{"id":8026,"date":"2026-08-18T10:17:08","date_gmt":"2026-08-18T14:17:08","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=8026"},"modified":"2026-08-18T10:17:08","modified_gmt":"2026-08-18T14:17:08","slug":"ftc-safeguards-breach-notification-30-day-rule","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/ftc-safeguards-breach-notification-30-day-rule\/","title":{"rendered":"When Does an Accounting Firm Have to Report a Data Breach to the FTC?"},"content":{"rendered":"\n<p><strong>Since May 13, 2024, the FTC Safeguards Rule has required tax and accounting firms to notify the FTC no later than 30 days after discovering a security breach involving unencrypted information of 500 or more consumers. The IRS layers its own expectations on top, including state attorney general notification. Both duties fall on the same firms that already keep a WISP under IRS Publication 4557.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Key takeaways<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The FTC Safeguards breach notification requirement has been in effect since May 13, 2024.<\/li>\n\n\n\n<li>Firms must notify the FTC no later than 30 days after discovering a breach of unencrypted customer information affecting 500 or more consumers.<\/li>\n\n\n\n<li>Unauthorized access to unencrypted data is presumed to be acquisition unless reliable evidence shows otherwise.<\/li>\n\n\n\n<li>The IRS separately expects state attorney general notification, and some states add credit monitoring.<\/li>\n\n\n\n<li>Encrypted data with a protected key does not trigger the FTC report.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#does-the-ftc-breach-notification-rule-apply-to-your-tax-firm\">Does the FTC breach notification rule apply to your tax firm?<\/a><\/li><li><a href=\"#what-counts-as-a-reportable-breach-under-the-safeguards-rule\">What counts as a reportable breach under the Safeguards Rule?<\/a><\/li><li><a href=\"#how-long-do-you-have-to-report-a-breach-to-the-ftc\">How long do you have to report a breach to the FTC?<\/a><\/li><li><a href=\"#what-does-the-irs-expect-after-a-tax-firm-data-breach\">What does the IRS expect after a tax firm data breach?<\/a><\/li><li><a href=\"#what-are-the-breach-notification-requirements-at-a-glance\">What are the breach notification requirements at a glance?<\/a><\/li><li><a href=\"#can-encryption-keep-a-breach-from-becoming-reportable\">Can encryption keep a breach from becoming reportable?<\/a><\/li><li><a href=\"#how-does-verito-help-your-firm-get-ahead-of-these-requirements\">How does Verito help your firm get ahead of these requirements?<\/a><\/li><li><a href=\"#sources\">Sources<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"does-the-ftc-breach-notification-rule-apply-to-your-tax-firm\">Does the FTC breach notification rule apply to your tax firm?<\/h2>\n\n\n\n<p><strong>Yes. Under the FTC Safeguards Rule (16 CFR Part 314), professional tax preparers, CPAs, EAs, and bookkeeping firms count as financial institutions, regardless of size. IRS Publication 4557 makes the same point: the security plan the IRS expects and the safeguards the FTC requires cover the same client data in the same firm.<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/verito.com\/blog\/how-to-comply-with-ftc-safeguards-rule\/\" target=\"_blank\" rel=\"dofollow\" >The Safeguards Rule<\/a> has covered professional tax preparers for more than two decades. What changed on <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">May 13, 2024<\/a> is the duty to tell the FTC when client data is taken. The rule&#8217;s definition of a financial institution reaches any business significantly engaged in preparing returns or handling client financial data. A solo EA with one PTIN and a three-office CPA firm sit under the same requirement.<\/p>\n\n\n\n<p>If your firm already keeps a WISP under <a href=\"https:\/\/verito.com\/blog\/irs-publication-4557-explained\/\" target=\"_blank\" rel=\"dofollow\">IRS Publication 4557<\/a>, none of this starts from zero. <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557<\/a> points preparers to the FTC Safeguards Rule by name, and the plan you wrote for the IRS covers the same categories of client information the FTC now expects you to report on. The full rule text lives at <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR Part 314<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-counts-as-a-reportable-breach-under-the-safeguards-rule\">What counts as a reportable breach under the Safeguards Rule?<\/h2>\n\n\n\n<p><strong>A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. The rule presumes that unauthorized access equals acquisition unless the firm has reliable evidence the data was never taken. Client tax files, which hold Social Security numbers and bank details, are exactly the information the rule protects.<\/strong><\/p>\n\n\n\n<p>Customer information means any record containing nonpublic personal information: Social Security numbers, income figures, bank and routing numbers, dependents&#8217; details. In a tax practice, that&#8217;s <a href=\"https:\/\/verito.com\/blog\/who-owns-your-tax-firm-data\/\" target=\"_blank\" rel=\"dofollow\">the whole client file<\/a>.<\/p>\n\n\n\n<p>The rule (<a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR Part 314<\/a>) sets the threshold at 500 consumers, not 500 clients. A single 1040 file usually covers more than one person once spouses and dependents are counted, so a practice with a few hundred client households can cross the line faster than the raw client count suggests.<\/p>\n\n\n\n<p>The presumption is the part that surprises firm owners. If someone gets into the system where unencrypted returns sit, <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">the rule treats the data as acquired<\/a>. You&#8217;d need reliable evidence that the intrusion stopped at access to rebut that, and most small firms can&#8217;t produce it. In practice, unauthorized access to unencrypted client data puts the burden of proof on you.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-long-do-you-have-to-report-a-breach-to-the-ftc\">How long do you have to report a breach to the FTC?<\/h2>\n\n\n\n<p><strong>The Safeguards Rule sets the deadline at 30 days from discovery, and it asks firms to report as soon as possible within that window. Discovery means the day the firm learns of the event, not the day the forensic investigation ends. Reports are filed electronically through the FTC&#8217;s online form.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-1024x576.jpg\" alt=\"Incident discovery and breach reporting timeline cinematic visual | Verito\" class=\"wp-image-8032\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-deadline.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The 30-day clock does not pause while you investigate. If your firm discovers ransomware on March 1 and the forensic report arrives in June, the FTC filing was still due by March 31.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">FTC&#8217;s notification form<\/a> asks for the firm&#8217;s name and contact information, the types of information involved, the date or date range of the event if you can determine it, and the number of consumers affected. Reported events go into a database the FTC makes public, which is one more reason preparation beats improvisation: the filing itself is short, but every field assumes you already know what happened.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-the-irs-expect-after-a-tax-firm-data-breach\">What does the IRS expect after a tax firm data breach?<\/h2>\n\n\n\n<p><strong>The IRS asks firms to contact their local IRS Stakeholder Liaison right away so fraudulent returns can be flagged, and to notify state tax agencies. Beyond the IRS, state breach laws add attorney general notification in affected states, and some states require firms to offer credit monitoring to clients.<\/strong><\/p>\n\n\n\n<p>The <a href=\"https:\/\/www.irs.gov\/individuals\/data-theft-information-for-tax-professionals\" target=\"_blank\" rel=\"nofollow noopener\">IRS data theft page for tax professionals<\/a> lays out its own track: report to your IRS Stakeholder Liaison immediately so the IRS can flag affected client accounts before fraudulent refunds go out, and alert the state tax agencies where you file.<\/p>\n\n\n\n<p>State obligations run on a third track. Every state has a breach notification law, most route through the state attorney general, and some states require that affected clients be offered credit monitoring. None of these filings satisfies another: telling the FTC does not tell the IRS, and neither one notifies your state. A firm with clients in three states can owe five or more separate notifications from one incident.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-are-the-breach-notification-requirements-at-a-glance\">What are the breach notification requirements at a glance?<\/h2>\n\n\n\n<p><strong>Five facts drive the whole obligation: the trigger is unauthorized acquisition of unencrypted customer information, the threshold is 500 consumers, the clock is 30 days from discovery, the report goes to the FTC, and the IRS layers on liaison contact, state attorney general notice, and credit monitoring in some states.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Requirement<\/strong><\/th><th><strong>What the rule says<\/strong><\/th><\/tr><\/thead><tbody><tr><td><strong>Trigger<\/strong><\/td><td>Unauthorized acquisition of unencrypted customer information. Unauthorized access is presumed to be acquisition unless reliable evidence shows it stopped at access (16 CFR Part 314).<\/td><\/tr><tr><td><strong>Threshold<\/strong><\/td><td>500 or more consumers affected. Consumers, not client households: spouses and dependents count.<\/td><\/tr><tr><td><strong>Clock<\/strong><\/td><td>As soon as possible, and no later than 30 days after discovery. Effective May 13, 2024.<\/td><\/tr><tr><td><strong>Who to notify<\/strong><\/td><td>The FTC, electronically, through its online reporting form. Reports become part of a public database.<\/td><\/tr><tr><td><strong>What the IRS adds<\/strong><\/td><td>IRS Stakeholder Liaison contact, state tax agency alerts, state attorney general notification, and credit monitoring for clients in some states.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"can-encryption-keep-a-breach-from-becoming-reportable\">Can encryption keep a breach from becoming reportable?<\/h2>\n\n\n\n<p><strong>Often, yes. The FTC notification duty attaches to unencrypted customer information. If the data involved was encrypted and the encryption key was not compromised, the event does not meet the rule&#8217;s definition of a notification event. That makes encryption the one control that changes what a bad day costs.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-1024x576.jpg\" alt=\"Encrypted client storage with protected key cinematic visual | Verito\" class=\"wp-image-8034\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/ftc-safeguards-breach-notification-30-day-rule-encryption.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">FTC&#8217;s own announcement<\/a> of the requirement draws the line at unencrypted data. Encrypt the client files and protect the keys, and a stolen laptop or an intercepted drive holds ciphertext instead of Social Security numbers.<\/p>\n\n\n\n<p>The gap in most small firms is where unencrypted copies live: the office server under the desk, laptops that travel, email attachments, the USB drive from the 2019 filing season. Moving client files onto <a href=\"https:\/\/verito.com\/blog\/cybersecurity-for-accounting-firms-guide\/\" target=\"_blank\" rel=\"dofollow\">an encrypted, dedicated private server with 256-bit encryption and MFA<\/a> narrows that surface to one place with one set of controls. Encryption doesn&#8217;t make an incident pleasant, and state rules still vary. <a href=\"https:\/\/verito.com\/blog\/encryption-ftc-breach-notification-tax-firms\/\" target=\"_blank\" rel=\"dofollow\">What it changes under the FTC rule is whether the event meets the definition that starts the 30-day clock<\/a>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;I find their security top-notch, providing a reliable service that never goes down, which assures me of consistent performance.&#8221;<\/em><\/p><cite>Ryan H., Owner, Capital Tax &amp; Accounting Inc \u00b7 G2, Oct 2025<\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-verito-help-your-firm-get-ahead-of-these-requirements\">How does Verito help your firm get ahead of these requirements?<\/h2>\n\n\n\n<p><strong>Verito builds the controls this rule assumes: VeritShield <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/written-information-security-plan\" target=\"_blank\" rel=\"dofollow noopener\" title=\"WISP\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1368\">WISP<\/a> delivers a custom written security plan designed to support IRS Pub 4557 and FTC Safeguards requirements for $999 per year, VeritGuard adds managed device security from $79 per device per month, and VeritComplete bundles hosting plus IT from $129 per user per month.<\/strong><\/p>\n\n\n\n<p>Start with the plan, because the rule does. The Safeguards Rule requires a written incident response plan (16 CFR 314.4(h)), which means the 30-day clock should start against a document with names and steps in it, not a blank page. <a href=\"https:\/\/verito.com\/buy-wisp\" target=\"_blank\" rel=\"dofollow\">VeritShield WISP<\/a> is a $999-per-year subscription: a 30-minute scoping call, a custom plan built around your firm&#8217;s size, software, and workflow, delivered in 5 business days, with unlimited revisions as your firm changes through the year. You don&#8217;t need to be a Verito hosting customer to buy it.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>What the rules assume you have<\/strong><\/th><th><strong>Where firms get it<\/strong><\/th><\/tr><\/thead><tbody><tr><td>A written security plan covering IRS Pub 4557 and the FTC Safeguards Rule<\/td><td>VeritShield WISP: $999 per year, delivered in 5 business days, unlimited revisions<\/td><\/tr><tr><td>Encrypted systems holding client data<\/td><td>Every <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritspace\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritSpace\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1369\">VeritSpace<\/a> hosting tier: a dedicated private server with 256-bit encryption, MFA, SOC 2 Type II and ISO 27001 certification<\/td><\/tr><tr><td>Monitored, protected devices<\/td><td>VeritGuard managed IT: $79, $149, or $199 per device per month, with EDR and device backup on every tier and 24\/7 SOC monitoring on Elite<\/td><\/tr><tr><td>A recurring FTC Safeguards audit<\/td><td>VeritGuard Pro (annual) and Elite (bi-annual), also included at those tiers of <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritcomplete\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritComplete\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1370\">VeritComplete<\/a><\/td><\/tr><tr><td>One agreement covering hosting and IT<\/td><td>VeritComplete: $129, $199, or $249 per user per month, with the full WISP included on every tier<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>For a firm putting all of this in place at once, VeritComplete is the recommendation: hosting and managed IT under one agreement, the complete $999-per-year WISP included at every tier, and a support team that answers in under 60 seconds. It&#8217;s the same infrastructure 1,000+ tax and accounting firms already run on, rated 4.9\/5 across 170+ G2 reviews.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;I like that Verito meets all the requirements for WISP and is secure to access.&#8221;<\/em><\/p><cite>Karli B., Owner \u00b7 G2, Jul 2025<\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p>The notification requirement rewards firms that did the quiet work early: an encrypted environment, monitored devices, and a current <a href=\"https:\/\/verito.com\/blog\/what-is-a-wisp\/\" target=\"_blank\" rel=\"dofollow\">WISP<\/a> with an incident response plan inside it. If the FTC, the IRS, or your insurance carrier asks, you have an answer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"sources\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">FTC: Safeguards Rule notification requirement now in effect<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">FTC Safeguards Rule, 16 CFR Part 314<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.irs.gov\/individuals\/data-theft-information-for-tax-professionals\" target=\"_blank\" rel=\"nofollow noopener\">IRS: Data theft information for tax professionals<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557: Safeguarding Taxpayer Data (PDF)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"Since May 13, 2024, the FTC Safeguards Rule has required tax and accounting firms to notify the FTC&hellip;\n","protected":false},"author":12,"featured_media":8031,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-8026","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=8026"}],"version-history":[{"count":4,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8026\/revisions"}],"predecessor-version":[{"id":8088,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8026\/revisions\/8088"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8031"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=8026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=8026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=8026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}