Missing documentation. Unclear ownership. Unmanaged devices. Weak email security. Backups nobody has tested.
That is how many compliance problems begin.
Not with a dramatic hacker in a hoodie. Not with a mysterious server room fire. With a partner who assumes someone else is handling security, an office manager who cannot locate the written policy, or a vendor relationship that was never formally reviewed.
For firms affected by the FTC Safeguards Rule, the question is no longer simply, “Are we secure?”
It is:
Can you prove that your organization identified its risks, implemented reasonable safeguards, monitored those safeguards, and corrected problems when they appeared?
That distinction matters for law firm cybersecurity, medical practice IT, accounting firm IT, and every professional-services organization handling sensitive financial or personal information.
First: Determine Whether the FTC Safeguards Rule Applies
The FTC Safeguards Rule implements portions of the Gramm-Leach-Bliley Act, commonly called GLBA compliance requirements, for certain financial institutions under FTC jurisdiction.
The definition is broader than many business owners expect.
The FTC specifically identifies tax preparation firms and accountants completing income tax returns as financial institutions. An accounting firm that handles Social Security numbers, income records, bank information, investment data, and tax documents should evaluate its obligations carefully.
Law firms and medical offices require a more fact-specific analysis. A law firm is not automatically covered simply because it stores client financial information. A medical practice is not automatically covered merely because it bills patients or maintains insurance records. However, coverage may apply when the organization is significantly engaged in activities that are financial in nature, such as consumer financing, certain financial advisory activities, real-estate settlement work, or other covered services.
Even when the FTC Safeguards Rule does not directly apply, the same controls may still be required by:
- HIPAA and state privacy laws
- Client contracts and security questionnaires
- Cyber-insurance requirements
- Professional confidentiality obligations
- Vendor agreements
- Industry standards and internal risk policies
When in doubt, consult qualified legal counsel. Do not rely on “I got a guy” as your regulatory analysis.
What an FTC Investigation Can Look Like
An FTC investigation is not necessarily a single dramatic visit. It is more likely to begin with a triggering event and expand into a detailed request for evidence.
A practical investigation may involve:
-
A security incident or consumer complaint
A ransomware event. An exposed database. A compromised email account. A complaint from a customer. Public reporting. Or information received from another regulator.
-
A formal information request
The FTC may request documents, written answers, records, or testimony. The request may resemble a Civil Investigative Demand or another formal investigative process.
-
A review of your written security program
Investigators will want to understand whether your organization maintains a written, risk-based information security program. A generic policy downloaded from the internet is not the same as a program designed around your actual systems, people, vendors, and data.
-
A comparison between policy and reality
This is where many organizations become vulnerable.
Your policy says MFA is required. Are all Microsoft 365 accounts protected?
Your policy says laptops are encrypted. Can you produce endpoint reports showing encryption status?
Your policy says access is reviewed. Where are the access-review records?
Your policy says backups are tested. When was the last documented restoration test?
-
A review of accountability
The FTC Safeguards Rule requires a Qualified Individual to oversee and implement the information security program. The organization may use an employee, affiliate, or managed services provider, but leadership responsibility does not disappear when technology is outsourced.
The FTC’s official Safeguards Rule business guidance identifies the core areas investigators and auditors will expect to see: risk assessment, access controls, encryption, MFA, monitoring, testing, training, vendor oversight, incident response, and executive reporting.
Penalty Math: What the Numbers Actually Mean
The maximum civil penalty listed by the FTC for certain violations under Sections 5(l), 5(m)(1)(A), and 5(m)(1)(B) of the FTC Act increased to $53,088 per violation effective January 17, 2025. The FTC confirmed that adjustment in its 2025 civil penalty announcement.
That number requires context.
It does not mean every missing policy automatically produces a $53,088 invoice. Enforcement depends on the legal authority used, the facts of the case, the seriousness and duration of the conduct, cooperation, consumer harm, and other factors.
However, continuing violations can create significant exposure.
For example, a purely hypothetical calculation might look like this:
- Four unresolved violation categories
- $53,088 maximum per violation
- Thirty days of continuing noncompliance
4 × $53,088 × 30 = $6,370,560
That is a mathematical exposure example, not a prediction of what the FTC will seek in a particular matter. The important lesson is that unresolved deficiencies do not remain static. Delayed remediation can increase risk, cost, and scrutiny.
There are also costs beyond civil penalties:
- Attorney fees and regulatory response
- Forensic investigation
- Notification and credit-monitoring expenses
- Emergency technology remediation
- Business interruption
- Lost client confidence
- Increased insurance premiums
- Required third-party assessments
- Long-term compliance reporting
The least expensive time to discover a gap is during a planned IT assessment, not during an investigation.
What a Consent Order Can Require
A consent order is not simply a fine followed by a return to normal operations.
It is a public, enforceable set of instructions governing how your organization must operate going forward.
Depending on the facts, a consent order may require you to:
- Maintain a comprehensive written information security program
- Designate accountable security leadership
- Perform recurring risk assessments
- Implement MFA and encryption
- Improve endpoint security and email security
- Restrict access using least-privilege principles
- Monitor systems and user activity
- Conduct vulnerability assessments or penetration testing
- Train employees and document attendance
- Review service providers and security contracts
- Maintain an incident-response plan
- Test business continuity and disaster recovery
- Submit periodic compliance reports
- Preserve records for regulatory review
- Complete independent security assessments
In other words, the FTC may require you to build the program you should have maintained before the investigation began.
Audit Readiness Means Producing Evidence
A policy document is not proof of compliance.
Think of it like medical care. A physician does not diagnose a patient by glancing at a blank chart and saying, “We probably checked that.” The chart needs symptoms, tests, treatment decisions, follow-up, and documented outcomes.
Your security program needs the same discipline.
You should be able to produce the following without weeks of searching:
-
A current written information security program
It should identify the scope of the program, responsible individuals, safeguards, procedures, and review requirements.
-
A written risk assessment
Document what sensitive data you hold, where it resides, who can access it, what vendors process it, and which threats are most relevant.
-
Evidence of technical controls
Include MFA reports, encryption status, endpoint security records, vulnerability scans, patch reports, backup verification, access reviews, and logging.
-
Qualified Individual oversight
Maintain meeting notes, reports, remediation decisions, leadership briefings, and annual reporting records.
-
Employee training records
Security awareness training should cover phishing, business email compromise, MFA fatigue, suspicious payment requests, lost devices, and incident reporting.
-
Vendor oversight documentation
Maintain a list of service providers, security questionnaires, contracts, security addenda, SOC reports, and periodic reviews.
-
Incident-response and recovery records
Keep the response plan, tabletop exercise results, restoration tests, incident logs, lessons learned, and corrective actions.
-
Change-management records
Adding a new EHR, tax platform, client portal, Microsoft 365 application, or remote-access system can create new risks. Document how those risks were reviewed.

What This Means for Each Professional Sector
Law Firms
Your sensitive information may be spread across email, document-management systems, practice-management platforms, e-discovery tools, client portals, billing systems, and cloud storage.
Law firm cybersecurity requires more than antivirus. You need controlled access to matter files, secure remote work, strong email security, endpoint security, vendor oversight, and a tested response plan.
If a client asks for your security documentation, you should not be assembling it from scratch.
Medical Offices
Medical practice IT must account for EHR systems, billing platforms, patient portals, clearinghouses, medical devices, and business associates.
A signed Business Associate Agreement does not secure your network. Your practice still needs MFA, encryption, role-based access, monitored endpoints, secure backups, ransomware protection, and tested disaster recovery.

Accounting Firms
Accounting firms and tax preparers are directly relevant to the Safeguards Rule because tax preparation is specifically identified as a financial activity.
Your risk increases during tax season, when temporary employees, contractors, remote access, file transfers, and large volumes of taxpayer information converge. Your program should address identity protection, secure portals, Microsoft 365 support, phishing defense, least-privilege access, and documented training.
Internal IT vs. a Managed Services Provider
Building an internal IT team can be the right choice for some organizations.
Potential advantages:
- Direct internal ownership
- Familiarity with business processes
- Immediate onsite support
- More control over daily priorities
Potential drawbacks:
- Hiring and training costs
- Limited coverage during turnover or vacations
- Dependence on one or two individuals
- Difficulty maintaining expertise across compliance, cloud security, endpoint protection, and disaster recovery
- Higher costs for enterprise-grade monitoring tools
A qualified managed services provider can provide broader coverage, predictable costs, economies of scale, proactive monitoring, Microsoft 365 support, endpoint security, business continuity planning, and helpdesk support.
But outsourcing does not eliminate leadership responsibility. Your firm still needs internal oversight and a clear understanding of what the provider does.
At A PC of Mind, we help regulated professional-services organizations build secure, modern environments with Microsoft 365, Intune, identity governance, endpoint protection, backup, disaster recovery, and ongoing support.
Your Audit-Readiness Action Plan
Start with these five steps:
- Confirm whether the FTC Safeguards Rule applies to your activities with qualified counsel.
- Schedule an IT assessment covering users, devices, applications, data, vendors, and access.
- Update your written security program and assign accountable leadership.
- Verify core controls: MFA, encryption, email security, endpoint security, backups, logging, patching, and training.
- Test your response plan with a tabletop exercise and backup restoration test.
Do not wait for the FTC, a ransomware incident, or a client questionnaire to reveal your gaps.
Final Word
Compliance is not a binder. It is not a checkbox. It is not a promise that your “IT guy” says everything is fine.
It is an operating discipline supported by documented decisions, enforced controls, continuous monitoring, and evidence that your organization responds when conditions change.
For accounting firms, GLBA compliance may be a direct obligation. For medical practices and law firms, HIPAA, confidentiality, contractual, and insurance requirements may create similar expectations.
The path forward is clear: assess your environment, correct the weaknesses, document the work, and maintain the program over time.
Schedule an IT assessment with A PC of Mind and turn audit readiness into an ongoing business advantage.
This article is for general informational purposes only and is not legal advice. Consult qualified counsel to determine whether the FTC Safeguards Rule, GLBA, HIPAA, or other regulatory requirements apply to your organization.