Verifying accessβ¦
Monay & Associates
π Security & Compliance
β
Active Staff
β
MFA Enabled
β
Active Consents
β
Failed Logins (30d)
π‘οΈ Security Compliance Checklist
Encryption in Transit
TLS 1.3 on all connections
Encryption at Rest
AES-256 database encryption
Audit Logging
All admin actions logged
Role-Based Access
Least-privilege by role
MFA Enforcement
Enable for all staff below
Session Timeout
30-min idle timeout configured
Secure Backups
Daily automated backups
Document Access Controls
Per-client file isolation
SSN Policy
Masked storage β last 4 only
| Name | Role | MFA | Status | Last Login | Actions |
|---|
No staff members yet β add your first team member above.
| Timestamp | User | Action | Entity | Description | IP |
|---|
No audit log entries yet.
| Timestamp | User | Event | Device | IP | Success | Failure Reason |
|---|
No login history yet.
Track all client consents, authorizations, and data sharing agreements.
| Client | Consent Type | Method | Date | Status | Document | Actions |
|---|
No consent records yet.
π Data Retention Policy
Client Files & Case Documents
Engagement letters, correspondence, filings, orders
Financial Records & Invoices
Billing, payments, settlements, trust accounts
Audit Logs
System access logs, login history, admin actions
Consent & Authorization Records
Signed authorizations, HIPAA forms, data-sharing agreements
SSN / Sensitive PII
Only last 4 digits stored; full SSNs never retained
Deleted Record Recovery Window
Soft-deleted records recoverable via database restore
π Download Restrictions
All document downloads are logged with user identity, timestamp, and IP address in the audit log.
Viewers (read-only role) cannot download documents β download access requires Paralegal role or higher.
Bulk exports require Owner or Attorney approval and are logged.
Vendor and third-party access to documents is prohibited without written authorization and is separately logged.
π¨ Breach Response Procedures
In the event of a suspected or confirmed data breach, follow these steps immediately.
Contain (0β1 hour)
Immediately revoke all active sessions, disable affected accounts, and isolate any compromised systems. Do not delete logs.
Assess (1β4 hours)
Determine the scope: what data was accessed, whose records were involved, and how the breach occurred. Review audit logs immediately.
Notify (within 72 hours)
Notify affected clients promptly. For HIPAA-covered data, notify HHS within 60 days. Consult state bar for attorney data breach notification obligations.
Remediate
Patch the vulnerability, rotate all credentials, force MFA enrollment for all staff, and conduct a full security audit.
Document & Review
Document the incident, response timeline, and corrective actions taken. Review policies and update training. Retain documentation for 7 years.
π€ Vendor Access Controls
β’ All third-party vendors must sign a Business Associate Agreement (BAA) before accessing any client data.
β’ Vendor access is role-restricted to minimum necessary data only.
β’ All vendor access sessions are logged in the audit log.
β’ Vendor access must be reviewed and reauthorized quarterly.
β’ Vendor credentials expire automatically after 90 days.
π Emergency Contacts
Add Staff Member
Owner β Full access including delete and security settings
Attorney β Cases, documents, clients, AI tools; no billing delete
Paralegal β Cases, documents, tasks, deadlines; no financial
Admin β Clients, billing, scheduling; no legal work product
Billing β Financial module only
Viewer β Read-only access; no downloads or edits