Since May 13, 2024, the FTC Safeguards Rule has required tax and accounting firms to notify the FTC no later than 30 days after discovering a security breach involving unencrypted information of 500 or more consumers. The IRS layers its own expectations on top, including state attorney general notification. Both duties fall on the same firms that already keep a WISP under IRS Publication 4557.
Key takeaways
The FTC Safeguards breach notification requirement has been in effect since May 13, 2024.
Firms must notify the FTC no later than 30 days after discovering a breach of unencrypted customer information affecting 500 or more consumers.
Unauthorized access to unencrypted data is presumed to be acquisition unless reliable evidence shows otherwise.
The IRS separately expects state attorney general notification, and some states add credit monitoring.
Encrypted data with a protected key does not trigger the FTC report.
Table of Contents
Does the FTC breach notification rule apply to your tax firm?
Yes. Under the FTC Safeguards Rule (16 CFR Part 314), professional tax preparers, CPAs, EAs, and bookkeeping firms count as financial institutions, regardless of size. IRS Publication 4557 makes the same point: the security plan the IRS expects and the safeguards the FTC requires cover the same client data in the same firm.
The Safeguards Rule has covered professional tax preparers for more than two decades. What changed on May 13, 2024 is the duty to tell the FTC when client data is taken. The rule’s definition of a financial institution reaches any business significantly engaged in preparing returns or handling client financial data. A solo EA with one PTIN and a three-office CPA firm sit under the same requirement.
If your firm already keeps a WISP under IRS Publication 4557, none of this starts from zero. IRS Publication 4557 points preparers to the FTC Safeguards Rule by name, and the plan you wrote for the IRS covers the same categories of client information the FTC now expects you to report on. The full rule text lives at 16 CFR Part 314.
What counts as a reportable breach under the Safeguards Rule?
A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. The rule presumes that unauthorized access equals acquisition unless the firm has reliable evidence the data was never taken. Client tax files, which hold Social Security numbers and bank details, are exactly the information the rule protects.
Customer information means any record containing nonpublic personal information: Social Security numbers, income figures, bank and routing numbers, dependents’ details. In a tax practice, that’s the whole client file.
The rule (16 CFR Part 314) sets the threshold at 500 consumers, not 500 clients. A single 1040 file usually covers more than one person once spouses and dependents are counted, so a practice with a few hundred client households can cross the line faster than the raw client count suggests.
The presumption is the part that surprises firm owners. If someone gets into the system where unencrypted returns sit, the rule treats the data as acquired. You’d need reliable evidence that the intrusion stopped at access to rebut that, and most small firms can’t produce it. In practice, unauthorized access to unencrypted client data puts the burden of proof on you.
How long do you have to report a breach to the FTC?
The Safeguards Rule sets the deadline at 30 days from discovery, and it asks firms to report as soon as possible within that window. Discovery means the day the firm learns of the event, not the day the forensic investigation ends. Reports are filed electronically through the FTC’s online form.
The 30-day clock does not pause while you investigate. If your firm discovers ransomware on March 1 and the forensic report arrives in June, the FTC filing was still due by March 31.
The FTC’s notification form asks for the firm’s name and contact information, the types of information involved, the date or date range of the event if you can determine it, and the number of consumers affected. Reported events go into a database the FTC makes public, which is one more reason preparation beats improvisation: the filing itself is short, but every field assumes you already know what happened.
What does the IRS expect after a tax firm data breach?
The IRS asks firms to contact their local IRS Stakeholder Liaison right away so fraudulent returns can be flagged, and to notify state tax agencies. Beyond the IRS, state breach laws add attorney general notification in affected states, and some states require firms to offer credit monitoring to clients.
The IRS data theft page for tax professionals lays out its own track: report to your IRS Stakeholder Liaison immediately so the IRS can flag affected client accounts before fraudulent refunds go out, and alert the state tax agencies where you file.
State obligations run on a third track. Every state has a breach notification law, most route through the state attorney general, and some states require that affected clients be offered credit monitoring. None of these filings satisfies another: telling the FTC does not tell the IRS, and neither one notifies your state. A firm with clients in three states can owe five or more separate notifications from one incident.
What are the breach notification requirements at a glance?
Five facts drive the whole obligation: the trigger is unauthorized acquisition of unencrypted customer information, the threshold is 500 consumers, the clock is 30 days from discovery, the report goes to the FTC, and the IRS layers on liaison contact, state attorney general notice, and credit monitoring in some states.
Requirement
What the rule says
Trigger
Unauthorized acquisition of unencrypted customer information. Unauthorized access is presumed to be acquisition unless reliable evidence shows it stopped at access (16 CFR Part 314).
Threshold
500 or more consumers affected. Consumers, not client households: spouses and dependents count.
Clock
As soon as possible, and no later than 30 days after discovery. Effective May 13, 2024.
Who to notify
The FTC, electronically, through its online reporting form. Reports become part of a public database.
What the IRS adds
IRS Stakeholder Liaison contact, state tax agency alerts, state attorney general notification, and credit monitoring for clients in some states.
Can encryption keep a breach from becoming reportable?
Often, yes. The FTC notification duty attaches to unencrypted customer information. If the data involved was encrypted and the encryption key was not compromised, the event does not meet the rule’s definition of a notification event. That makes encryption the one control that changes what a bad day costs.
The FTC’s own announcement of the requirement draws the line at unencrypted data. Encrypt the client files and protect the keys, and a stolen laptop or an intercepted drive holds ciphertext instead of Social Security numbers.
“I find their security top-notch, providing a reliable service that never goes down, which assures me of consistent performance.”
Ryan H., Owner, Capital Tax & Accounting Inc · G2, Oct 2025
How does Verito help your firm get ahead of these requirements?
Verito builds the controls this rule assumes: VeritShield WISP delivers a custom written security plan designed to support IRS Pub 4557 and FTC Safeguards requirements for $999 per year, VeritGuard adds managed device security from $79 per device per month, and VeritComplete bundles hosting plus IT from $129 per user per month.
Start with the plan, because the rule does. The Safeguards Rule requires a written incident response plan (16 CFR 314.4(h)), which means the 30-day clock should start against a document with names and steps in it, not a blank page. VeritShield WISP is a $999-per-year subscription: a 30-minute scoping call, a custom plan built around your firm’s size, software, and workflow, delivered in 5 business days, with unlimited revisions as your firm changes through the year. You don’t need to be a Verito hosting customer to buy it.
What the rules assume you have
Where firms get it
A written security plan covering IRS Pub 4557 and the FTC Safeguards Rule
VeritShield WISP: $999 per year, delivered in 5 business days, unlimited revisions
Encrypted systems holding client data
Every VeritSpace hosting tier: a dedicated private server with 256-bit encryption, MFA, SOC 2 Type II and ISO 27001 certification
Monitored, protected devices
VeritGuard managed IT: $79, $149, or $199 per device per month, with EDR and device backup on every tier and 24/7 SOC monitoring on Elite
A recurring FTC Safeguards audit
VeritGuard Pro (annual) and Elite (bi-annual), also included at those tiers of VeritComplete
One agreement covering hosting and IT
VeritComplete: $129, $199, or $249 per user per month, with the full WISP included on every tier
For a firm putting all of this in place at once, VeritComplete is the recommendation: hosting and managed IT under one agreement, the complete $999-per-year WISP included at every tier, and a support team that answers in under 60 seconds. It’s the same infrastructure 1,000+ tax and accounting firms already run on, rated 4.9/5 across 170+ G2 reviews.
“I like that Verito meets all the requirements for WISP and is secure to access.”
Karli B., Owner · G2, Jul 2025
The notification requirement rewards firms that did the quiet work early: an encrypted environment, monitored devices, and a current WISP with an incident response plan inside it. If the FTC, the IRS, or your insurance carrier asks, you have an answer.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
Verito ranked #1 in 21 G2 reports this summer across Managed Hosting and Cloud Application Hosting. Here is what the verified customer reviews behind those rankings actually say.
Practice management software runs your firm's clients, projects, deadlines, and time in one place. How to pick the right tool for your firm and host it securely.