FTC SAFEGUARDS RULE
Every requirement, covered in one plan.
The FTC Safeguards Rule requires tax preparers, accounting firms and other non-bank financial businesses to protect customer information with a written security program. PurpleCare Secure, at $129 per user per month, includes the safeguards, documents and testing each part of the rule calls for.
| Rule | What it requires | What PurpleCare Secure provides |
|---|---|---|
| 314.4(a)Qualified Individual | Name one person to oversee and run the security program. | We support your Qualified Individual with the security expertise, records and reports the role needs. Your firm designates that person and keeps a senior person overseeing the program, as the rule requires. |
| 314.4(b)Written risk assessment | Assess in writing the risks to customer information, and reassess periodically. | An annual written risk assessment, updated after major changes. |
| 314.4(c)(1)Access controls | Only authorized people can reach customer information, and only what their job needs. | Role-based access reviews, and same-day access removal when someone leaves. |
| 314.4(c)(2)Data and system inventory | Know what data, people, devices and systems you have. | A maintained inventory of your devices, systems and where customer data lives. |
| 314.4(c)(3)Encryption | Encrypt customer information at rest and in transit. | Full-disk encryption on computers, and encrypted email and file transfer. |
| 314.4(c)(5)Multi-factor authentication | MFA for anyone accessing your information systems. | MFA rolled out and enforced for every user. |
| 314.4(c)(6)Secure disposal | Dispose of customer information within two years of last use unless you need it, and review your retention policy. | A retention policy review, and data destruction to NIST SP 800-88 with a certificate for retired drives. |
| 314.4(c)(7)Change management | Have procedures for changes to your systems. | Documented, approved changes to your network, systems and security settings. |
| 314.4(c)(8)Monitoring and logging | Monitor and log user activity to detect unauthorized access. | Endpoint detection and response with security event logging on every workstation. |
| 314.4(d)Testing | Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. | Included: vulnerability scans every 6 months. When the rule requires it or your cyber insurer asks, an annual external penetration test for $4,000 per test, quoted before it is scheduled. |
| 314.4(e)Training | Security awareness training for staff, and qualified security personnel. | Monthly phishing simulations and security awareness training, delivered and tracked by us. |
| 314.4(f)Service provider oversight | Choose capable vendors, require safeguards by contract, and check on them. | Help listing, assessing and documenting the vendors who handle your customer data. |
| 314.4(g)Evaluate and adjust | Update the program after testing, changes or new risks. | The program and documents are updated after every assessment, test or incident. |
| 314.4(h)Incident response plan | A written plan for responding to a security event. | A written incident response plan, and we lead the technical response if something happens. |
| 314.4(i)Annual report | The Qualified Individual reports in writing to the owner or board at least once a year. | A written annual report to your owner or board. |
| 314.4(j)FTC notification | Notify the FTC within 30 days of discovering an event involving 500 or more consumers. | Help preparing and filing the FTC notice. |
Good to know
- Your firm stays responsible. Under the rule, compliance belongs to your business. Secure gives you the safeguards, the written documents and the records that show the program is working.
- Smaller firms are exempt from four parts. Firms with information on fewer than 5,000 consumers don't have to meet 314.4(b)(1), (d)(2), (h) or (i). We include them anyway, because cyber insurers and clients ask for the same things.
- Tax professionals have an IRS requirement too. The IRS expects every paid preparer to keep a written information security plan (WISP). The plan we write for you is built to satisfy both.
This page summarizes 16 CFR Part 314 in plain language. It isn't legal advice; talk with your attorney about how the rule applies to your firm.
Get Safeguards-ready without the guesswork.
Start with the free 21-Point Office IT Review. We'll show you which parts of the rule you already meet and what's missing, in plain English.
Already a client? Call the support line, email support@purplebunny.tech or open a ticket at purple.repair.