Data Security
Data security for CPA firms and tax preparers
When you last renewed your PTIN, you checked a box saying you are required by law to keep a written information security plan. Plenty of firms check it, mean it, and then nothing about the way the office actually handles client data changes. We are in Saint Charles, and we set up and run the technical half of that plan for accounting practices across the St. Louis metro.
What the rule actually says
Four things worth knowing before you go looking for a template. Every one is taken from the regulation itself or from the IRS, rather than paraphrased from a vendor blog.
You are a financial institution
That is the sentence the whole obligation hangs on, and it is easy to go years without being told. The Safeguards Rule names you directly. Its list of examples at 16 CFR 314.2 includes "an accountant or other tax preparation service that is in the business of completing income tax returns," so the duty attaches to the work itself rather than to how the firm describes itself.
The plan has to be written down
16 CFR 314.3(a) calls for a security program "written in one or more readily accessible parts." A shared understanding between four people who have worked together for fifteen years is not that, however well it works in practice.
Two controls are named specifically
Encryption of customer information in transit and at rest, and multi-factor authentication for anyone getting into an information system. Both allow a documented alternative signed off by your Qualified Individual, which is a narrower exit than it first reads.
The IRS gives you the template free
Publication 5708 is a fill-in WISP template built for smaller practices, and Publication 4557 is the accompanying guidance. Both are free downloads, and the PTIN form points at them by number. Nobody needs to sell you a template.
The exemption most small firms have never heard of
If your firm holds customer information on fewer than five thousand consumers, 16 CFR 314.6 takes four requirements off the table. It leaves the rest exactly where they were.
What drops away under 5,000
The written risk assessment, the penetration testing and vulnerability assessments, the written incident response plan, and the annual written report to a board or governing body. Those are 314.4(b)(1), (d)(2), (h) and (i), and a small practice is not bound by any of them.
What does not
The written program itself, encryption, multi-factor authentication, access controls, secure disposal, activity logging, oversight of the vendors who touch your data, and staff training. This is the half that gets skipped, and it is the half nobody is excused from.
Counting is not as obvious as it looks
The threshold counts consumers, which the rule defines as individuals who obtained a financial product or service for personal, family or household purposes. That is not the same number as the returns you filed, and retained prior-year files still count while you hold them. Whether your firm sits under the line is a call for you and your own advisers, not for us.
Breach notification applies either way
Since May 2024, 314.4(j) requires telling the FTC within thirty days of discovering a notification event affecting 500 or more consumers. The rule defines that as acquisition of unencrypted customer information without authorization, and the word "unencrypted" is doing a lot of quiet work in it.
Your web vendor is already in your plan
16 CFR 314.4(f) makes the companies handling your data your responsibility to oversee. Your website sits further inside that boundary than it looks, and it's the corner of this topic almost nobody writes about.
Oversight is a named requirement
The rule asks three things of you: take reasonable steps to select and retain providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them against the risk they present. Your host, your DNS, your mail tenant and whoever handles your contact form are all in scope.
The contact form is a real gap
A form on an accounting site invites people to type financial detail into a browser. Where that submission lands, and whether it sat in an unencrypted inbox on the way, is a question your plan is supposed to answer. It usually does not, because nobody asked the person who built the site.
Mail on your domain is in scope too
SPF, DKIM and DMARC on your own domain decide whether someone can send filing-season email that looks like it came from your firm. That is your domain configuration, not your tax software, and it is a place a small practice rarely has anyone assigned.
You need the paperwork, not just the service
Because the obligation is on you, we tell you plainly what we run, where it runs, and what is covered, so you can write an accurate description into your own plan rather than an optimistic one. Your agreement with us documents what we actually operate, which is the part you were going to have to describe anyway.
Where we stop, and where we start
Worth saying plainly, because the line matters more in this vertical than in any other we work in.
We do not write your plan
We do not author your WISP, review it, certify it, or tell you whether your firm complies with anything. That is yours, with your professional bodies and your own counsel if you want them. Any vendor offering to hand you compliance is selling you something they cannot deliver.
We run the systems it describes
A written plan describes real systems, and somebody has to set those up and keep them running. That part is ours: the mail, the accounts and access around it, the hosting, and the domain. We set it up and we run it.
Email on your own domain
Managed Microsoft 365 at $6 per user per month. Mail is where the multi-factor requirement bites first at a small firm, and it is a setting that needs an owner rather than a good intention.
Hosting, domain, and DNS
Your site runs serverless on AWS with an SSL/TLS certificate on every plan, so the public-facing side is not the soft spot. We handle the domain, DNS and renewals end to end, which is one fewer account with a forgotten password on it.
How this usually goes
No scorecard, no compliance report. A conversation, then the technical work.
-
1
1. You download Publication 5708
Free from the IRS, and the right starting point whether or not you ever call us. Working through it tells you what your plan needs to say about your systems, which is the part we can actually help with.
-
2
2. We talk about what you are running now
Where the mail lives, who has a mailbox and what each one can reach, which domain and DNS you are on, and who is hosting the site today. Usually a short call.
-
3
3. We set up the pieces that are ours
Business email on your own domain with the accounts and access configured, hosting with a certificate, and the domain and DNS brought under management. You get to describe real systems in your plan instead of aspirations.
-
4
4. We keep it running
You run the practice through filing season. We keep the mail, the site and the domain working, and you have a local number to call when something needs changing.
Questions CPA firms ask about the Safeguards Rule
If yours is not here, call +1 (636) 362-6221 or email yourfriends@adamsdigital.com and you will reach a person.
Does my tax practice actually need a written information security plan?
If you prepare returns for a fee, the Federal Trade Commission's Safeguards Rule treats your firm as a financial institution, and 16 CFR 314.3(a) requires a security program that is written. It is also the thing you affirmed on your last PTIN renewal: line 11 of Form W-12 (Rev. 10-2025) reads "I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information."
Which law requires a WISP, the IRS or the FTC?
The FTC. The duty comes from the Safeguards Rule at 16 CFR Part 314, which implements the Gramm-Leach-Bliley Act. The IRS reinforces it and gives you the paperwork, but it is not the source of the requirement. Getting this backwards is common, and it matters when someone asks you which rule you are working to.
Is IRS Publication 4557 the rule itself?
No. Publication 4557, "Safeguarding Taxpayer Data," is IRS guidance and recommendations. The enforceable text is the FTC Safeguards Rule. Publication 5708 is the one most small firms are actually looking for: a free fill-in WISP template written for smaller practices.
Where can I get a free WISP template?
From the IRS, at no cost. Publication 5708, "Creating a Written Information Security Plan for your Tax & Accounting Practice," is a fill-in template aimed at small firms, and Publication 4557 is the accompanying guidance. Those are the two the PTIN form itself points you at. Download them first. You do not need to buy a template, and you do not need us to hand you one.
My firm has far fewer than 5,000 clients. Does the Safeguards Rule still apply?
The rule still applies, but four of its requirements drop away. Under 16 CFR 314.6, a firm holding customer information on fewer than five thousand consumers is not bound by 314.4(b)(1), (d)(2), (h) or (i): the written risk assessment, the penetration testing and vulnerability assessments, the written incident response plan, and the annual written report to a governing body. Everything else stands, including the written program itself.
How do I count whether I am under five thousand?
It counts consumers, which 16 CFR 314.2 defines as individuals who obtained a financial product or service for personal, family or household purposes. That is not the same number as the returns you filed or the invoices you raised, and files you retained from prior years still count while you hold them. The arithmetic is less obvious than it looks, and where your firm actually lands is a call for you and your own advisers, not for your web host.
Does the Safeguards Rule require multi-factor authentication?
Yes, at 16 CFR 314.4(c)(5), for any individual accessing any information system. There is one door out of it: your Qualified Individual can approve, in writing, access controls that are reasonably equivalent or more secure. That is narrower than it sounds, and it is not the same as deciding MFA is inconvenient.
Does it require encryption?
Yes. 16 CFR 314.4(c)(3) covers customer information both in transit over external networks and at rest. Where encryption is genuinely infeasible you may use compensating controls instead, again reviewed and approved by your Qualified Individual. For a small firm the practical translation is mail, file transfer and whatever is sitting on the laptop that goes home at night.
Who has to be the Qualified Individual?
16 CFR 314.4(a) requires you to designate someone to oversee and implement the program. At a small firm that is usually a partner rather than a hire. It is a named person inside your practice, not a vendor, and it is not a role we can occupy for you.
What has to happen if my firm has a breach?
Since 13 May 2024, 16 CFR 314.4(j) requires notifying the FTC after a "notification event" affecting at least 500 consumers, as soon as possible and no later than thirty days after you discover it. The rule defines a notification event narrowly, as acquisition of unencrypted customer information without the authorization of the person it belongs to, and it treats information as unencrypted if the key was taken too. State law and your professional obligations sit on top of that. Note what the encryption requirement quietly buys you here.
Does my website host count as a service provider under the FTC Safeguards Rule?
If it handles customer information, yes. 16 CFR 314.4(f) asks you to take reasonable steps to select and retain providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to periodically assess them. That reaches your host, your DNS, your mail tenant and whoever receives your contact form submissions. It's the section of a WISP most likely to sit empty, because nobody ever put the question to the web vendor.
Is my firm's website contact form a compliance problem?
It can be, and it is rarely looked at. A form on an accounting site invites people to type financial detail into a browser, and what matters is where that submission goes and whether it travelled or rested unencrypted on the way. It is a fair question to put to whoever built your site, and if the answer is a shrug, that is your answer.
How often does a WISP need updating?
16 CFR 314.4(g) requires you to evaluate and adjust the program in light of your own testing, and in light of any material change to your operations or business arrangements. In practice that means a plan describing systems you stopped using two seasons ago is not doing its job. Changing web host, moving your mail, or taking on a new practice-management tool are all triggers.
Is it safe to email tax documents to clients?
The rule does not ban it, but 16 CFR 314.4(c)(3) applies to customer information in transit over external networks, so ordinary email with a return attached is exactly the case it has in mind. The regulatory point is simple enough: if the file is not protected in transit, your plan has to explain what is standing in for that. On our side the relevant product is managed Microsoft 365 email on your own domain, which is where those settings live.
Will you write our WISP or tell us whether we comply?
No, and we would be the wrong people to ask. We do not author, review, certify or sign off on your plan, and we do not tell you whether your firm meets the rule. We set up and run the technical pieces your plan has to describe: business email on your own domain, the accounts and access that go with it, hosting with a certificate, and your domain and DNS.
We are a three-person office in St. Charles. Is this aimed at firms our size?
It is written for exactly that. The rule scales its safeguards to your size and complexity, and Publication 5708 exists because the IRS knows most preparers are not large firms. Small does not mean exempt, and the encryption and multi-factor requirements land the same way on three people as on thirty. We are in Saint Charles and work across the St. Louis metro, so this is a conversation you can have with someone local.
Get the technical half sorted
Download Publication 5708 first, it costs nothing. Then, if you want the systems behind it set up and looked after by someone in Saint Charles rather than a support queue somewhere else, send us a note or ring +1 (636) 362-6221. Plan details are on our pricing page, and how we handle security on our own infrastructure is set out in our security policy.