What Does a CPA Firm's WISP Actually Need to Include?
A practical look at the written plan, operating controls and evidence that turn a WISP from a downloaded document into a working security program.
Read Article →Clear, practical explanations of the IT, cybersecurity and compliance issues that matter to businesses, CPA firms and medical practices.
Article library
A practical look at the written plan, operating controls and evidence that turn a WISP from a downloaded document into a working security program.
Read Article →The Safeguards Rule translated into practical program ownership, risk assessment, safeguards, testing, training and vendor oversight for accounting firms.
Read Article →How a firm-designated Qualified Individual governs the security program, how technical providers support execution and why incident communications need a separately assigned role.
Read Article →Real enforcement actions show that the cost can extend far beyond a fine—including mandated security programs, independent assessments, training and years of regulatory oversight.
Read Article →A dozen employees can still mean thousands of sensitive records. Real cases show why small firm size does not eliminate security obligations or incident exposure.
Read Article →Containing an incident is only one workstream. State notification clocks can create separate exposure when firms do not know in advance who must be told, by when and by whom.
Read Article →A federal court upheld the IRS's authority over e-file participation, underscoring why tax firms should treat the security of their e-file environment as an operational business risk.
Read Article →Article library
Why the EHR is only one part of a shared-responsibility environment that also includes identities, endpoints, email, networks, people and documentation.
Read Article →A plain-language guide to scoping ePHI, identifying threats and vulnerabilities, evaluating safeguards and documenting a usable remediation plan.
Read Article →How BAAs, data inventories, notification terms, incident readiness and the practice’s own documentation affect the response to a vendor incident.
Read Article →Practical ways independent practices can share space or providers while keeping identities, devices, data, networks and responsibilities appropriately separated.
Read Article →If your practice receives federal financial assistance from HHS, new Section 504 requirements may affect your website and mobile applications. Here’s what WCAG 2.1 AA means, who is covered, and when the current deadlines take effect.
Read Article →Article library
Why underwriting answers should reflect controls that are implemented, maintained and verifiable—not assumptions or planned improvements.
Read Article →Cyber coverage can still be lost after an incident when notice is late, consent requirements are ignored or the claims process is mishandled.
Read Article →A practical explanation of the three layers of resilience—and why a successful backup job does not prove the business can recover.
Read Article →