{"id":8030,"date":"2026-08-20T07:39:00","date_gmt":"2026-08-20T11:39:00","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=8030"},"modified":"2026-08-18T10:18:34","modified_gmt":"2026-08-18T14:18:34","slug":"encryption-ftc-breach-notification-tax-firms","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/encryption-ftc-breach-notification-tax-firms\/","title":{"rendered":"Does Encryption Exempt a Tax Firm From FTC Breach Notification?"},"content":{"rendered":"\n<p><strong>Encryption does not free a tax firm from the FTC Safeguards Rule, but it narrows the duty firm owners ask about most. The FTC must be told within 30 days only when unencrypted customer information tied to at least 500 consumers is taken without authorization. Stolen data that was encrypted, with its key kept safe, does not create that notification event. The firm still reports the theft to the IRS.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Key takeaways<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The FTC trigger: unencrypted customer information of 500 or more consumers, taken without authorization, reported within 30 days of discovery.<\/li>\n\n\n\n<li>Data encrypted with a protected key does not meet that trigger, so its theft alone requires no FTC notice.<\/li>\n\n\n\n<li>If the key was also reached, the data counts as unencrypted and the 30-day clock runs.<\/li>\n\n\n\n<li>The Safeguards Rule requires encryption anyway, and IRS data-theft reporting applies either way.<\/li>\n\n\n\n<li>Every <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/veritspace\" target=\"_blank\" rel=\"dofollow noopener\" title=\"VeritSpace\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1371\">VeritSpace<\/a> tier includes 256-bit encryption at rest and in transit.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#where-does-breach-notification-fit-in-a-tax-firms-wisp\">Where Does Breach Notification Fit in a Tax Firm&#8217;s WISP?<\/a><\/li><li><a href=\"#what-triggers-the-ft-cs-breach-notification-requirement\">What Triggers the FTC&#8217;s Breach Notification Requirement?<\/a><\/li><li><a href=\"#how-does-encryption-change-what-counts-as-a-notification-event\">How Does Encryption Change What Counts as a Notification Event?<\/a><\/li><li><a href=\"#what-do-an-encrypted-and-an-unencrypted-incident-look-like-side-by-side\">What Do an Encrypted and an Unencrypted Incident Look Like Side by Side?<\/a><\/li><li><a href=\"#what-does-a-firm-still-have-to-do-after-an-encrypted-incident\">What Does a Firm Still Have To Do After an Encrypted Incident?<\/a><\/li><li><a href=\"#how-does-a-dedicated-private-server-cover-the-encryption-requirement\">How Does a Dedicated Private Server Cover the Encryption Requirement?<\/a><\/li><li><a href=\"#sources\">Sources<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"where-does-breach-notification-fit-in-a-tax-firms-wisp\">Where Does Breach Notification Fit in a Tax Firm&#8217;s WISP?<\/h2>\n\n\n\n<p><strong>IRS Publication 4557 tells every tax preparer to keep a written plan for handling a data breach, so this duty already lives in your <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/written-information-security-plan\" target=\"_blank\" rel=\"dofollow noopener\" title=\"WISP\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1372\">WISP<\/a>. What changed in May 2024 is the deadline: a notification event under the FTC Safeguards Rule must reach the FTC within 30 days of discovery.<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557<\/a> expects your <a href=\"https:\/\/verito.com\/blog\/what-is-a-wisp\/\" target=\"_blank\" rel=\"dofollow\">written information security plan<\/a> (WISP) to say what the firm does when data is lost or stolen. That part is old. The deadline is new: the <a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">FTC Safeguards Rule notification requirement<\/a> took effect on May 13, 2024. A current WISP names the duty, the person who owns it, and the 30-day clock, all part of ongoing <a href=\"https:\/\/verito.com\/blog\/how-to-comply-with-ftc-safeguards-rule\/\" target=\"_blank\" rel=\"dofollow\">FTC Safeguards Rule compliance<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-triggers-the-ft-cs-breach-notification-requirement\"><span id=\"what-triggers-the-ftcs-breach-notification-requirement\">What Triggers the FTC&#8217;s Breach Notification Requirement?<\/span><\/h2>\n\n\n\n<p><strong>A firm covered by the FTC Safeguards Rule must notify the FTC when unencrypted customer information tied to at least 500 consumers is acquired without authorization. That duty took effect May 13, 2024. The notice is due as soon as possible, and no later than 30 days after the firm discovers the event.<\/strong><\/p>\n\n\n\n<p>Three things have to line up before the duty exists, all set out in <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR Part 314<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Unencrypted customer information.<\/strong> Client data the firm holds for its work, sitting in readable form.<\/li>\n\n\n\n<li><strong>Unauthorized acquisition.<\/strong> Someone took the data. When unencrypted data was accessed, the rule presumes it was taken, unless the firm has reliable evidence it was not.<\/li>\n\n\n\n<li><strong>At least 500 consumers.<\/strong> Below that count, no FTC notice is due. The IRS still wants data theft reported, at any count.<\/li>\n<\/ul>\n\n\n\n<p>The notice includes the firm&#8217;s name and contact information, the types of information involved, the date range if known, the consumer count, and a general description of the event. The clock starts at discovery, the first day the firm knows, under <a href=\"https:\/\/verito.com\/blog\/ftc-safeguards-breach-notification-30-day-rule\/\" target=\"_blank\" rel=\"dofollow\">the FTC&#8217;s 30-day breach notification rule<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-1024x576.jpg\" alt=\"Unencrypted client data breach deadline cinematic visual | Verito\" class=\"wp-image-8039\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-trigger.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-encryption-change-what-counts-as-a-notification-event\">How Does Encryption Change What Counts as a Notification Event?<\/h2>\n\n\n\n<p><strong>The trigger is written around unencrypted customer information. Client data that was encrypted when it was taken does not create a notification event, on one condition: the key must not have been compromised. If the thief reached the key too, the rule treats the data as unencrypted.<\/strong><\/p>\n\n\n\n<p>The definition does the work here. The <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">Safeguards Rule<\/a> defines a notification event as acquisition of unencrypted customer information without authorization. The FTC has said plainly that data counts as unencrypted if the key was reached by an unauthorized person.<\/p>\n\n\n\n<p>Two points keep this precise rather than comforting:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Encryption status is judged at the incident, not on a brochure.<\/strong> A firm leaning on this reading needs proof: which data was encrypted, with what, and where the keys lived. Keep that record in the WISP.<\/li>\n\n\n\n<li><strong>Encryption is not optional under the rule anyway.<\/strong> 16 CFR 314.4 already requires encrypting customer information at rest and in transit, so the narrower trigger comes from doing what the rule asks.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-do-an-encrypted-and-an-unencrypted-incident-look-like-side-by-side\">What Do an Encrypted and an Unencrypted Incident Look Like Side by Side?<\/h2>\n\n\n\n<p><strong>Two firms lose the same laptop or face the same server break-in, and the outcome under 16 CFR Part 314 splits on one fact. Unencrypted client files are presumed taken, which starts the 30-day notice clock. Encrypted files with a protected key never meet the definition of a notification event.<\/strong><\/p>\n\n\n\n<p>Picture the same bad Tuesday twice: an intruder copies a folder of returns for 600 clients, or a laptop full of client files is stolen.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Question<\/strong><\/th><th><strong>Unencrypted files<\/strong><\/th><th><strong>Encrypted files, key protected<\/strong><\/th><\/tr><\/thead><tbody><tr><td>What the thief has<\/td><td>Readable client returns<\/td><td>Scrambled files and no key to read them<\/td><\/tr><tr><td>Is the data presumed taken?<\/td><td>Yes, unless reliable evidence shows it was not<\/td><td>No. The files are not unencrypted customer information, so the presumption never starts<\/td><\/tr><tr><td>FTC notice due?<\/td><td>Yes, at 500 or more consumers, within 30 days of discovery<\/td><td>No, if the review confirms the key stayed safe<\/td><\/tr><tr><td>IRS data theft report<\/td><td>Yes. Call the firm&#8217;s IRS Stakeholder Liaison<\/td><td>Yes. IRS reporting does not turn on encryption<\/td><\/tr><tr><td>Bottom line<\/td><td>The 30-day clock is running<\/td><td>No FTC notice due, and the WISP file shows why<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Which column a firm lands in was decided before the incident, by how the data was stored.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-a-firm-still-have-to-do-after-an-encrypted-incident\">What Does a Firm Still Have To Do After an Encrypted Incident?<\/h2>\n\n\n\n<p><strong>Encryption narrows when a firm must notify the FTC. It does not shrink the incident work. The firm still finds out what was taken, confirms the key stayed safe, writes down the finding, reports the theft to its IRS Stakeholder Liaison, and follows the incident steps in its WISP under IRS Pub 4557.<\/strong><\/p>\n\n\n\n<p>Treat the encrypted case as a full incident with a different last step:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Work the incident itself.<\/strong> Pin down which systems were touched, what data was involved, and the date the firm first knew. Any 30-day clock runs from that discovery date.<\/li>\n\n\n\n<li><strong>Confirm the key really stayed safe.<\/strong> If key material sat next to the data, 16 CFR Part 314 treats the incident as an unencrypted one.<\/li>\n\n\n\n<li><strong>Report the theft to the IRS.<\/strong> The IRS asks preparers to <a href=\"https:\/\/www.irs.gov\/individuals\/data-theft-information-for-tax-professionals\" target=\"_blank\" rel=\"nofollow noopener\">report data theft to their IRS Stakeholder Liaison<\/a> right away, so fake returns can be flagged. State tax agencies get told too. None of that waits on the FTC review.<\/li>\n\n\n\n<li><strong>Write it down in the WISP.<\/strong> A written no-event call, with the proof behind it, is the answer on file if the FTC, the IRS, or an insurer asks later.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-1024x576.jpg\" alt=\"Tax firm incident response after encrypted breach cinematic visual | Verito\" class=\"wp-image-8040\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/08\/encryption-ftc-breach-notification-tax-firms-response.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-does-a-dedicated-private-server-cover-the-encryption-requirement\">How Does a Dedicated Private Server Cover the Encryption Requirement?<\/h2>\n\n\n\n<p><strong>Every VeritSpace plan puts the firm on a dedicated private server with 256-bit encryption at rest and in transit, starting at $69 per user per month. Client files stay encrypted on hardware no other firm shares, so the incident question becomes whether the key stayed safe, not what a thief could read.<\/strong><\/p>\n\n\n\n<p>Encryption at rest and in transit is standard on every VeritSpace tier. Essentials is <a href=\"https:\/\/verito.com\/hosting\/pricing\" target=\"_blank\" rel=\"dofollow\">$69 per user per month<\/a>, Pro is $99 (where UltraTax firms start), and Elite is $149. Every tier also carries MFA, backups four times a day, and a <a href=\"https:\/\/verito.com\/blog\/dedicated-vs-shared-cloud-hosting-what-growing-accounting-firms-should-know\/\" target=\"_blank\" rel=\"dofollow\">dedicated private server<\/a>. The whole setup is SOC 2 Type II and ISO 27001 certified, built to support <a href=\"https:\/\/verito.com\/blog\/irs-publication-4557-explained\/\" target=\"_blank\" rel=\"dofollow\">IRS Pub 4557<\/a> and FTC Safeguards requirements. The encryption item in 16 CFR 314.4 is part of the price, not a project.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;The technical support is always quick to respond and has fixed every issue we have encountered. Excellent communication and I feel very comfortable knowing that our accounting data is secure.&#8221;<\/em><\/p><cite>Kimberly B., Owner, Sheets Sterling, Inc. \u00b7 G2, Mar 2025<\/cite><\/blockquote><\/figure>\n<\/blockquote>\n\n\n\n<p>Office machines still matter. Client files cached on a laptop sit outside the server&#8217;s encryption. Hosting shrinks that surface: working copies stay on the server, not riding around on devices. VeritGuard covers the devices themselves from $79 per device per month (priced per device, not per user), with antivirus, EDR, and device backup. VeritShield WISP writes the plan that records where data lives and how it is encrypted. It costs $999 per year with unlimited revisions, delivered in 5 business days.<\/p>\n\n\n\n<p>For a firm weighing a move, setup on Verito&#8217;s side takes as little as 24 to 48 hours once the firm&#8217;s data is available, typically scheduled over a weekend. Support picks up in under 60 seconds.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"sources\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.ftc.gov\/business-guidance\/blog\/2024\/05\/safeguards-rule-notification-requirement-now-effect\" target=\"_blank\" rel=\"nofollow noopener\">FTC Business Blog: Safeguards Rule notification requirement now in effect (May 2024)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"nofollow noopener\">16 CFR Part 314, Standards for Safeguarding Customer Information (eCFR, current)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\" target=\"_blank\" rel=\"nofollow noopener\">IRS Publication 4557, Safeguarding Taxpayer Data (PDF)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.irs.gov\/individuals\/data-theft-information-for-tax-professionals\" target=\"_blank\" rel=\"nofollow noopener\">IRS: Data Theft Information for Tax Professionals<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"Encryption does not free a tax firm from the FTC Safeguards Rule, but it narrows the duty firm&hellip;\n","protected":false},"author":12,"featured_media":8037,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-8030","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=8030"}],"version-history":[{"count":4,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8030\/revisions"}],"predecessor-version":[{"id":8104,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8030\/revisions\/8104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8037"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=8030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=8030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=8030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}