A CPA firm that loses control of client data faces a harder problem than most business owners realize: figuring out exactly who has to be told, how fast, and under which law. Accounting firms sit at an odd intersection of regulatory regimes. They hold Social Security numbers, bank account details, and tax records for thousands of individuals, which makes them financial institutions in the eyes of federal regulators, even though no one at the firm processes loans or holds deposits. That classification carries real consequences the moment a breach occurs.
The FTC Safeguards Rule lives at 16 CFR Part 314 and implements Section 501(b) of the Gramm-Leach-Bliley Act. The rule defines "financial institution" broadly enough to include tax preparers, accountants, and bookkeepers who handle customers' financial information, regardless of whether the firm considers itself a bank-adjacent business. The FTC has been direct about this scope in its own guidance, noting that covered entities include tax preparation firms, collection agencies, and financial advisors who fall outside the traditional definition of a bank.
Firm size doesn't create an exemption. A three-person tax practice in a strip mall carries the same underlying obligations as a regional firm with hundreds of clients. However, the FTC does scale expectations based on the institution's size and complexity, as well as the sensitivity of the information it holds. What changes with scale is the sophistication of the written information security program a firm needs to maintain, not whether the program is required at all.
The part of the rule that catches firms off guard is the breach reporting requirement added in December 2023 and effective as of May 13, 2024. Under Section 314.4(j), a covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, when a "notification event" occurs. The FTC defines that event narrowly: unauthorized acquisition of unencrypted customer information affecting at least 500 consumers. Encrypted data still counts as unencrypted for this purpose if the attacker also obtains the decryption key, so encryption alone doesn't guarantee an exemption if key management fails.
Thirty days sounds generous until a firm tries to build the internal process backward from that deadline. Discovery must be documented, the scope of the affected records must be assessed, and the report itself must include specific information about what happened. Firms that don't already know how they would detect a breach, let alone document one, tend to discover this gap only once the clock is already running.
The question to ask your firm is this: would your firm actually recognize a reportable incident when it occurs, and could you provide the controls that were in place beforehand? Most firms answer that question honestly only after being asked directly.
Every state and the District of Columbia has its own breach notification statute, and none of them defer automatically to the FTC Safeguards Rule. According to the International Association of Privacy Professionals, California passed the first such law in 2002, and Alabama became the last state to adopt one in 2018, closing out a fifty-state patchwork that businesses now have to navigate simultaneously.
The patchwork isn't uniform. Roughly 20 states specify a hard numeric deadline for consumer notification, typically somewhere between 30 and 60 days. In contrast, the remaining states rely on softer language such as "without unreasonable delay" or "the most expedient time possible," according to a 2026 fifty-state survey from Privacy Rights Clearinghouse. A firm serving clients across three or four states has to satisfy whichever state's deadline is shortest, because state jurisdiction typically attaches based on the affected individual's residency, not the firm's location.
Some states also require notifying more than just the affected people. Pennsylvania's law, for instance, requires written notice and mandates that firms alert nationwide consumer reporting agencies when more than 500 residents are affected, a threshold Pennsylvania lowered from 1,000 to 500 under Act 33 of 2024. Other states require notice to the state attorney general in addition to, or instead of, direct consumer notice. A firm that builds its incident response plan around the FTC's 500-consumer, 30-day standard and stops there is likely to miss at least one state-level obligation the first time an actual breach happens.
The Safeguards Rule doesn't just impose a reporting deadline after the fact. It requires firms to maintain a Written Information Security Program, appoint a Qualified Individual to oversee it, and conduct a periodic risk assessment that documents where sensitive data is stored and how it's protected, according to the FTC's compliance guide for small entities. Nine specific elements make up that program, covering everything from access controls and encryption to employee training and vendor oversight.
The connection between these requirements and breach notification is direct. A firm can't identify a "notification event" within 30 days if it has no monitoring in place to detect unauthorized access. Detection depends on visibility into authentication logs, endpoint activity, and the systems that actually hold customer data. That visibility is one of the nine elements the rule requires firms to document as part of their risk management process. Firms that treat the WISP as a compliance document to file away rather than as an operational plan tend to find out the hard way that the plan doesn't align with what their systems can actually detect.
Scale of exposure matters here too. The IRS reported 870,679 individuals holding active Preparer Tax Identification Numbers as of December 2025. That is the scale of the attack surface across the tax preparation industry. Every one of those PTIN holders is a potential entry point into taxpayer financial data, and attackers know it.
A workable incident response plan starts well before an incident. It names who makes the call on whether an event qualifies as a notification trigger under the FTC rule, who tracks the parallel state-law obligations in every state where the firm has clients, and who drafts the actual notices. Waiting until a breach occurs to figure out these roles guarantees the firm burns through several of its 30 days just assigning responsibility.
Firms that already conduct annual risk assessments have a head start because those assessments should identify which states' residents are represented in the firm's client base and flag the corresponding notification deadlines in advance. Pairing the FTC's federal timeline with a state-by-state reference sheet, reviewed at least once a year as the client roster changes, turns a scramble into a checklist. The firm that has already mapped its obligations is the one that makes the 30-day deadline.
Not sure whether your firm could actually meet the 30-day clock? Schedule a time to chat with our team to work through where you stand and what to fix first.