Direct answer
Every claim is sourced below
Immigration case management software should enforce encryption of data at rest and in transit, administrator-enforced multi-factor authentication with single sign-on, a stated tenant isolation model, role-based permissions with exportable audit logs, geo-redundant backups with a defined recovery point, independent penetration testing, and contractual rights covering data export, deletion, and breach notification [6][7][9]. The bar is set by ABA Model Rule 1.6(c), which requires a lawyer to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client" [1]. Comment 18 makes that a fact-based test in which the sensitivity of the information is the first factor, and an immigration file carries a Social Security number, a passport number, an A-Number, financial history, and the sealed medical examination USCIS requires with an adjustment application [1][4]. Because the duty extends to the vendors a firm hires, ABA Formal Opinion 477R tells lawyers to conduct due diligence on technology vendors under Model Rule 5.3, which means asking every vendor the same written questions and keeping the answers [1]. The risk is documented: in an April 2026 notice to affected individuals, one immigration platform reported that an unauthorized actor used valid credentials to clone third-party repositories, exposing Social Security numbers, passport numbers, and medical condition or treatment information [11].