Client Confidentiality Rules by Profession: What Lawyers, Accountants & Healthcare Providers Are Required to Protect

The Short Answer: What Do Client Confidentiality Rules Actually Cover?

Client confidentiality rules require lawyers, accountants, and healthcare providers to protect the information their clients share with them. However, the three professions operate under three different rulebooks. Attorneys follow ABA Model Rule 1.6 and attorney-client privilege. CPAs follow the AICPA Confidential Client Information Rule. Healthcare providers follow HIPAA. So while the duties overlap in spirit, they differ significantly in scope, exceptions, and enforcement.

Every professional who handles sensitive client information owes that client a duty of confidentiality. Most people know this in the abstract. Fewer know that the rules differ meaningfully depending on the profession.

For example, an attorney and a CPA may both hold the same tax file. If a court subpoenas it, the attorney can often assert privilege and refuse to hand it over. The CPA usually cannot. Meanwhile, a healthcare provider handling the same file adds an entirely different layer, because HIPAA applies as a federal statute with civil and criminal penalties, not a professional ethics rule.

This guide walks through the confidentiality rules for lawyers, accountants, and healthcare providers side by side. It also covers the exceptions to those rules, when it is appropriate to discuss confidential information, and where most confidentiality failures actually happen. Spoiler: not in the conference room.

Do Lawyers Have Client Confidentiality? Attorney-Client Privilege and ABA Model Rule 1.6

Yes. Lawyers have one of the strongest client confidentiality duties in any profession. The duty comes from two sources.

ABA Model Rule 1.6 requires attorneys to keep client information confidential. The rule covers everything relating to representation, not only what the client tells the lawyer directly. Adopted in some form by every U.S. state bar, Rule 1.6 also requires lawyers to make “reasonable efforts” to prevent unauthorized disclosure or access. See the current text at americanbar.org.

Attorney-client privilege is separate but related. Privilege is an evidentiary rule that protects certain communications from compelled disclosure in court. In litigation, a lawyer can refuse to reveal privileged communications even under subpoena.

For a practical walkthrough of what to do after a data breach, see our Law Firm Data Breach Response Playbook.

Which of the Following Is an Exception to Client Confidentiality?

Under Rule 1.6, a lawyer may reveal client information in specific circumstances:

  • To prevent reasonably certain death or substantial bodily harm
  • To prevent or rectify a crime or fraud in which the client is using the lawyer’s services
  • To comply with a court order or other law
  • To secure legal advice about the lawyer’s own compliance with the rules
  • To defend against a claim involving the lawyer’s representation
  • To respond to a fee dispute
  • To detect and resolve conflicts of interest

Each exception is narrow. Most lawyers will consult ethics counsel before invoking one.

Are Accountants Bound by Client Confidentiality? The AICPA Rule Explained

Yes. CPAs owe their clients a confidentiality duty under the AICPA Confidential Client Information Rule (1.700.001). The rule prohibits a CPA from disclosing confidential client information without specific client consent, with narrow exceptions.

The rule covers most information a CPA learns during an engagement. That includes tax data, financial statements, personnel matters, and business strategy.

The most important difference from attorney confidentiality is that CPAs do not have evidentiary privilege in most states. A CPA usually must comply with a subpoena for workpapers. Only a handful of states recognize a limited CPA-client privilege. Section 7216 of the Internal Revenue Code also adds federal criminal penalties for tax preparers who disclose tax return information without authorization.

The practical difference matters most in litigation. So many firms bring in legal counsel through joint engagements when the exposure is significant.

How Does HIPAA Compare? Healthcare’s Federal Confidentiality Framework

Healthcare providers protect client information under HIPAA. However, HIPAA stands apart from the other two frameworks in one important way. Instead of a professional ethics rule enforced by a state licensing body, HIPAA is a federal statute with civil and criminal penalties enforced by the U.S. Department of Health and Human Services.

The HIPAA Privacy Rule covers protected health information (PHI). It requires healthcare providers, health plans, clearinghouses, and their business associates to safeguard PHI in nearly every context.

Unlike attorney privilege, HIPAA does not create an evidentiary shield. A court can subpoena a HIPAA-covered record, though disclosure typically requires specific procedural steps such as a qualified protective order.

Also unlike attorney or CPA confidentiality, HIPAA applies regardless of what profession the individual practices. So a nurse, an insurance clerk, and an IT vendor at the same hospital all operate under it.

The three frameworks are worth understanding together because many businesses touch all three. For example, a law firm handling medical malpractice cases follows Rule 1.6 for its own confidentiality duty and HIPAA as a business associate for the healthcare data it receives.

When Is It Appropriate to Discuss Confidential Client Information?

There are a limited number of situations where a professional may discuss confidential client information. In general:

  • With the client’s informed consent. Most disclosures fall here. If the client authorizes it in writing, the professional can share what the consent covers.
  • With others in the same firm working on the matter. A junior associate, a paralegal, or an accounting clerk assisting the engagement generally has a need to know.
  • When required by a court order or subpoena. In most cases, the professional must comply, though attorneys can assert privilege where it applies.
  • To prevent serious harm. Every profession recognizes some version of this exception, though the threshold varies.
  • For legitimate professional review. Peer reviews, audits, and ethics investigations often require limited disclosure.
  • To defend against claims. A professional facing a malpractice or fee dispute claim may disclose what is reasonably necessary for their defense.

Outside these situations, casual disclosure of client information is a confidentiality violation and can be a disciplinary offense. That includes elevators, restaurants, social media, and even overheard conversations at industry events.

Where Confidentiality Actually Breaks Down: The File, Not the Conversation

Most confidentiality violations across all three professions do not happen because a lawyer, CPA, or clinician said something they should not have. Instead, they happen because a confidential file left the firm through the wrong channel.

The pattern is the same across all three:

  • A tax return attached to a regular email that a paralegal or clerk accidentally sends to the wrong address
  • A client’s medical records saved to a personal Dropbox for weekend work
  • A settlement draft shared through a free file transfer service with no audit trail
  • A discovery production dropped on a USB drive that gets lost between offices

None of these look dramatic. However, all of them can trigger a bar complaint, an OCR investigation, or a Section 7216 penalty depending on the profession.

Our guide on the top methods of protecting data covers this in more detail.

The underlying problem is that regular email, personal cloud drives, and free file transfer tools were not built for regulated client data. They lack encryption in transit and at rest, tamper-evident audit trails, granular access controls, and the ability to revoke access after the fact. A purpose-built secure file sharing platform closes each of those gaps.

TitanFile is a secure client portal built for legal, accounting, and healthcare workflows. Files stay encrypted in transit and at rest. Every access is logged. Access can be revoked at any time. And a signed Business Associate Agreement makes HIPAA workflows straightforward.

A Practical Client Confidentiality Checklist

Six steps every firm should apply, regardless of profession:

  1. Know which rule applies to your work. Attorney privilege, AICPA rule, HIPAA, or all three depending on the client.
  2. Get informed consent in writing before any non-essential disclosure.
  3. Restrict access to client files by role and by matter.
  4. Use encrypted channels for every external file transfer.
  5. Keep an audit trail of who accessed each file and when.
  6. Train staff annually on the specific rule that applies, not just “confidentiality” as a general concept.

Conclusion

Confidentiality is not one duty. It is three overlapping duties with three different sets of exceptions, three different regulators, and three different consequences when things go wrong.

The good news is that the practical protection is the same across all three. Encrypt the file, control who sees it, and log every access. Everything else is training, consent forms, and knowing when to call ethics counsel.

If your firm sends client files through email, consumer cloud drives, or free file transfer tools, that is where to start. Start your TitanFile free trial or book a demo to see how a purpose-built secure client portal fits the workflow you already have.

This article is general information, not legal or professional-conduct advice. Consult ethics counsel or a compliance professional in your jurisdiction for guidance on your specific circumstances.