Skip to main content

← All posts

Stop emailing client files: secure exchange for professional practices

Tax documents and case files still travel as email attachments. Here is how a 5 to 50 person practice standardizes one secure channel without losing clients along the way.

· Jake Schaaf, Founder of Atticus Rowan

A client scans last year’s tax return and emails it to their accountant. A paralegal sends a settlement draft to opposing counsel and copies the client’s personal Gmail. A bookkeeper forwards a payroll register to the owner’s assistant because that is who asked. Multiply that by every engagement in a 5 to 50 person practice and the firm’s most sensitive files are scattered across hundreds of mailboxes the firm does not control.

Email is how professional practices moved files in 2005 and it is still the default in 2026. The problem is not that email gets intercepted in transit. Modern mail is encrypted between servers and interception is genuinely rare. The real failure modes are more ordinary.

Why email is the wrong transport

  • Misaddressing. Autocomplete picks the wrong “Mike” and a tax organizer lands in a stranger’s inbox. There is no recall. The mistake is permanent the moment you hit send.
  • Mailbox compromise. When an attacker phishes their way into one mailbox, they read everything in it. Every attachment ever sent or received is now in their hands, and attackers routinely sit in compromised mailboxes for weeks watching for payment conversations.
  • Retention sprawl. Every attachment exists in the sender’s sent folder, the recipient’s inbox, the phone that syncs it and every forward after that. When a practice later needs to purge a client’s records or respond to discovery, nobody can say where all the copies live. Our post on retention and legal hold covers why that sprawl becomes liability.
  • No access control. Once a file leaves as an attachment, the practice has zero say over what happens next. No expiration, no revocation, no log.

Law firms carry confidentiality duties that make this worse, which we cover in our post on data protection for law firms. Accounting firms have their own regulatory floor. The FTC Safeguards Rule and IRS Publication 4557 both expect controlled handling of client data, and we walk through those expectations in our guide for accounting firms. Email-attachment habits sit poorly against both.

The 3 realistic options

For a practice between 5 and 50 people, the options rank like this.

1. The portal inside your practice management platform. Most modern suites for accounting and legal work include a client portal: document request lists, secure upload, e-signature. If your platform has one, it is almost always the right answer. Clients already know the firm uses the platform, files land attached to the engagement and there is nothing new to buy. The common blocker is not technology. It is that nobody turned the portal on and told clients to use it.

2. Microsoft 365 sharing done properly. If you live in M365, SharePoint and OneDrive links can replace attachments today at no added cost. Done properly means configured, not default:

  • Links restricted to specific people, not “anyone with the link”
  • Expiration on external links, 30 days is a sane default
  • Anonymous editing disabled at the tenant level
  • A dedicated folder structure per client, so sharing happens at the engagement level

The gap in this option is inbound collection. Getting files from clients works through file request links, but the experience is rougher than a purpose-built portal.

3. A dedicated client portal tool. Standalone secure-exchange products typically run $10 to $30 per user per month. They make sense when the practice management platform has no portal and the firm wants a branded, audit-logged exchange experience with document request checklists. Evaluate them like any vendor that will hold client data, with contract terms to match.

Standardize on 1 channel

The failure pattern we see is not choosing a bad tool. It is running 4 channels at once. Some clients use the portal, some email, some text photos of documents, and staff quietly default to whatever the client prefers. The security value comes from standardization, and standardization is a management decision, not a technical one.

  • Pick the channel. One primary way files move in and out of the practice.
  • Put it in the engagement letter. A sentence that says the firm exchanges documents through the portal and does not accept sensitive files by email sets the expectation at signature, when the client is most agreeable.
  • Give staff the script. When a client emails a sensitive file anyway, staff should know the polite move: acknowledge, upload it to the portal themselves and reply with the portal link for next time.
  • Turn off the pressure valve. Once the portal is running, tighten mail flow rules so common sensitive types, like tax forms and account statements, get flagged when they leave as attachments.

The rollout is smaller than most firms fear. Standing up a portal channel and moving active clients onto it typically takes 2 to 4 weeks, most of which is communication rather than configuration. Client pushback is real but short-lived, and it drops sharply when the engagement letter set the expectation up front.

The archive you already have

Moving future exchanges to a portal does not clean up the past. Years of attachments still sit in mailboxes, and that archive deserves 2 decisions rather than a shrug.

First, decide how long email needs to be kept at all, and let a retention policy delete beyond that horizon automatically. Most practices discover their mail retention is “forever by accident,” which maximizes exposure while serving no client. Second, for engagements that are active, pull the working documents out of mail threads and into the client’s folder in the new channel, so the file of record lives where the controls are. This takes an afternoon per active client at most and usually much less.

The related habit worth breaking is the text message channel. Clients photograph documents and text them to whoever they have a number for, and those photos live on personal phones indefinitely. The fix is the same as for email: acknowledge, move the file into the portal and reply from there. Staff should never have to improvise this. Give them the 2-sentence script and the problem shrinks quarter by quarter.

What this buys you

A single controlled channel gives the practice things email can never provide. Access that expires. Sharing that can be revoked when an engagement ends. A log showing who touched what and when. One place to look during a security review or an insurance renewal instead of a firm-wide mailbox archaeology project. And when a client’s information must be produced or purged, the answer lives in one system.

Atticus Rowan helps professional practices pick the right exchange channel for their stack, configure it correctly and write the client-facing rollout so adoption sticks. If your firm’s client files still move as attachments, talk to us and we will map the shortest path off email.