Cybersecurity

Data Breach Steps for a Texas CPA Firm: FTC, Texas AG and IRS Deadlines

Data Breach Steps for a Texas CPA Firm: FTC, Texas AG and IRS Deadlines

What Does a Texas CPA Firm Have to Do After a Data Breach?

A Texas CPA firm that loses client data has several clocks running at once. The Texas Attorney General must be told within 30 days if 250 or more Texans are affected, clients must be notified within 60 days, and the FTC must be told within 30 days if a breach reaches 500 or more consumers' unencrypted information. The IRS also asks tax professionals to report client data theft to their local Stakeholder Liaison.

Call your attorney and your cyber insurer early, since both will shape how you handle the rest.

The deadlines at a glance
Who Trigger Deadline
Affected individuals (Texas law) A breach of system security involving sensitive personal information Without unreasonable delay, no later than the 60th day after you determine a breach occurred
Texas Attorney General Breach affecting 250 or more Texas residents No later than the 30th day after you determine the breach occurred
FTC (Safeguards Rule) Unauthorized acquisition of unencrypted customer information of 500 or more consumers As soon as possible, no later than 30 days after discovery
IRS Stakeholder Liaison Client data theft The IRS says to report it, with no fixed number of days stated on its guidance page

Law enforcement can ask you to delay notification if it would impede a criminal investigation. Notice is due once the delay is no longer needed.

Step by step

  1. Contain it. Isolate affected computers and accounts. Change passwords and revoke access. Do not wipe systems before someone has preserved the evidence.

  2. Call your insurer and hire an expert. The IRS advises contacting your insurance company to report the breach and to check whether your policy covers breach costs, and hiring a security expert to work out the scope.

  3. Contact the IRS. Report the client data theft to your local IRS Stakeholder Liaison, who will notify IRS Criminal Investigation.

  4. Contact law enforcement. The IRS guidance names your local FBI office and says to file a police report. Coordinate the timing of client letters with law enforcement.

  5. Notify the Texas Attorney General if 250 or more Texans are affected. Texas requires the report to be filed electronically through the Attorney General's data breach webform. The report must state how many Texans you have notified by mail or email.

  6. Notify the FTC if 500 or more consumers are affected. File through the form on the FTC website. The notice covers your firm's contact details, the types of information involved, the date range if known, the number of consumers, a general description of the event and any law enforcement determination about delaying public notice.

  7. Notify state tax agencies. The IRS directs tax professionals to contact state tax agencies through the Federation of Tax Administrators. It also says to check whether you must contact the attorney general in each state where you prepare returns.

  8. Send letters to affected clients. The IRS advises sending an individual letter to every victim while working with law enforcement on timing. Also tell the credit bureaus (Equifax, Experian and TransUnion) so your clients can get their services.

  9. Document everything. Keep a timeline of what you found, when, and what you did. You will need it for the reports and for your insurer.

What makes this easier

The firms that handle a breach best did the work before it happened.

A written incident response plan. The Safeguards Rule requires one in writing, except for firms with customer information on fewer than 5,000 consumers. Even if you are exempt, a plan is the fastest way to know who does what.

Encryption. The FTC's notification trigger is unauthorized acquisition of unencrypted customer information. Encrypted data lowers your exposure.

Backups you can restore from. If ransomware locks the office in February, restoring from a clean backup is the difference between days and weeks.

Logs and monitoring. You cannot report what you cannot see. Endpoint monitoring and logging help establish what was accessed.

Client data inventory. Know how many clients you hold data for and where it lives. The 250 and 500 thresholds require you to count.

Where to start today

Write your call list: your attorney, your insurer, your IT provider, your local IRS Stakeholder Liaison and the FBI field office. Put it somewhere that does not depend on your firm's network being up.

This post is general information and not legal advice. Talk to your attorney about your specific obligations.

safemode IT is a managed IT and cybersecurity provider based in Kyle, Texas. We support CPA firms and other small businesses along the I-35 corridor, from Bastrop and Austin to Buda and San Marcos. To build your incident plan before you need it, call 512-761-7652 or visit safemodeit.com.

Sources
Texas Business and Commerce Code, Section 521.053
Texas Attorney General, Data Breach Reporting
FTC, FTC Safeguards Rule: What Your Business Needs to Know
ACA Global, The FTC Safeguards Rule Amendments Become Effective May 13, 2024
IRS, Data Theft Information for Tax Professionals
eCFR, 16 CFR 314.4 Elements
eCFR, 16 CFR 314.6 Exceptions

Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.

Book a 10-Minute Discovery Call →

Last updated: September 29, 2026

data breachtexas cpacybersecuritycompliancenotificationsregulations