- Regulatory expectations are increasing.
- Cyber insurance applications are more demanding.
- Ransomware attacks are targeting professional services firms.
- Clients want proof, not promises, that their information is protected.
- A policy sitting in a shared folder is not a security program.
For law firms, medical practices, and accounting firms, 2026 is the year to move from paper compliance to operational security.
The FTC Safeguards Rule is not automatically applicable to every professional services organization. Coverage depends on the financial activities your business performs. Accounting firms and tax preparers are commonly within scope. A law firm or medical practice may also be covered if it is significantly engaged in activities that are financial in nature, such as consumer financing or certain advisory services.
Even when the FTC Safeguards Rule does not directly apply, the security expectations are still relevant. Law firm cybersecurity, HIPAA compliance, client confidentiality, cyber insurance, and contractual obligations all demand many of the same controls.
Here is what you need to know, and what you should do now.
First: Determine Whether the FTC Safeguards Rule Applies to Your Firm
The Safeguards Rule implements the Gramm-Leach-Bliley Act, or GLBA, for certain non-bank financial institutions. The FTC’s definition is broader than the phrase “financial institution” may suggest.
The question is not simply, “Are we a law firm, medical practice, or accounting firm?”
The better question is:
Does your organization provide services that are financial in nature and handle nonpublic personal information as part of those services?
Accounting firms and tax preparers
Accounting and tax practices are the most likely to fall directly under the Rule. If your firm prepares tax returns, provides financial advisory services, or handles information such as Social Security numbers, income records, bank account details, or investment information, you should evaluate your GLBA obligations carefully.
The FTC specifically identifies tax preparation firms and certain financial advisors as examples of covered financial institutions.
Law firms
A traditional litigation, estate planning, or family law practice may not automatically qualify as a GLBA financial institution merely because it stores client financial information.
However, the analysis can change if your firm provides consumer financial services, operates a financing program, or performs other activities that qualify as financial in nature. Law firms also face significant indirect pressure from clients, insurers, courts, and professional responsibility obligations.
Your clients may require MFA, encryption, endpoint security, logging, incident response, and vendor oversight regardless of whether the FTC Safeguards Rule technically applies.
Medical practices
Most medical practices primarily focus on HIPAA compliance, state privacy laws, and the protection of electronic protected health information. A medical office generally does not become subject to the FTC Safeguards Rule simply because it maintains patient financial information.
The analysis may be different if the practice is significantly engaged in consumer financing, lending, or other financial activities.
When in doubt, ask qualified legal counsel to determine your coverage. Do not rely on a vendor, office manager, or “I got a guy” interpretation of federal law.
What the FTC Safeguards Rule Requires in 2026
The Rule requires covered organizations to develop, implement, and maintain a written information security program appropriate to the organization’s size, complexity, operations, and data sensitivity.
That means a small accounting firm does not necessarily need the same program as a national financial institution. It does need a program that is real, documented, risk-based, and consistently enforced.
The FTC’s official guidance identifies several core elements.
1. Designate a Qualified Individual
Someone must be responsible for implementing and supervising the information security program.
That person may be an internal employee, an affiliate, or a qualified service provider. But outsourcing the work does not eliminate leadership accountability. Your firm still needs a senior individual who understands the program and oversees the relationship.
2. Complete a Written Risk Assessment
You cannot protect information you have not identified.
Your assessment should document:
- What sensitive information you collect
- Where the information is stored
- Who can access it
- How it moves between systems
- Which vendors or applications process it
- What threats could expose, alter, destroy, or misuse it
The assessment should be reviewed periodically and whenever your systems, workforce, vendors, or business operations change.

3. Implement Technical and Administrative Safeguards
The required safeguards should address the risks found in your assessment. Common controls include:
- Multi-factor authentication: Require MFA for email, cloud applications, remote access, administrative accounts, and systems containing customer information.
- Encryption: Encrypt sensitive information at rest and in transit. This includes laptops, mobile devices, cloud storage, backups, and email-based transfers.
- Access controls: Limit access according to job responsibilities. Review permissions regularly, especially after role changes or employee departures.
- Endpoint security: Use modern endpoint detection and response tools to identify suspicious behavior and isolate compromised devices.
- Logging and monitoring: Track access to sensitive information and investigate unusual activity.
- Secure disposal: Establish processes for securely deleting digital information and destroying paper records when retention is no longer required.
- Vulnerability management: Scan systems, remediate known weaknesses, and test your defenses regularly.
- Change management: Evaluate security risks when adding a new application, server, cloud service, device, or network connection.
Traditional antivirus alone is not enough. A firewall alone is not enough. Compliance is not achieved by purchasing a software license and hoping someone checks the dashboard.
Medical Practices Need a Parallel HIPAA Security Strategy
A medical practice may focus primarily on HIPAA compliance rather than GLBA compliance. The operational reality, however, is similar.
Patient records need protection. Access must be limited. Systems must be monitored. Vendors must be evaluated. Employees must know how to respond to suspicious emails, unauthorized requests, and lost devices.
Your medical practice IT strategy should include:
- Encrypted workstations and mobile devices
- MFA for clinical and administrative systems
- Role-based access to electronic health records
- Secure backups and tested restoration procedures
- Business associate and vendor oversight
- Security awareness training
- Documented incident response procedures
- Ongoing IT assessments and vulnerability reviews

HIPAA is not a substitute for cybersecurity. A signed Business Associate Agreement does not secure your network. You need technical enforcement behind the documentation.
4. Create an Incident Response and Business Continuity Plan
The FTC Safeguards Rule requires covered organizations to maintain a written incident response plan.
Your plan should identify:
- Who has authority to declare an incident
- How employees report suspected security events
- How compromised accounts and devices are isolated
- Who communicates with clients, regulators, insurers, and law enforcement
- How evidence is preserved
- How systems are restored
- How lessons learned are incorporated into future improvements
For covered financial institutions, a breach involving the unauthorized acquisition of unencrypted information belonging to at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
Do not wait until a ransomware attack to decide who calls the insurance carrier. Do not discover during an outage that your backup was never tested.
Review this related guide on business continuity and disaster recovery for professional services firms.
5. Train Employees and Manage Your Vendors
Your employees are part of your security architecture.
The “Hey Margaret!” scenario is familiar:
“Hey Margaret, it’s Kevin from IT. I need you to approve this sign-in so I can fix your Microsoft 365 account.”
It sounds routine. It may be an attacker using urgency and authority to bypass your controls.
Security awareness training should cover phishing, business email compromise, vishing, password security, MFA fatigue, physical security, and suspicious payment requests.
Vendor oversight matters just as much. Your managed services provider, software vendors, payroll company, cloud applications, and document platforms may all handle sensitive information. Contracts should define security expectations, access requirements, incident notification responsibilities, and ongoing assessment procedures.

Internal IT vs. a Managed Services Provider
You may be deciding whether to build a larger internal IT department or engage a managed services provider.
Internal IT: Pros and Cons
Pros:
- Direct familiarity with your people and office
- Immediate physical presence
- Internal ownership of day-to-day technology
Cons:
- Hiring and training costs
- Limited coverage during vacations or turnover
- Dependence on one or two individuals
- Difficulty maintaining expertise across cybersecurity, compliance, cloud infrastructure, and disaster recovery
- Higher costs for enterprise-grade monitoring and security tools
Managed IT: Pros and Cons
Pros:
- Predictable monthly costs
- Access to a broader technical team
- Economies of scale on security tools and monitoring
- Proactive maintenance and helpdesk support
- Documented compliance processes
- Strategic planning and vendor management
- Better continuity when a technician is unavailable or leaves
Cons:
- Requires careful provider selection
- Transitioning from informal support may take planning
- Your firm must remain engaged in leadership and oversight
Managed IT is not about giving up control. It is about gaining the expertise, accountability, and operational consistency that a small or mid-sized firm may not be able to build alone.
At A PC of Mind, we help professional services firms build secure, modern technology environments with Microsoft 365, Intune, endpoint protection, identity governance, backup, disaster recovery, and ongoing support.
Your 2026 FTC Safeguards and Cybersecurity Checklist
Start with these five actions:
- Confirm your regulatory obligations with counsel, including whether GLBA, HIPAA, or other requirements apply.
- Schedule an IT assessment to identify sensitive data, outdated systems, excessive permissions, and security gaps.
- Document or update your WISP and assign a Qualified Individual or responsible security leader.
- Verify foundational controls: MFA, encryption, endpoint security, secure backups, logging, patching, and employee training.
- Test your response plan through a tabletop exercise, backup restoration test, vulnerability scan, or independent security review.
A checklist is a starting point. It is not the finished program.
Final Word
The FTC Safeguards Rule is one part of a larger shift in professional services. Regulators, insurers, corporate clients, and patients increasingly expect evidence that your firm can protect sensitive information and continue operating under pressure.
For accounting firms, GLBA compliance may be a direct obligation. For medical practices, HIPAA compliance remains central. For law firms, confidentiality and client-driven security requirements may be equally consequential.
The strategy is the same: identify your risks, enforce practical safeguards, monitor continuously, and maintain a tested plan for recovery.
Do not wait for an audit letter, ransomware event, or client security questionnaire to expose the gaps.
Schedule an IT assessment with A PC of Mind and turn cybersecurity from a recurring problem into a reliable business advantage.
This article is for general informational purposes and is not legal advice. Consult qualified counsel to determine whether the FTC Safeguards Rule or other regulatory requirements apply to your organization.