set your firm up on enterprise-tier tools instead, configured so client data isn't retained or used for training — the same default-secure standard we hold every other system in your firm to. We're not your ethics counsel and won't tell you what a specific bar opinion means for your fact pattern — that's your counsel's call — but making sure the tool itself can't leak client data is ours to deliver, and we already do.
We run Prevail for our disability/injury caseload — do you actually support it, or just "legal software" in general?
We support Prevail specifically. It's built for Social Security disability, workers' comp, and personal injury practices — not general case management — and it's meaningfully different from platforms like Clio or MyCase in how it structures a case file. We size the network, backup, and access controls around how Prevail is actually used in your firm, not a generic legal-software template.
Our attorneys have to submit evidence through the SSA's electronic systems — does that affect our IT setup?
Yes, and it's not optional if your firm requests direct fee payment, which is the norm in contingency-fee SSDI/SSI practice. Since November 2020, federal rule has required representatives who take direct payment to submit evidence electronically through the Social Security Administration's Electronic Records Express (ERE) or Appointed Representative Services (ARS) — not a firm preference, a requirement. That means your internet connection, browser security, and staff access all become load-bearing for a federal filing requirement, not just your own convenience. We treat that dependency the same way we treat a court e-filing deadline — as infrastructure that has to be up when it matters, not an afterthought.
Are we a HIPAA business associate because we handle our clients' medical records?
It depends on the specifics of how your firm obtains and uses those records, and it's genuinely a fact-specific legal question — we're not going to tell you your firm's HIPAA status, and you shouldn't take that determination from an IT vendor either way; that's a question for your own counsel. What we can tell you is that the practical safeguards HIPAA would require if you are covered — encryption, access controls, audit logging — are exactly what we already build into every account by default. The IT side of that question is covered regardless of how the legal question resolves.
Where to start