A Breach of Client Data: Risks to CPA Firms

Amy Waldron, David Hallstrom · Journal of accountancy online/Journal of accountancy · 2013

You walk into your office on a Saturday morning during tax season to find a staff member waiting for you with sweaty palms and a look of terror on her face. She takes a while to get the words out, but you soon learn that she backed up some client files to an unencrypted flash drive and dropped it in her purse before going to a happy hour the night before. Upon returning to her table from the restroom, she discovered her purse was nowhere to be found. She had been preparing payroll tax returns for several clients with multistate locations, and the flash drive contained payroll data such as names, Social Security numbers, addresses, salaries, and wages. You have a lot of questions. What other data were on the flash drive? Which records were exposed? What information should be shared with your staff?. How should they respond to related inquiries? How and when should the firm break the news to affected clients? Other questions may not immediately come to mind but are still very important. Is the clock ticking on state law requirements to notify affected businesses and individuals? Does state law require you to offer credit monitoring services to affected individuals? COMMON DATA BREACH SCENARIOS CPA firms have made great strides in embracing technology. Electronic data management systems, client portals, and cloud-computing systems foster an ease of doing business. However, records maintained by firms must remain confidential because of professional standards, statutes, and regulations governing record retention. Data breaches can happen in numerous ways, including the following: a lost or stolen device, hacking, fraud, improper disposal of data, and errant email messages. It may be only a matter of time until you face a similar breach. A FIRM'S EXPOSURE A CPA firm faces numerous exposures in the event of a data breach: Claim for damages. A client or third party can bring both direct claims and cross-claims for indemnification against the firm for damages incurred as a result of the exposure. Direct claims may relate to costs incurred to investigate and mitigate damages that could be attributed to the breach, including forensic services, public relations expenses, and costs incurred to place affected parties on notice of the breach and provide credit monitoring services. Damages also may be sought for lost business directly related to the breach, or indirectly related, such as those arising from a disclosure of trade secrets. Cross-claims for indemnification may arise from individual or class action lawsuits filed against the client by employees or customers. These claims typically allege failure to secure confidential data, resulting in identity theft or loss of business. Clients also may encounter civil and criminal enforcement proceedings if regulators such as the Federal Deposit Insurance Corp. (FDIC), Federal Trade Commission (FTC), the Department of Health and Human Services (HHS), or SEC deem the client was responsible for the breach. Legal costs to defend such proceedings can be substantial-attorneys who specialize in this work charge as much as $1,000 an hour--and the client can bring a cross-claim against the firm to recover its losses. If commercial information is compromised, such as trade secrets entrusted to clients, the related damages also can be significant (e.g., damages in health care-related cases have run in the millions of dollars). Cost of compliance with state and federal statutes and regulations. Currently, there are security breach notification laws in 46 states, the District of Columbia, Guam, Puerto Rico, and the Virgin Islands. Some require notification to affected individuals and to state authorities. State laws are applicable to residents of a state, so multiple state laws could apply in the event of a data breach. According to a study published by Ponemon Institute, 2011 Cost of Data Breach Study: United States, the cost per record of a data breach was $194 in 2011. …

Read the paper · More papers on PaperTik