Sensitive data. Limited staffing. Rising regulatory expectations.
If your firm handles financial information, protected health information, tax records, client funds, or other confidential data, cybersecurity is no longer only an IT concern. It is a business governance issue.
The Federal Trade Commission’s Safeguards Rule, formally found in 16 CFR Part 314, requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program.
That may include your business.
In 2026, law firms, medical practices, accounting firms, tax preparers, financial advisors, and other professional services organizations should be prepared to answer a straightforward question:
Can you demonstrate that your customer information is protected through a documented, operational, and regularly reviewed security program?
A password policy and an antivirus subscription are not enough.
Who Does the FTC Safeguards Rule Apply To?
First, understand the scope.
The Safeguards Rule applies to financial institutions under the FTC’s jurisdiction. The term “financial institution” is broader than a bank. It is based primarily on the activities your business performs: not necessarily the industry name on your website.
The FTC identifies examples such as:
- Tax preparation firms
- Mortgage lenders and brokers
- Finance companies
- Account servicers
- Collection agencies
- Credit counselors
- Financial advisors
- Investment advisors not required to register with the SEC
- Wire transferors
- Check cashers
- Finders that bring buyers and sellers together for financial transactions
Accounting firms
Accounting firms that provide tax preparation or other covered financial services are commonly subject to the Safeguards Rule. If your firm stores clients’ Social Security numbers, financial statements, banking information, investment records, or tax documentation, you should evaluate your obligations carefully with legal counsel.
A firm does not become compliant simply because it has a written “IT policy.” The program must be appropriate to the firm’s size, complexity, activities, and information risks.
Law firms
Law firms are not automatically covered merely because they represent clients in financial matters. However, a firm may fall within the Rule if it is significantly engaged in activities that are financial in nature: for example, certain consumer financial, credit-related, loan-servicing, or investment activities.
Law firms also face professional duties involving confidentiality, client protection, records management, and secure communications. Even if the Safeguards Rule does not apply to your specific practice, its controls provide a useful benchmark for reducing risk.
Medical practices
Medical practices are typically more directly associated with HIPAA, not the FTC Safeguards Rule. However, a medical practice that is significantly engaged in financial activities: such as offering certain consumer financing products: could face overlapping obligations.
The answer depends on what your organization actually does. Have your attorney or compliance advisor determine whether GLBA and the Safeguards Rule apply alongside HIPAA.
The FTC’s Safeguards Rule guidance is a practical starting point, but it is not a substitute for legal advice.
The Core Safeguards Rule Requirements
The Rule requires more than a one-time assessment. It requires a living security program that evolves as your business, technology, and threats change.
1. A written information security program
Your program should explain how your organization protects customer information through administrative, technical, and physical safeguards.
It should address:
- What information you collect
- Where that information is stored
- Who can access it
- How it is transmitted
- How it is backed up
- How it is disposed of
- How incidents are detected and handled
- How vendors are evaluated and monitored
This is often called a Written Information Security Program, or WISP.
A generic template downloaded from the internet is unlikely to reflect your actual environment. Your WISP should match your systems, workflows, people, vendors, and regulatory obligations.
2. A written risk assessment
You cannot protect what you do not understand.
The risk assessment should identify reasonably foreseeable internal and external threats to the confidentiality, security, and integrity of customer information. That includes risks such as:
- Phishing and business email compromise
- Ransomware
- Lost or stolen devices
- Excessive employee access
- Former employee accounts
- Unsecured cloud applications
- Weak vendor controls
- Unpatched software
- Inadequate backups
- Insecure file sharing
- Improper disposal of paper records
The assessment should also document how you evaluated those risks and why your selected safeguards are appropriate.

3. A Qualified Individual
Covered organizations must designate a Qualified Individual to implement and supervise the information security program.
That person may be an internal employee, an affiliate, or a qualified service provider. The Rule does not require a particular job title or degree. It requires practical knowledge appropriate to your environment.
Importantly, outsourcing the role does not outsource responsibility. Your organization remains accountable for its compliance program.
4. Access controls and multi-factor authentication
Access should be based on business need.
A bookkeeper may need access to accounting systems. A receptionist may not. A physician may need access to clinical records. A billing employee may need access to payment information but not every administrative folder.
You should periodically review:
- Who has access to sensitive information
- Whether each person still needs that access
- Whether former employees have been removed
- Whether administrator privileges are limited
- Whether shared accounts still exist
- Whether remote access is secure
The Rule also requires multi-factor authentication, or an equivalent control approved in writing by the Qualified Individual. MFA helps prevent a stolen password from becoming a full system compromise.
Encryption is also required for customer information in transit over external networks and at rest, unless an effective alternative control is approved when encryption is not feasible.
Incident Response and Breach Notification
Hope is not an incident response plan.
The Safeguards Rule requires a written plan that explains what happens when unauthorized access, misuse, or disruption occurs. It should define:
- Response goals
- Internal escalation procedures
- Roles and decision-making authority
- Communication responsibilities
- Containment and recovery steps
- Documentation and reporting requirements
- Post-incident review and corrective action
Beginning in 2024, covered financial institutions must notify the FTC as soon as possible: and no later than 30 days after discovery: of a notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
The FTC’s breach notification guidance explains the reporting requirement and links to the online reporting form.
Your incident plan should also account for cyber insurance, law enforcement, regulators, affected customers, legal counsel, and public communications.

Vendor Management Is Part of Your Compliance Program
“I got a guy.”
That may be a fine way to find a plumber. It is not a vendor management program.
If a cloud provider, payroll company, document management platform, billing vendor, or managed IT provider can access customer information, you need to evaluate that provider’s security practices.
Your contracts should establish security expectations and provide ways to monitor the vendor’s performance. Practical steps include:
- Conducting vendor due diligence before engagement
- Reviewing security documentation and certifications
- Confirming encryption and access controls
- Requiring prompt incident notification
- Including appropriate confidentiality and security terms
- Reassessing vendors periodically
- Removing access when a relationship ends
A vendor’s security failure can become your business problem. Economies of scale are valuable, but accountability still needs to be clearly defined.
How the Safeguards Rule Overlaps With HIPAA, GLBA, and SOC 2
Compliance frameworks often overlap, but they are not interchangeable.
GLBA
The Safeguards Rule is part of the broader Gramm-Leach-Bliley Act framework. GLBA focuses on protecting nonpublic personal financial information and may also require privacy disclosures related to information sharing.
If your organization is covered, the Safeguards Rule provides the security requirements you must operationalize.
HIPAA
HIPAA applies to covered entities and business associates handling protected health information. Its Security Rule also requires risk analysis, administrative safeguards, physical safeguards, technical safeguards, and contingency planning.
Many controls overlap with the Safeguards Rule, including:
- Risk assessments
- Access controls
- Audit logging
- Encryption
- Incident response
- Workforce training
- Vendor oversight
However, HIPAA compliance does not automatically establish Safeguards Rule compliance, and Safeguards Rule compliance does not automatically satisfy HIPAA. If both apply, map the requirements deliberately.
The U.S. Department of Health and Human Services HIPAA Security Rule resources provide additional guidance.
SOC 2
SOC 2 is an independent attestation framework based on the AICPA Trust Services Criteria. It is not a law, and it does not replace regulatory obligations.
A strong SOC 2 program can support Safeguards Rule compliance because both may address security, availability, confidentiality, access management, monitoring, incident response, and vendor controls. But you still need to address Safeguards-specific obligations, including the Qualified Individual, written program, leadership reporting, and applicable FTC breach notifications.
Practical Steps to Take in 2026
Whether you are a law firm, medical office, accounting practice, or another professional services organization, use this sequence:
-
Confirm whether the Rule applies.
Review your business activities with legal counsel. Do not rely on your industry label alone. -
Inventory sensitive information.
Identify customer, patient, tax, financial, and confidential client information. Document where it is collected, stored, transmitted, and deleted. -
Complete a written risk assessment.
Evaluate threats, vulnerabilities, business impact, and existing safeguards. -
Create or update your WISP.
Ensure the program reflects your real environment: not an imaginary organization. -
Enforce identity and access controls.
Implement MFA, least-privilege access, secure remote access, and regular account reviews. -
Verify encryption and backups.
Protect information at rest and in transit. Test backups and document recovery procedures. -
Review vendors and contracts.
Require appropriate safeguards and clear incident notification obligations. -
Build and test your incident response plan.
A tabletop exercise can reveal gaps before a real breach does. -
Train employees.
Your staff are part of your security control system. Teach them how to recognize phishing, report suspicious activity, handle data, and use approved tools. -
Document evidence.
Maintain policies, logs, training records, test results, vendor reviews, access reviews, and leadership reports.
DIY Compliance vs. Managed Cybersecurity
Managing compliance internally can work for organizations with experienced IT and security leadership. You retain direct control, build internal knowledge, and may avoid some external service costs.
The tradeoffs are significant:
- Training and retaining specialized staff is expensive
- Internal teams may lack time for continuous monitoring
- Documentation often becomes outdated
- Employee turnover can create control gaps
- Security tools may be deployed inconsistently
- Incident response experience may be limited
A managed IT and cybersecurity provider brings specialized expertise, standardized processes, monitoring, and economies of scale. The right provider can help translate regulatory requirements into practical controls across Microsoft 365, endpoints, identity, networks, cloud systems, backups, and vendors.
Think of it like medical care. You may be able to treat a minor issue yourself. But for ongoing prevention, diagnostics, and emergency response, a qualified care team is more reliable than waiting until something goes wrong.
A PC of Mind helps organizations assess and strengthen cybersecurity controls, manage technology proactively through managed IT services, and build a more stable, secure technology foundation.
Final Word
FTC Safeguards Rule compliance is not a binder on a shelf. It is an operating discipline.
For accounting and tax firms, coverage is especially important to evaluate. For law firms and medical practices, applicability may depend on the financial activities your organization performs. Regardless of the outcome, the Rule’s core principles: risk-based security, strong access controls, encryption, vendor oversight, incident response, and continuous review: are sound business practices.
Your clients trust you with information they cannot afford to lose.
In 2026, the firms that earn and keep that trust will be the ones that can show: not merely promise: that their security program is documented, tested, monitored, and improving.