Encryption does not free a tax firm from the FTC Safeguards Rule, but it narrows the duty firm owners ask about most. The FTC must be told within 30 days only when unencrypted customer information tied to at least 500 consumers is taken without authorization. Stolen data that was encrypted, with its key kept safe, does not create that notification event. The firm still reports the theft to the IRS.
Key takeaways
The FTC trigger: unencrypted customer information of 500 or more consumers, taken without authorization, reported within 30 days of discovery.
Data encrypted with a protected key does not meet that trigger, so its theft alone requires no FTC notice.
If the key was also reached, the data counts as unencrypted and the 30-day clock runs.
The Safeguards Rule requires encryption anyway, and IRS data-theft reporting applies either way.
Every VeritSpace tier includes 256-bit encryption at rest and in transit.
Table of Contents
Where Does Breach Notification Fit in a Tax Firm’s WISP?
IRS Publication 4557 tells every tax preparer to keep a written plan for handling a data breach, so this duty already lives in your WISP. What changed in May 2024 is the deadline: a notification event under the FTC Safeguards Rule must reach the FTC within 30 days of discovery.
What Triggers the FTC’s Breach Notification Requirement?
A firm covered by the FTC Safeguards Rule must notify the FTC when unencrypted customer information tied to at least 500 consumers is acquired without authorization. That duty took effect May 13, 2024. The notice is due as soon as possible, and no later than 30 days after the firm discovers the event.
Three things have to line up before the duty exists, all set out in 16 CFR Part 314:
Unencrypted customer information. Client data the firm holds for its work, sitting in readable form.
Unauthorized acquisition. Someone took the data. When unencrypted data was accessed, the rule presumes it was taken, unless the firm has reliable evidence it was not.
At least 500 consumers. Below that count, no FTC notice is due. The IRS still wants data theft reported, at any count.
The notice includes the firm’s name and contact information, the types of information involved, the date range if known, the consumer count, and a general description of the event. The clock starts at discovery, the first day the firm knows, under the FTC’s 30-day breach notification rule.
How Does Encryption Change What Counts as a Notification Event?
The trigger is written around unencrypted customer information. Client data that was encrypted when it was taken does not create a notification event, on one condition: the key must not have been compromised. If the thief reached the key too, the rule treats the data as unencrypted.
The definition does the work here. The Safeguards Rule defines a notification event as acquisition of unencrypted customer information without authorization. The FTC has said plainly that data counts as unencrypted if the key was reached by an unauthorized person.
Two points keep this precise rather than comforting:
Encryption status is judged at the incident, not on a brochure. A firm leaning on this reading needs proof: which data was encrypted, with what, and where the keys lived. Keep that record in the WISP.
Encryption is not optional under the rule anyway. 16 CFR 314.4 already requires encrypting customer information at rest and in transit, so the narrower trigger comes from doing what the rule asks.
What Do an Encrypted and an Unencrypted Incident Look Like Side by Side?
Two firms lose the same laptop or face the same server break-in, and the outcome under 16 CFR Part 314 splits on one fact. Unencrypted client files are presumed taken, which starts the 30-day notice clock. Encrypted files with a protected key never meet the definition of a notification event.
Picture the same bad Tuesday twice: an intruder copies a folder of returns for 600 clients, or a laptop full of client files is stolen.
Question
Unencrypted files
Encrypted files, key protected
What the thief has
Readable client returns
Scrambled files and no key to read them
Is the data presumed taken?
Yes, unless reliable evidence shows it was not
No. The files are not unencrypted customer information, so the presumption never starts
FTC notice due?
Yes, at 500 or more consumers, within 30 days of discovery
No, if the review confirms the key stayed safe
IRS data theft report
Yes. Call the firm’s IRS Stakeholder Liaison
Yes. IRS reporting does not turn on encryption
Bottom line
The 30-day clock is running
No FTC notice due, and the WISP file shows why
Which column a firm lands in was decided before the incident, by how the data was stored.
What Does a Firm Still Have To Do After an Encrypted Incident?
Encryption narrows when a firm must notify the FTC. It does not shrink the incident work. The firm still finds out what was taken, confirms the key stayed safe, writes down the finding, reports the theft to its IRS Stakeholder Liaison, and follows the incident steps in its WISP under IRS Pub 4557.
Treat the encrypted case as a full incident with a different last step:
Work the incident itself. Pin down which systems were touched, what data was involved, and the date the firm first knew. Any 30-day clock runs from that discovery date.
Confirm the key really stayed safe. If key material sat next to the data, 16 CFR Part 314 treats the incident as an unencrypted one.
Report the theft to the IRS. The IRS asks preparers to report data theft to their IRS Stakeholder Liaison right away, so fake returns can be flagged. State tax agencies get told too. None of that waits on the FTC review.
Write it down in the WISP. A written no-event call, with the proof behind it, is the answer on file if the FTC, the IRS, or an insurer asks later.
How Does a Dedicated Private Server Cover the Encryption Requirement?
Every VeritSpace plan puts the firm on a dedicated private server with 256-bit encryption at rest and in transit, starting at $69 per user per month. Client files stay encrypted on hardware no other firm shares, so the incident question becomes whether the key stayed safe, not what a thief could read.
Encryption at rest and in transit is standard on every VeritSpace tier. Essentials is $69 per user per month, Pro is $99 (where UltraTax firms start), and Elite is $149. Every tier also carries MFA, backups four times a day, and a dedicated private server. The whole setup is SOC 2 Type II and ISO 27001 certified, built to support IRS Pub 4557 and FTC Safeguards requirements. The encryption item in 16 CFR 314.4 is part of the price, not a project.
“The technical support is always quick to respond and has fixed every issue we have encountered. Excellent communication and I feel very comfortable knowing that our accounting data is secure.”
Kimberly B., Owner, Sheets Sterling, Inc. · G2, Mar 2025
Office machines still matter. Client files cached on a laptop sit outside the server’s encryption. Hosting shrinks that surface: working copies stay on the server, not riding around on devices. VeritGuard covers the devices themselves from $79 per device per month (priced per device, not per user), with antivirus, EDR, and device backup. VeritShield WISP writes the plan that records where data lives and how it is encrypted. It costs $999 per year with unlimited revisions, delivered in 5 business days.
For a firm weighing a move, setup on Verito’s side takes as little as 24 to 48 hours once the firm’s data is available, typically scheduled over a weekend. Support picks up in under 60 seconds.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.