Claremont SecurityManaged compliance · Enterprise AI protection
Reference table · notification deadlines

The clocks that start after a breach at a professional firm

A firm that discovers an incident is usually running several clocks at once, and they start on different days. None of them starts on the day of the breach. Four run from the day the firm, or its provider, finds out; the IRS clock runs from the day the incident is confirmed. Every row below was read against the rule itself. HIPAA is not counted here.

5 clocksFTC · SEC · state · IRS
Breach Deadline CalculatorEnter the day your firm found out and get every date below, worked outOpen →
Five clocks, one incidentDay 0 to day 45 · each node is a deadline
++++
Calendarevery day counts, weekends and holidays includedClock hourselapsed time, nights and weekends includedBusiness daya weekday that is not a federal holiday
Day 0 is the day the firm finds out, not the day of the breach, which can sit weeks or months before it. Each clock runs from its own trigger, named under each lane and in the table below. The IRS clock runs from confirmation of the incident, which can come after discovery, and ends the next business day.
// Clock_Table5 clocks
Notice toDeadlineClock starts onCitationExceptions and limits
IRS · e-file IRS, from an Authorized IRS e-file Provider1 business dayafter confirmationConfirmation of the incident, which can come after discovery. Any event that can result in unauthorized disclosure, misuse, modification or destruction of taxpayer information countsIRS Pub 1345 (Rev. 10-2024), ch. 2No exception in the text. A Provider that is an ERO only reports through its local IRS stakeholder liaison. A violation can bring an e-file sanction, up to suspension or expulsion
SEC Regulation S-P Service provider, to the covered institution it serves72 clock hoursBecoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system the provider maintains17 CFR 248.30(a)(5)(i)(B)The rule binds the covered institution: its written policies must be reasonably designed to make its providers notify within 72 hours. The provider’s own duty usually arrives by contract
FTC Safeguards Rule FTC, for a notification event involving 500 or more consumers30 calendar daysDiscovery: the first day the event is known to any employee, officer or other agent, other than the person committing the breach16 CFR 314.4(j)(1), (j)(2); 314.2(m)Not a notification event if the information was encrypted and the key was not accessed by an unauthorized person. Unauthorized access is presumed to be acquisition unless reliable evidence shows otherwise. A law enforcement request can delay public notice of the breach, not the notice to the FTC
SEC Regulation S-P Each affected individual, from a covered institution: a broker-dealer, an investment company, or a registered investment adviser or transfer agent30 calendar daysBecoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred17 CFR 248.30(a)(4)(i), (iii)Not required if, after a reasonable investigation, the institution determines the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. The U.S. Attorney General can delay the notice for national security or public safety
Wisconsin Each person whose personal information was acquired, for a firm based in Wisconsin or holding the data here; each Wisconsin resident, for a firm based elsewhere45 calendar days, at mostLearning of the acquisition of personal information. The notice is due within a reasonable time, not to exceed 45 daysWis. Stat. 134.98(2), (3)(a)Does not apply to a firm subject to, and in compliance with, the GLBA privacy and security requirements that has a breach policy in effect (134.98(3m)). No notice where the acquisition creates no material risk of identity theft or fraud. A law enforcement request can hold the notice, and the clock begins when the hold ends. At 1,000 or more people from one incident, the nationwide consumer reporting agencies are notified too, without unreasonable delay
// Questions6 answers

Questions firms ask about these clocks

Does a breach notification clock start on the day of the breach or the day it is discovered?+

None of the five clocks on this page starts on the day of the breach. The FTC clock starts on discovery: the first day any employee, officer or other agent, other than the person committing the breach, knows of it. The SEC Regulation S-P clocks start when the firm or its service provider becomes aware. Wisconsin’s starts when the firm learns of the acquisition. The IRS reporting standard runs from confirmation of the incident, which can come after discovery.

Are breach notification deadlines counted in calendar days or business days?+

The FTC, SEC Regulation S-P and Wisconsin rules count days, and the SEC service-provider rule counts hours. None of them says business days, and none moves a deadline that lands on a weekend or a holiday. The IRS reporting standard is the exception: Publication 1345 says to report as soon as possible, and no later than the next business day after confirmation of the incident.

When does a CPA firm have to notify the FTC of a data breach?+

When a notification event involves the information of at least 500 consumers, the firm must notify the FTC as soon as possible, and no later than 30 days after discovery, on the electronic form at ftc.gov (16 CFR 314.4(j)). A notification event is the acquisition of unencrypted customer information without the authorization of the person it belongs to. Information counts as unencrypted if the encryption key was accessed by an unauthorized person (16 CFR 314.2(m)).

How fast must a tax preparer report a data breach to the IRS?+

Publication 1345 (Rev. 10-2024) says Authorized IRS e-file Providers “must report security incidents to the IRS as soon as possible but not later than the next business day after confirmation of the incident.” A reportable incident is any event that can result in an unauthorized disclosure, misuse, modification, or destruction of taxpayer information. A Provider that is an ERO only contacts its local IRS stakeholder liaison.

Does Wisconsin’s breach notification law apply to a CPA firm?+

It may not. Wis. Stat. 134.98(3m) says the section does not apply to an entity that is subject to, and in compliance with, the privacy and security requirements of the Gramm-Leach-Bliley Act (15 USC 6801 to 6827), if it has a policy concerning breaches of information security in effect. Whether your firm meets that test is a question for your counsel. Where the section applies, notice is due within a reasonable time, not to exceed 45 days after the firm learns of the acquisition.

What does SEC Regulation S-P require after a breach?+

A covered institution, meaning a broker-dealer, an investment company, or an investment adviser or transfer agent registered with the SEC or another appropriate regulatory agency, must notify each affected individual as soon as practicable, and no later than 30 days after becoming aware of the unauthorized access or use (17 CFR 248.30(a)(4)). Its policies must require its service providers to notify it within 72 hours of becoming aware of a breach of a customer information system they maintain (17 CFR 248.30(a)(5)).

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States