The clocks that start after a breach at a professional firm
A firm that discovers an incident is usually running several clocks at once, and they start on different days. None of them starts on the day of the breach. Four run from the day the firm, or its provider, finds out; the IRS clock runs from the day the incident is confirmed. Every row below was read against the rule itself. HIPAA is not counted here.
Breach Deadline CalculatorEnter the day your firm found out and get every date below, worked outOpen →| Notice to | Deadline | Clock starts on | Citation | Exceptions and limits |
|---|---|---|---|---|
| IRS · e-file IRS, from an Authorized IRS e-file Provider | 1 business dayafter confirmation | Confirmation of the incident, which can come after discovery. Any event that can result in unauthorized disclosure, misuse, modification or destruction of taxpayer information counts | IRS Pub 1345 (Rev. 10-2024), ch. 2 | No exception in the text. A Provider that is an ERO only reports through its local IRS stakeholder liaison. A violation can bring an e-file sanction, up to suspension or expulsion |
| SEC Regulation S-P Service provider, to the covered institution it serves | 72 clock hours | Becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system the provider maintains | 17 CFR 248.30(a)(5)(i)(B) | The rule binds the covered institution: its written policies must be reasonably designed to make its providers notify within 72 hours. The provider’s own duty usually arrives by contract |
| FTC Safeguards Rule FTC, for a notification event involving 500 or more consumers | 30 calendar days | Discovery: the first day the event is known to any employee, officer or other agent, other than the person committing the breach | 16 CFR 314.4(j)(1), (j)(2); 314.2(m) | Not a notification event if the information was encrypted and the key was not accessed by an unauthorized person. Unauthorized access is presumed to be acquisition unless reliable evidence shows otherwise. A law enforcement request can delay public notice of the breach, not the notice to the FTC |
| SEC Regulation S-P Each affected individual, from a covered institution: a broker-dealer, an investment company, or a registered investment adviser or transfer agent | 30 calendar days | Becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred | 17 CFR 248.30(a)(4)(i), (iii) | Not required if, after a reasonable investigation, the institution determines the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. The U.S. Attorney General can delay the notice for national security or public safety |
| Wisconsin Each person whose personal information was acquired, for a firm based in Wisconsin or holding the data here; each Wisconsin resident, for a firm based elsewhere | 45 calendar days, at most | Learning of the acquisition of personal information. The notice is due within a reasonable time, not to exceed 45 days | Wis. Stat. 134.98(2), (3)(a) | Does not apply to a firm subject to, and in compliance with, the GLBA privacy and security requirements that has a breach policy in effect (134.98(3m)). No notice where the acquisition creates no material risk of identity theft or fraud. A law enforcement request can hold the notice, and the clock begins when the hold ends. At 1,000 or more people from one incident, the nationwide consumer reporting agencies are notified too, without unreasonable delay |
Questions firms ask about these clocks
Does a breach notification clock start on the day of the breach or the day it is discovered?+
None of the five clocks on this page starts on the day of the breach. The FTC clock starts on discovery: the first day any employee, officer or other agent, other than the person committing the breach, knows of it. The SEC Regulation S-P clocks start when the firm or its service provider becomes aware. Wisconsin’s starts when the firm learns of the acquisition. The IRS reporting standard runs from confirmation of the incident, which can come after discovery.
Are breach notification deadlines counted in calendar days or business days?+
The FTC, SEC Regulation S-P and Wisconsin rules count days, and the SEC service-provider rule counts hours. None of them says business days, and none moves a deadline that lands on a weekend or a holiday. The IRS reporting standard is the exception: Publication 1345 says to report as soon as possible, and no later than the next business day after confirmation of the incident.
When does a CPA firm have to notify the FTC of a data breach?+
When a notification event involves the information of at least 500 consumers, the firm must notify the FTC as soon as possible, and no later than 30 days after discovery, on the electronic form at ftc.gov (16 CFR 314.4(j)). A notification event is the acquisition of unencrypted customer information without the authorization of the person it belongs to. Information counts as unencrypted if the encryption key was accessed by an unauthorized person (16 CFR 314.2(m)).
How fast must a tax preparer report a data breach to the IRS?+
Publication 1345 (Rev. 10-2024) says Authorized IRS e-file Providers “must report security incidents to the IRS as soon as possible but not later than the next business day after confirmation of the incident.” A reportable incident is any event that can result in an unauthorized disclosure, misuse, modification, or destruction of taxpayer information. A Provider that is an ERO only contacts its local IRS stakeholder liaison.
Does Wisconsin’s breach notification law apply to a CPA firm?+
It may not. Wis. Stat. 134.98(3m) says the section does not apply to an entity that is subject to, and in compliance with, the privacy and security requirements of the Gramm-Leach-Bliley Act (15 USC 6801 to 6827), if it has a policy concerning breaches of information security in effect. Whether your firm meets that test is a question for your counsel. Where the section applies, notice is due within a reasonable time, not to exceed 45 days after the firm learns of the acquisition.
What does SEC Regulation S-P require after a breach?+
A covered institution, meaning a broker-dealer, an investment company, or an investment adviser or transfer agent registered with the SEC or another appropriate regulatory agency, must notify each affected individual as soon as practicable, and no later than 30 days after becoming aware of the unauthorized access or use (17 CFR 248.30(a)(4)). Its policies must require its service providers to notify it within 72 hours of becoming aware of a breach of a customer information system they maintain (17 CFR 248.30(a)(5)).
