The WISP Book Written Information Security Plans for small financial practices

The reporting deadlines

When a small financial practice has a breach, more than one clock starts, and they do not run at the same speed. This is the table. It is free, and you are welcome to print it and put it on the wall.

What this page is. The deadlines themselves, with the authority for each, so you can verify them. What it is not: the procedure for working through a breach. Knowing that the IRS clock is one business day does not tell you who to call, in what order, what to say, or what to write down while you do it. That is Appendix B of the book.

The clocks

Reporting obligations after a breach, for a firm subject to the FTC Safeguards Rule. The Florida rows are an example of a state layer; your state's law may differ.
Who you notify Deadline What triggers it Authority
IRS
via Stakeholder Liaison
Next business day
after confirmation
A security incident, for an Authorized IRS e‑file Provider. If your own website caused the incident, you must also stop collecting taxpayer information until it is resolved. IRS Pub 1345
Standard 6, which applies to all Authorized e‑file Providers, not only Online Providers
Federal Trade Commission 30 days
from discovery
Unauthorized acquisition of unencrypted customer information of 500 or more consumers. Counted nationwide — all consumers, every state. 16 CFR § 314.4(j)
Effective May 13, 2024
Florida Department of Legal Affairs 30 days
15‑day extension for good cause
A breach affecting 500 or more Florida residents. Counted against Florida residents only, not the nationwide total. Fla. Stat. § 501.171(3)
The individuals affected
Florida
30 days Their personal information was breached. A law‑enforcement delay is available, as is a written harm determination — which you must document, retain for five years, and provide to the Department within 30 days. Fla. Stat. § 501.171(4)
Nationwide consumer reporting agencies
Equifax, Experian, TransUnion
See § 501.171(5) More than 1,000 individuals require notice under Florida law. At exactly 1,000 this does not trigger. Fla. Stat. § 501.171(5)
Read the subsection for the timing before you rely on a date
You, from a third‑party agent 10 days An agent holding personal information on your behalf discovers a breach. This is a clock that runs toward you — and your contracts should say so. Fla. Stat. § 501.171(6)

Four things the table cannot show you

Encryption stops one clock. It does not stop the other.

The FTC trigger is unauthorized acquisition of unencrypted customer information. Encrypt properly, and a lost laptop may not be a reportable event to the FTC at all. The IRS clock has no such qualifier: a security incident is reportable by the next business day whether or not the data was encrypted. Encryption is worth doing for many reasons. Skipping the first phone call is not one of them.

One caveat that gets missed: encryption only helps if the key did not travel with the data. A laptop with full-disk encryption and the password on a sticky note is not encrypted in any sense the rule cares about.

The counting basis changes between rows.

The FTC counts total consumers nationwide. State laws count that state's residents. The same incident can be a 600‑consumer FTC event and a 200‑resident Florida non‑event, or the reverse. Work each row separately; do not carry one number across the table.

Two adjacent Florida subsections use different comparators.

Subsection (3)(a) reads “500 or more individuals in this state.” Subsection (5) reads “more than 1,000.” Adjacent subsections, different comparators. At exactly 1,000 the credit‑bureau notice does not trigger. This is the kind of detail that gets flattened when a table compresses two thresholds into one cell.

Florida is one state.

The Florida rows are here because they are the ones the book works through in full, as a worked example of a state layer. Every state has its own breach law, its own thresholds, and its own clock. If your clients live somewhere else, those rows are not yours — the method is.

What happens if you miss one

Florida sets civil penalties for notice violations at $1,000 per day for the first 30 days, then $50,000 per 30‑day period through 180 days, capped at $500,000 per breach. There is no private cause of action under the statute. For an Authorized e‑file Provider, the IRS grades infractions in three levels, and a Level Two infraction — one with adverse impact — typically draws a one- to two-year suspension from e‑file.


Sources: 16 CFR § 314.4(j) · IRS Publication 1345 · IRS Publication 3112 · Fla. Stat. § 501.171. Each is linked and dated on the source status page. Verify against the primary text before you rely on it.

The threshold numbers Check your readiness