The FTC Safeguards Rule sets specific data security requirements for businesses that handle sensitive consumer financial information, including many accounting and tax preparation firms. For Maryland firms, compliance means more than using secure software or following general cybersecurity best practices. It requires a documented information security program, clearly assigned responsibilities, and specific safeguards for protecting client data.
Understanding whether your firm is covered, what the rule requires, and how those requirements affect your day-to-day operations is the first step toward reducing compliance and security risk.
Who is covered by the FTC Safeguards Rule
The FTC Safeguards Rule applies to businesses that qualify as financial institutions under the Gramm-Leach-Bliley Act. The definition is based on the financial activities a business performs rather than its size, title, or industry label. Tax preparation firms and certain accounting practices can fall within this definition because they routinely collect, process, and store nonpublic financial information.
For Maryland accounting firms, coverage generally depends on the services provided and the type of client information handled. Firms that prepare tax returns, maintain financial records, provide financial advisory services, or perform other covered financial activities may be required to comply with the rule.
Smaller firms are not automatically exempt. Businesses that maintain information on fewer than 5,000 consumers may be exempt from certain specific requirements, but they can still remain subject to the broader Safeguards Rule and its obligation to protect customer information.
What the rule requires
Covered firms must establish and maintain a documented security program that protects customer information through administrative, technical, and physical safeguards. The program should reflect the firm’s size, operational complexity, and the sensitivity of the information it handles.
Key requirements include:
- Designating a Qualified Individual to oversee and enforce the information security program
- Conducting a documented risk assessment to identify where sensitive client information is stored, how it is accessed, and where vulnerabilities may exist
- Using encryption to protect customer information at rest and in transit
- Implementing multi-factor authentication for users who access sensitive systems and data
- Maintaining a written incident response plan that defines how the firm will respond to and recover from a security event
- Providing regular reports to the firm’s governing body or senior leadership on the status and effectiveness of the security program
Breach notification requirements
The FTC Safeguards Rule also requires covered firms to report certain security incidents directly to the Federal Trade Commission. If an incident involves the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers, the firm generally must notify the FTC within 30 days of discovering the event.
This reporting requirement makes incident response an important part of compliance. Accounting firms should have documented procedures for identifying, assessing, and escalating security incidents so they can determine quickly whether a notification is required and meet the applicable reporting deadline.
Why the FTC Safeguards Rule matters beyond compliance
For a small or midsize Maryland accounting firm, the impact of weak data security can extend beyond regulatory penalties. Insurers, referral partners, and clients increasingly expect firms to demonstrate that sensitive financial information is protected through documented policies and established controls.
A well-structured security program can also support professional liability and cyber insurance applications, strengthen relationships with banks, attorneys, and financial advisors, and reinforce client confidence in how their information is handled.
Common signs that a firm may need to strengthen its safeguards include:
- No individual is formally responsible for overseeing information security
- Client files are transferred between devices or cloud platforms without appropriate encryption or access controls
- The firm lacks a written incident response plan outlining what staff should do after a suspected breach
Where NetQuest fits in
Building and documenting a compliant program takes technical work most accounting firms aren't staffed to handle internally: encryption configuration, access control, monitoring, and the ongoing testing the rule requires.
NetQuest works with accounting firms and other financial services firms across Maryland to build that infrastructure. And should the rule and your practice evolve, our experts will also help keep the documentation up to date. Get in touch with us to start the process.


