When Does an Accounting Firm Have to Report a Data Breach to the FTC?

Unprotected tax data requiring breach response cinematic visual | Verito
Summarize and analyze this article with:

Since May 13, 2024, the FTC Safeguards Rule has required tax and accounting firms to notify the FTC no later than 30 days after discovering a security breach involving unencrypted information of 500 or more consumers. The IRS layers its own expectations on top, including state attorney general notification. Both duties fall on the same firms that already keep a WISP under IRS Publication 4557.

Key takeaways

  • The FTC Safeguards breach notification requirement has been in effect since May 13, 2024.
  • Firms must notify the FTC no later than 30 days after discovering a breach of unencrypted customer information affecting 500 or more consumers.
  • Unauthorized access to unencrypted data is presumed to be acquisition unless reliable evidence shows otherwise.
  • The IRS separately expects state attorney general notification, and some states add credit monitoring.
  • Encrypted data with a protected key does not trigger the FTC report.

Does the FTC breach notification rule apply to your tax firm?

Yes. Under the FTC Safeguards Rule (16 CFR Part 314), professional tax preparers, CPAs, EAs, and bookkeeping firms count as financial institutions, regardless of size. IRS Publication 4557 makes the same point: the security plan the IRS expects and the safeguards the FTC requires cover the same client data in the same firm.

The Safeguards Rule has covered professional tax preparers for more than two decades. What changed on May 13, 2024 is the duty to tell the FTC when client data is taken. The rule’s definition of a financial institution reaches any business significantly engaged in preparing returns or handling client financial data. A solo EA with one PTIN and a three-office CPA firm sit under the same requirement.

If your firm already keeps a WISP under IRS Publication 4557, none of this starts from zero. IRS Publication 4557 points preparers to the FTC Safeguards Rule by name, and the plan you wrote for the IRS covers the same categories of client information the FTC now expects you to report on. The full rule text lives at 16 CFR Part 314.

What counts as a reportable breach under the Safeguards Rule?

A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. The rule presumes that unauthorized access equals acquisition unless the firm has reliable evidence the data was never taken. Client tax files, which hold Social Security numbers and bank details, are exactly the information the rule protects.

Customer information means any record containing nonpublic personal information: Social Security numbers, income figures, bank and routing numbers, dependents’ details. In a tax practice, that’s the whole client file.

The rule (16 CFR Part 314) sets the threshold at 500 consumers, not 500 clients. A single 1040 file usually covers more than one person once spouses and dependents are counted, so a practice with a few hundred client households can cross the line faster than the raw client count suggests.

The presumption is the part that surprises firm owners. If someone gets into the system where unencrypted returns sit, the rule treats the data as acquired. You’d need reliable evidence that the intrusion stopped at access to rebut that, and most small firms can’t produce it. In practice, unauthorized access to unencrypted client data puts the burden of proof on you.

How long do you have to report a breach to the FTC?

The Safeguards Rule sets the deadline at 30 days from discovery, and it asks firms to report as soon as possible within that window. Discovery means the day the firm learns of the event, not the day the forensic investigation ends. Reports are filed electronically through the FTC’s online form.

Incident discovery and breach reporting timeline cinematic visual | Verito

The 30-day clock does not pause while you investigate. If your firm discovers ransomware on March 1 and the forensic report arrives in June, the FTC filing was still due by March 31.

The FTC’s notification form asks for the firm’s name and contact information, the types of information involved, the date or date range of the event if you can determine it, and the number of consumers affected. Reported events go into a database the FTC makes public, which is one more reason preparation beats improvisation: the filing itself is short, but every field assumes you already know what happened.

What does the IRS expect after a tax firm data breach?

The IRS asks firms to contact their local IRS Stakeholder Liaison right away so fraudulent returns can be flagged, and to notify state tax agencies. Beyond the IRS, state breach laws add attorney general notification in affected states, and some states require firms to offer credit monitoring to clients.

The IRS data theft page for tax professionals lays out its own track: report to your IRS Stakeholder Liaison immediately so the IRS can flag affected client accounts before fraudulent refunds go out, and alert the state tax agencies where you file.

State obligations run on a third track. Every state has a breach notification law, most route through the state attorney general, and some states require that affected clients be offered credit monitoring. None of these filings satisfies another: telling the FTC does not tell the IRS, and neither one notifies your state. A firm with clients in three states can owe five or more separate notifications from one incident.

What are the breach notification requirements at a glance?

Five facts drive the whole obligation: the trigger is unauthorized acquisition of unencrypted customer information, the threshold is 500 consumers, the clock is 30 days from discovery, the report goes to the FTC, and the IRS layers on liaison contact, state attorney general notice, and credit monitoring in some states.

RequirementWhat the rule says
TriggerUnauthorized acquisition of unencrypted customer information. Unauthorized access is presumed to be acquisition unless reliable evidence shows it stopped at access (16 CFR Part 314).
Threshold500 or more consumers affected. Consumers, not client households: spouses and dependents count.
ClockAs soon as possible, and no later than 30 days after discovery. Effective May 13, 2024.
Who to notifyThe FTC, electronically, through its online reporting form. Reports become part of a public database.
What the IRS addsIRS Stakeholder Liaison contact, state tax agency alerts, state attorney general notification, and credit monitoring for clients in some states.

Can encryption keep a breach from becoming reportable?

Often, yes. The FTC notification duty attaches to unencrypted customer information. If the data involved was encrypted and the encryption key was not compromised, the event does not meet the rule’s definition of a notification event. That makes encryption the one control that changes what a bad day costs.

Encrypted client storage with protected key cinematic visual | Verito

The FTC’s own announcement of the requirement draws the line at unencrypted data. Encrypt the client files and protect the keys, and a stolen laptop or an intercepted drive holds ciphertext instead of Social Security numbers.

The gap in most small firms is where unencrypted copies live: the office server under the desk, laptops that travel, email attachments, the USB drive from the 2019 filing season. Moving client files onto an encrypted, dedicated private server with 256-bit encryption and MFA narrows that surface to one place with one set of controls. Encryption doesn’t make an incident pleasant, and state rules still vary. What it changes under the FTC rule is whether the event meets the definition that starts the 30-day clock.

“I find their security top-notch, providing a reliable service that never goes down, which assures me of consistent performance.”

Ryan H., Owner, Capital Tax & Accounting Inc · G2, Oct 2025

How does Verito help your firm get ahead of these requirements?

Verito builds the controls this rule assumes: VeritShield WISP delivers a custom written security plan designed to support IRS Pub 4557 and FTC Safeguards requirements for $999 per year, VeritGuard adds managed device security from $79 per device per month, and VeritComplete bundles hosting plus IT from $129 per user per month.

Start with the plan, because the rule does. The Safeguards Rule requires a written incident response plan (16 CFR 314.4(h)), which means the 30-day clock should start against a document with names and steps in it, not a blank page. VeritShield WISP is a $999-per-year subscription: a 30-minute scoping call, a custom plan built around your firm’s size, software, and workflow, delivered in 5 business days, with unlimited revisions as your firm changes through the year. You don’t need to be a Verito hosting customer to buy it.

What the rules assume you haveWhere firms get it
A written security plan covering IRS Pub 4557 and the FTC Safeguards RuleVeritShield WISP: $999 per year, delivered in 5 business days, unlimited revisions
Encrypted systems holding client dataEvery VeritSpace hosting tier: a dedicated private server with 256-bit encryption, MFA, SOC 2 Type II and ISO 27001 certification
Monitored, protected devicesVeritGuard managed IT: $79, $149, or $199 per device per month, with EDR and device backup on every tier and 24/7 SOC monitoring on Elite
A recurring FTC Safeguards auditVeritGuard Pro (annual) and Elite (bi-annual), also included at those tiers of VeritComplete
One agreement covering hosting and ITVeritComplete: $129, $199, or $249 per user per month, with the full WISP included on every tier

For a firm putting all of this in place at once, VeritComplete is the recommendation: hosting and managed IT under one agreement, the complete $999-per-year WISP included at every tier, and a support team that answers in under 60 seconds. It’s the same infrastructure 1,000+ tax and accounting firms already run on, rated 4.9/5 across 170+ G2 reviews.

“I like that Verito meets all the requirements for WISP and is secure to access.”

Karli B., Owner · G2, Jul 2025

The notification requirement rewards firms that did the quiet work early: an encrypted environment, monitored devices, and a current WISP with an incident response plan inside it. If the FTC, the IRS, or your insurance carrier asks, you have an answer.

Sources

Want the next step based on this article?
Continue in your favorite AI assistant using this page as the source.
You May Also Like