IT Support for Accounting Firms
IT support for CPA and tax practices in Greater Boston, built around IRS Publication 4557, the FTC Safeguards Rule and the security plan your PTIN requires.
Accounting and tax practices carry an obligation that most small businesses do not: you hold Social Security numbers, bank details and full financial pictures for hundreds of people, and there is specific federal guidance about how you are expected to protect it.
Most IT providers do not know that guidance exists. The penalties, and the client relationships, land on you.
What actually applies to you
IRS Publication 4557, Safeguarding Taxpayer Data. The IRS guidance for tax professionals — the reference point for what a reasonable security program looks like in your profession.
The FTC Safeguards Rule. Tax preparers are “financial institutions” under the Gramm-Leach-Bliley Act. That is not a technicality; it means the Safeguards Rule applies to a two-person practice in Newton exactly as it applies to a bank, with obligations including a designated qualified individual, a written risk assessment, MFA, encryption, vendor oversight and an incident response plan.
PTIN renewal. Since 2023 the renewal application asks you to confirm you maintain a written information security plan. Confirming it and not having it is its own problem.
Massachusetts 201 CMR 17.00. On top of the federal layer, the state regulation applies to any business holding personal information about a Massachusetts resident. See cybersecurity.
What we do about it
Write the WISP with you, properly. Not a downloaded template with your name inserted. A document that describes what you actually do — because in an examination or after an incident, a plan that does not match reality is evidence against you rather than for you.
MFA on everything holding client data. Email, tax software, document portal, remote access. This is explicit in the Safeguards Rule and it is the single control that prevents the most common serious incident.
Encryption at rest and in transit. Workstations and laptops encrypted, client files never moving by unencrypted email. Portal rather than attachment, as a matter of routine.
Backups you have restored. Tested, with an offline copy. During filing season, the tolerable amount of downtime is close to zero.
Access control that reflects roles. Seasonal preparers should not have access to every client file from every prior year. Accounts disabled the day someone finishes.
Secure document handling. Scan-to-email configured with modern authentication, and print release so client returns do not sit in an open tray. See printer support.
Vendor oversight. The Safeguards Rule makes you responsible for the security of the providers you use. We help you ask them the right questions and keep the answers on file.
Season-aware support
The way we work with accounting firms differs from the rest of our clients in three concrete ways.
Nothing disruptive is scheduled between January and April — no migrations, no hardware swaps, no anything that could go sideways in your busiest ten weeks. Patching moves to evenings and weekends during that window. And response expectations tighten, because an hour of downtime on April 12 is not the same as an hour in September.
We plan projects for May through November, when you can absorb them.
Your software, specifically
The recurring technical issues in this market are consistent: shared tax data files on a slow or misconfigured network share, which turns a quick operation into a minute of waiting a hundred times a day; licence servers that stop responding; workstation performance that degrades under the memory demands of tax software; and multi-user conflicts on QuickBooks Desktop files.
These are network and configuration problems, not software problems, which is why the vendor’s support line cannot fix them.
Related
- Managed IT support — the underlying service
- Cybersecurity — controls and the Massachusetts requirement
- Professional offices — law, architecture and consulting practices
Frequently asked questions
- Does the IRS actually require a written security plan?
- Yes. Paid tax return preparers are required to have a written information security plan under the FTC Safeguards Rule, and since 2023 the PTIN renewal application asks you to confirm you have one. IRS Publication 4557 is the guidance describing what it should contain. This is not advisory.
- We already have antivirus and a locked office. Is that not enough?
- Not for the requirements you are under. The Safeguards Rule expects a named person responsible for the program, a written risk assessment, MFA on systems holding client data, encryption of client data at rest and in transit, vendor oversight and an incident response plan. Antivirus is one line in a much longer document.
- Can you support us during tax season without slowing us down?
- That is the period we plan around. Nothing disruptive is scheduled between January and April, patching windows move to evenings, and response expectations tighten. Any provider who proposes a migration in March does not work with accounting firms.
- Do you know the software we use?
- The common stack in this market — UltraTax, Lacerte, Drake, ProSeries, QuickBooks Desktop and Online, and the document management and portal products that sit alongside them. The specific issues are network paths for shared data files, licence servers and the performance problems that hit when a data file is on a slow share.
- What happens if a client's data is exposed?
- Massachusetts requires notification to affected residents and to the Attorney General and Office of Consumer Affairs. The IRS asks that you report a data theft to your Stakeholder Liaison, and the FTC has its own reporting expectations. Part of the plan we help you write is who makes those calls, in what order, before anyone is under pressure.
Tell us what stopped working
Text or email is usually faster than a call. We serve Boston and everything within 20 miles — and remote support has no radius.