Texas Compliance and Cybersecurity for Tax Preparation Practices

If you hold a PTIN, federal law already treats your practice as a financial institution — the FTC Safeguards Rule sets what your written security plan has to contain, and the IRS asks whether you have one every time you renew. Texas layers its own requirements on top. Which of these reach your firm, and how, is what the Compliance Readiness Review determines. Briggs IT reviews what you have against what you need to be able to produce, plans what has to change, implements those changes or guides your internal IT team through them, and builds the documentation — steady enough to carry you through your busiest weeks.

You’re a financial institution —
even if no one ever told you

Under the Gramm-Leach-Bliley Act, a tax preparation practice that handles customer financial information is defined as a “financial institution,” which places it under the FTC Safeguards Rule. Most preparers never learn this until the moment it counts: the renewal question they can’t answer truthfully, a breach, or an inquiry from a regulator. The obligation has been there the whole time — quietly — whether or not anyone pointed it out.

The IRS makes it explicit. When you renew your PTIN, the W-12 form asks directly whether you maintain a Written Information Security Plan — and answering falsely is a serious federal matter. Between IRS Publication 4557 and the FTC Safeguards Rule, the standard your practice is held to is already set. What most preparers lack isn’t awareness of the rules so much as proof they’ve met them.

Texas adds its own layer on top of the federal rules — the SB 2610 safe harbor against punitive damages, the TITEPA and TDPSA breach and privacy duties, and TRAIGA’s new AI-governance expectations. Which of these reach your practice, and what each one demands, is what the Compliance Readiness Review sorts out.

What a tax preparation practice
actually needs

A defensible program is a set of pieces that work together — and, just as important, the written evidence that each one exists.
For most tax practices, that looks like things such as:

This isn’t something you do once and forget. It’s a program you maintain, update, and re-evidence every year.
With the proof attached, ready for the day the IRS or the FTC asks to see it.

For a tax practice,
timing is everything

A system failure in your slow season is a bad day. The same failure at the height of filing season is something else entirely — because so much of your year runs through such a narrow window that there’s no room to recover. A breach or an outage you’d shrug off in the off-season can put the whole year’s revenue at risk if it lands at the wrong moment. For a tax practice, this isn’t just a cybersecurity concern. It’s a stay-in-business concern.

That’s why the work belongs in the off-season, and why it runs in order. First we gather what you have and review it against what the IRS and the FTC require — you get a written report of where the practice stands, yours to keep. Then the gaps get closed before any recurring billing begins: if you have internal or outside IT, we guide them through the changes and verify each one — including that backups are tested and recovery is planned, not just assumed; if you don’t, we do the build ourselves in a scoped, defined, and billable remediation and implementation phase, a phase with an end, not us becoming your IT. By the time filing season hits, the program is built, documented, and current, and recurring simply keeps it that way — so you walk into your busiest weeks with nothing hanging over them.

The two things every
practice says first

“We use tax software that handles security.”

Your tax software vendor secures their own platform — not your practice. The workstations your team uses, the email you exchange with clients, the cloud storage holding working papers, the machines where returns are prepared and reviewed: all of that is your responsibility, not the software provider’s. The FTC Safeguards Rule applies to your practice, not to the software you log into. The platform is one piece. The program around it is yours.

“We’re too small.”

Being small doesn’t put you outside these rules. The FTC Safeguards Rule’s lighter-touch provisions only reach the very smallest practices — and that’s measured by total customer records, which includes the records belonging to your clients’ clients. Most small practices cross that line without realizing it. And no matter where a practice lands on that question, the IRS’s written-plan requirement applies to every preparer who holds a PTIN. Small doesn’t make this go away.

See where your practice stands

The Compliance Readiness Review is a working session built for tax practices. We gather what you already have and review it against the rules that actually reach your practice — the FTC Safeguards Rule and IRS Publication 4557, plus the Texas statutes on top — then hand you a written report in plain English: what’s in place, what’s missing, and what to fix first. No sales pressure. The report is yours to keep, whether or not you ever hire Briggs IT. The quiet stretch before your next busy season is the ideal time to take it.