Skip to main content
Articles

How to Choose an IT Provider for Your Law Firm in Kansas City

Ask any IT company in the metro whether they work with law firms and the answer is yes. Every provider in town has a law firm or two on the books, or wants one, and none of them will talk you out of signing. What separates providers is whether they understand that a law firm's IT problems are ethics problems wearing a technical costume.

I run an IT company, so read this the way you'd read a roofer's guide to hiring roofers. But I also spent more than 20 years in legal technology before starting this business, and every question below works on us too. I'd rather compete on these answers than on who says yes the fastest.

Why a law firm can't hire IT like a normal business

A retail shop that loses a laptop has an inconvenience. A law firm that loses a laptop may have a reportable event, a malpractice question, and a conversation with clients it would rather not have.

Those stakes come straight from the rules of professional conduct. Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorized access to client information. The comment to Rule 1.1 makes keeping up with the benefits and risks of relevant technology part of the duty of competence itself. And ABA Formal Opinion 483 spells out what a lawyer's obligations look like when a breach happens anyway, including when clients have to be told.

Here's the part that matters for choosing a provider: those duties are yours. They don't transfer to your IT provider, the same way you can't outsource a conflicts check. What you can do is hire a provider who builds and runs your systems as if those rules apply, because for your firm, they do. Most providers have never read a word of any of this. The questions below find out fast.

The questions that separate providers

You don't need to be technical to ask these questions, but the pattern of the answers is what you're listening for.

Who at your company can see our client files, and how would we know? In most firms, the IT provider has administrative access to everything: documents, email, the practice management system. That means every technician at the provider is inside your duty of confidentiality. A capable provider can tell you exactly who has access, how it's logged, and what their own staff can and can't see. A provider who's surprised by the question hasn't thought about it, and they already have the keys.

Can you restrict access by matter, not just by person? Screened lawyers, lateral hires with conflicts, a matter where only three people in the firm should ever see the file. Ethical screens are only as real as the file permissions behind them. Ask the provider to describe how they'd wall off a matter in your document system. If the answer is a blank look or "everyone can see everything, it's simpler that way," the screens your firm promises clients are fiction.

What happens on day one of a breach, and who tells whom? Formal Opinion 483 puts obligations on the lawyer when client data is compromised, and breach notification laws add legal clocks on top. You're listening for two things: concrete detection (who's watching, what alerts exist, and whether that's still true at 2 a.m.) and an understanding that at a law firm, the incident response plan has to include the lawyers deciding what to tell clients, not just a technician rebuilding a server. "We'd take a look in the morning" is an answer too. It's just not one you want.

What will you document, and what do we walk away with if we fire you? When a corporate client's security questionnaire arrives, or your malpractice carrier's renewal application asks about safeguards, or opposing counsel challenges how documents were handled, the answer has to exist in writing. Ask what records the provider keeps: who has access to what, what changed and when, where backups go and how often restoring from them is actually tested. Then ask the uncomfortable one: if the relationship ends, what do you hand us? If the documentation lives only in the provider's head, you don't have documentation.

Where does our data physically live, and who else touches it? Backups, email filtering, remote support tools, the practice management platform: each one is a vendor in your chain, and your confidentiality obligations follow the data into every one of them. A capable provider can walk you down that chain without checking notes. A provider who's never mapped it has vendors holding your client files that neither of you has vetted.

Have you ever dealt with a litigation hold? Not because your IT provider runs your discovery, they don't. But a provider who has been through one knows that deleting old data on an automatic schedule, a habit that's good hygiene everywhere else, can destroy evidence at a law firm. You want a provider who asks before purging anything, ever.

Who else do you support that has confidentiality obligations? Not for the name-drop. A provider whose other clients are medical practices, accounting firms, and other law firms is forced by their whole book of business to stay current on this kind of work. A provider whose book is retail and construction relearns it on your dime.

Red flags, stated plainly

Some answers end the conversation:

  • "Everyone in the firm has access to everything, it keeps things simple"
  • No answer for who at the provider can see client files
  • No mention of documentation until you raise it
  • Every question answered with a product name instead of a practice ("we use [tool], so you're covered")
  • An automatic data purge policy nobody can pause
  • Pricing that only makes sense if they never actually monitor anything

That last one deserves an extra note: hourly break-fix pricing means the provider earns money when things break and earns nothing for the quiet monitoring and record-keeping that confidentiality work actually is. The incentives point away from what you're hiring for. Most providers doing this well charge a flat monthly rate per user; the number matters less than whether the model pays them to prevent problems.

The Kansas City part

If your firm is in the metro, ask where the provider's other clients are and whether anyone ever shows up on site. National firms will happily sell you a help desk in another time zone. That can work for some businesses. The risk for a small firm is ending up as nobody's priority: big enough to carry real confidentiality exposure, too small for a national provider to know your name. The right provider is one where your firm is a meaningful client, not a rounding error.

Since this guide asks providers to show their cards: we're based in Shawnee, and Johnson County is our home territory. Our service area is at https://www.tech360solutions.com/service-area/johnson-county if you want to see whether you're in it.

What to do with all this

Pick your top two candidates and put the access, breach, and documentation questions to both in the same week. Take notes. The provider who answers in specifics without referencing a brochure is the one who's done this before.

And if you want to test the theory cheaply first: ask your current provider, today, who on their staff can open your client files, and where that's written down. That answer, or the awkward pause before it, is your starting point.


Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.

See Where Your IT Actually Stands

Free compliance and IT assessment, a $500 value. Actionable findings on where your systems stand and what, if anything, needs attention.

  • Response within 1 business day
  • Written report you can keep
  • Follow-up only if you ask
Book a 15-Minute Call