HD Tech - SecurITy Delivered
Back to Blog
Managed IT

CCPA/CPRA Compliance for Orange County Law Firms

By Tom Hermstad · HD Tech

CCPA/CPRA Compliance for Orange County Law Firms

What IT security controls do Orange County law firms need for CCPA/CPRA compliance?

CCPA/CPRA compliance isn't a future project for Orange County law firms — it's a current obligation with real teeth. California's privacy law stacks directly on top of ABA Model Rule 1.6's duty to protect client data. Both demand specific, verifiable controls, not vague policies. This guide maps each obligation to the IT controls your firm needs now, in plain English.


A Firm in Irvine. A Breach. And Nobody Could Find the Incident Response Plan.

I got the call on a Tuesday.

A firm in Irvine had been hit. Someone asked for the incident response plan. Nobody knew where it was. Turns out there wasn't one.

Here's what made that story worse: the firm had someone "handling IT." A generalist — sharp, well-intentioned — but when the regulator asked for a Data Processing Agreement (DPA) and an incident log, neither existed. He'd never been asked to build them. Nobody told him to.

That's the nephew dynamic in a professional-services context. He didn't build an incident response plan because he didn't know he needed to. That's the gap that costs you — and it costs far more than a dedicated IT partner ever would.

I work with manufacturers, law firms, and professional-services companies across Orange County. The discipline is the same across every industry: documented controls, verified outcomes, no assumptions. That's the Plain-English Promise™ — no jargon, no guesswork, no gaps hiding behind vague assurances.

CCPA and its provisions, which became operative January 1, 2020, apply to businesses based on data volume and revenue — not industry. If your firm handles mass tort, employment, or healthcare matters, you almost certainly qualify. The CPRA carries penalties for unintentional violations and up to $7,500 per intentional violation — and violations affecting large numbers of consumers can generate penalties across the full scope of consumers affected.

That math gets painful fast. A breach hitting a large client file database isn't one incident. Under California law, it can generate penalties across every consumer affected.

Meanwhile, ABA Model Rule 1.6(c) and California Bar guidance require "reasonable efforts" to prevent unauthorized access — a standard that has moved well beyond "we have antivirus." California's privacy regime adds consumer rights and enforcement obligations on top of existing confidentiality duties. These rules don't replace each other. They stack.

Firms that get hammered are the ones treating compliance as a checkbox instead of an operating reality.


The Competitive Differentiator Nobody Talks About

Here's something that fires me up every time I talk to a managing partner: firms that invest in documented controls before a breach aren't just protected — they're winning new business because of it.

Corporate clients are asking for your data security protocols. Not someday. Now. Their legal teams, their risk officers, and their insurers want to know how you handle client data before they hand you the engagement letter.

Here's what that looks like in practice:

Firm A gets the question: "Can you share your data security policy and incident response plan?" They say, "We'll get back to you on that." They don't close the deal.

Firm B gets the same question. They hand over a one-page summary: MFA in place, encrypted file storage, vendor agreements current, incident response plan recently tested. The client signs within the week.

Same legal talent. Same rates. Different answer. Different outcome.

Documented IT controls aren't just a liability shield. They're proof you're a serious firm — one that can be trusted with confidential matters and survive scrutiny.

Managed IT isn't a cost center. It's your competitive edge — and in this market, it's the proof that wins the engagement.

Build your controls before the call comes in. Not during. Not after.

Don't be a casualty. Get prepared now, while the cost is a fraction of what cleanup looks like on the other side.


Why Orange County Law Firms Can't Treat CCPA and Bar Rules as Separate Problems

Most firms handle these two frameworks in separate silos. Privacy counsel tracks CCPA. You, as managing partner, assume the IT person handles "security." That gap is exactly how firms get exposed on both fronts at once.


The Real Cost of Waiting — Why "We'll Get to It" Is the Most Expensive Decision You'll Make

Here's the belief I want you to walk away with: waiting costs more than acting.

The longer a threat sits in your environment undetected, the more files are touched, the more consumers are affected, and the higher the penalty count climbs. Breach costs grow with the gap between when a threat enters your environment and when you catch it.

I've worked with firms that put off a security assessment for years because things felt fine. Then a phishing email hit a paralegal's inbox. Credentials got compromised. Suddenly they were trying to scope a breach across a vast accumulation of client files — with no logging in place.

No logs means no answers. No answers means you can't define your notification obligation. An unbounded breach notification is a law firm's worst nightmare — professionally and financially.

Keep paddling. That's my honest advice to any managing partner who knows they have gaps but hasn't moved yet. Don't let the size of the problem freeze you. One control added this week is better than a perfect plan that never starts. Progress beats paralysis — every time.


The Cyber Lifeguard Standard™ Applied to Client-File Security

At HD Tech, we use the Cyber Lifeguard Standard™ to assess how well a firm's controls protect what matters: client confidentiality, data integrity, and the ability to operate after an incident. For Orange County law firms, that means addressing each of the following control areas.

1. Identity and Access Management

Who has access to client files — and how do you prove it?

Multi-factor authentication (MFA) — a second verification step beyond a password — is the baseline. Attorneys, paralegals, and staff accessing client systems should use MFA. That includes Microsoft 365, your practice management platform (Clio, MyCase, iManage), and any remote access tool.

Layer MFA with role-based access controls. A billing coordinator has no business in litigation files. Segment access by matter type and role, then audit those permissions on a schedule.

When a staff member leaves, revoke access the same day — not a week later when someone remembers. If you can't produce an access audit log on demand, you can't prove who touched what. That's a problem before any regulator walks in the door.

2. Encryption — Data at Rest and in Transit

Plain-English Promise™ translation: "encryption at rest" means stored files are scrambled and unreadable without a key. "Encryption in transit" means files moving over the internet can't be intercepted in readable form. Both matter.

California's "reasonable security" standard is benchmarked against CIS Controls and NIST frameworks — both treat encryption as foundational. Client files in Azure, SharePoint, or any cloud platform should be encrypted at rest. Files transmitted externally should be encrypted in transit.

Unencrypted email attachments with case materials are a direct exposure point. "We use the cloud" is not an encryption policy.

Confirm encryption is enabled at the configuration level — not just assumed because your vendor says it's secure. If you've never verified your encryption settings with a written configuration report, you don't actually know they're on.

3. Endpoint Detection and Response — and Why AI Changes the Calculus

This one fires me up — because the threat has shifted faster than most firms realize, and the gap between legacy tools and what attackers are deploying right now is growing by the quarter.

Every laptop, desktop, and mobile device that touches client data is a potential breach point.

Plain-English Promise™ translation: endpoint detection and response (EDR) is software that watches what your devices are doing in real time and flags anything suspicious. Antivirus checks files against a list of known threats. EDR watches behavior. Modern attackers get past antivirus. EDR catches what antivirus misses.

This matters even more now because attackers are using AI too. According to the 2025 Verizon Data Breach Investigations Report, stolen credentials are among the most common initial access vectors in breaches — and AI-powered tools are making those attacks harder to spot, generating messages that are personalized, grammatically flawless, and built to fool even careful people.

Here's the number that should wake up every managing partner: IBM's Cost of a Data Breach Report found the average time to identify and contain a breach was 241 days — roughly eight months a threat can sit in your environment — touching client files, escalating access, growing the scope of your notification obligation — before you know it's there. The window to catch a threat is shrinking, not growing, but the damage done before detection is not.

Waiting another quarter to upgrade your endpoint protection isn't a neutral decision. The threat is accelerating. Legacy antivirus is fighting yesterday's battle. AI-assisted threat detection — built into modern EDR platforms — is what keeps pace.

If your firm is still running standard antivirus and calling it a day, the threat has already lapped you. For firms with remote-working attorneys, this is non-negotiable. An attorney on a home laptop, on an unsecured connection, accessing client files — that's an open door. EDR plus device management policies close it.

This is also where the nephew solution fails hardest. A well-meaning generalist isn't monitoring AI-accelerated threat patterns across your endpoints in real time. A cyber lifeguard is.

4. Vendor and Third-Party Oversight

Your vendors can become your liability. This one fires me up too — not because vendor contracts are glamorous, but because fixing this gap is one of the fastest wins a firm can achieve. It takes discipline, not budget.

Every technology vendor touching client data — cloud storage, e-discovery, billing software, IT support — needs a signed contract governing how your data is handled. Plain-English: that agreement spells out exactly how a vendor protects, uses, and destroys your data.

CPRA added explicit requirements around these agreements, including restrictions on selling or sharing personal information. This is where the "someone handles our IT" model breaks down completely.

If your IT generalist can't hand you a signed vendor contract for every vendor touching client data, you have a documented compliance gap under CPRA. Not a process hiccup — a gap. One unsigned vendor contract is all it takes to turn a containable incident into a regulatory problem.

That's Keep Paddling in practice. Here's your three-step action:

  1. List every vendor currently touching client data.
  2. Pull the signed agreement for each one.
  3. If it doesn't exist, make getting it this week's action — not next quarter's.

Progress beats paralysis here too. Our cybersecurity services for law firms include vendor risk assessment as a standard component.

5. Logging, Monitoring, and Incident Detection

You cannot respond to what you cannot see.

Logging records who accessed what files, when, and from which device. It's both a security control and an evidentiary safeguard.

It's not if, it's when.

When a breach happens, logs let you determine scope, notify clients correctly, and show regulators that reasonable controls were in place. I've seen firms try to scope a breach with no logs. It's like figuring out who was in your building last Tuesday with no security footage. You just don't know.

No logs means no answers. And no answers is the most dangerous place to stand under a breach notification clock.

This is exactly where the Lifeguard Loop™ earns its name. Our Fortify & Future-Proof phase deploys centralized log management and continuous monitoring — so instead of discovering a breach when a client calls, you're getting an alert the moment something looks wrong.

Anomalous access patterns trigger a review. They don't go unnoticed for weeks. That's the Outcome Obsession Framework™ in action: every control maps to a measurable outcome. In this case — the ability to define breach scope, meet notification deadlines, and show regulators documented evidence of reasonable security. Not a vague "we monitor things." A verified, tested result.

Set up centralized log management. Configure alerts for unusual access. This is where many Orange County firms are exposed — and where a true cyber lifeguard earns the title.

6. Documented Incident Response and CCPA Breach Notification

CCPA's private right of action targets organizations that failed to implement "reasonable security procedures and practices." Security breach class actions are already being filed in California using this standard. A documented incident response plan is part of what "reasonable" looks like.

Your plan should cover four things:

  • Who leads the response
  • How notification decisions get made
  • Which breaches trigger CCPA's statutory requirements
  • How the firm preserves evidence

Firms with a documented, tested incident response plan consistently come out better in regulatory inquiries. Firms without one are improvising under pressure — while the clock is running and clients are waiting.

Know what to do before the call comes in. That's the difference between managed recovery and chaos.


How This Maps to the Controls Your Firm Needs Right Now

Here's how every control maps to a real obligation — nothing theoretical, nothing vague.

Control ABA Rule 1.6 Duty CCPA/CPRA Obligation
MFA + access controls Reasonable effort to prevent unauthorized access Part of the "reasonable security" standard benchmarked to CIS Controls and NIST
Encryption at rest + in transit Protecting confidential client information Part of "reasonable security procedures and practices" under Cal. Civ. Code §1798.81.5
EDR on all endpoints Preventing unauthorized disclosure Consistent with "reasonable security" frameworks referenced by the California AG
Vendor contracts (statutory requirements) Supervising third parties with client data Mandatory contractor agreements under CPRA (Cal. Civ. Code §1798.140)
Centralized logging Ability to detect and respond to breaches Evidentiary basis for breach scope
Incident response plan Duty to notify affected clients CCPA notification requirements

This is the framework we apply when our managed IT services for law firms team onboards a new firm. Every control maps to a real obligation. Nothing on this list is theoretical.

One long-standing HD Tech client, Greg Burnight of APC, Curtis & Burnight in Seal Beach, put it directly: "Careful attention to detail, solution-oriented services and implementation and fair pricing. We have worked with HD Tech for a long time now and are extremely satisfied with their professionalism and capabilities."

That kind of relationship is built on showing your work — and on controls that hold up when regulators or opposing counsel come looking.


The threat changes. So do we. If you're a professional-services firm in Orange County managing sensitive data, the same discipline applies — the parallels to client data protection for accounting and CPA firms are direct, and the control framework travels across industries.


Frequently Asked Questions

Here's the short answer: yes, you likely qualify — and this surprises nearly every firm I sit down with. The law applies based on revenue, data volume, or data monetization — not whether you sell records. A mid-size Irvine firm handling mass tort, employment, or healthcare litigation can qualify on revenue alone. Check the full thresholds directly from the California legislature and confirm your numbers today.

It means documented, verifiable steps — not a vague assumption your vendor handled it. The California AG benchmarks this against CIS Controls and the NIST Cybersecurity Framework. See the California AG's guidance here. For law firms, that means MFA, encryption, endpoint protection, vendor oversight, and a tested incident response plan. "We have antivirus" no longer clears the bar.

They stack — and each adds obligations the other doesn't cover. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access. CCPA/CPRA layers on statutory consumer rights, documented technical safeguards, and civil enforcement on top of that. Satisfying one does not satisfy the other. Build one coordinated approach that addresses both at the same time.

The absence of documentation is itself evidence of inadequate security. Affected individuals can sue under CCPA's private right of action — between $100 and $750 per consumer per incident, or actual damages, whichever is greater. State regulators can pursue up to $7,500 per intentional violation. Get controls in place before the call comes in — not after.

Ask three questions and push for real answers, not reassurances. Can your vendor show you a written security policy covering encryption, access controls, and incident response? Do you have signed vendor contracts for every vendor handling client data? Has your firm completed a formal security assessment recently? If any answer is "no" — or "I'll have to check" — that's your gap. Book a Cyber Preparation Assessment and find out exactly where you stand.


Your client files carry attorney-client privilege. Your firm carries CCPA/CPRA compliance liability. The controls that protect one protect the other. Don't wait for a breach to find out which gaps you have.

You built this firm — protect what you've earned.

Book your Cyber Preparation Assessment with HD Tech and walk away knowing exactly where your firm stands — and what needs to close before it matters.

CCPA/CPRA compliance
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.