FTC Safeguards Rule compliance is now mandatory for a far wider range of businesses than most owners realize — and it is no longer just a box-checking exercise. Since May 2024, covered organizations must report certain data breaches directly to the Federal Trade Commission. If your business touches consumer financial data in almost any way, eMDTec helps you build, document, and maintain a compliant information security program that stands up to scrutiny.

What Is the FTC Safeguards Rule?

The FTC Safeguards Rule is a federal regulation under the Gramm-Leach-Bliley Act (GLBA) that requires “financial institutions” to develop, implement, and maintain a written information security program protecting customer data. It took effect in 2003, was significantly strengthened in 2021 to keep pace with modern threats, and was amended again in 2023 to add breach-reporting obligations.

The 2021 update moved the Rule from broad guidance to specific, enforceable requirements — encryption, multi-factor authentication, access controls, a named security lead, and regular testing among them.

Does the FTC Safeguards Rule Apply to My Business?

The word “financial institution” is misleading. The Rule reaches many businesses that never think of themselves as financial, because “finance” here means any handling of consumer financial data. Commonly covered organizations include:

  • Mortgage brokers and lenders
  • Tax preparation firms and accountants
  • Auto dealerships that arrange financing
  • Debt collectors and credit counselors
  • Financial and career counselors
  • Real estate appraisers
  • Businesses that cash checks, wire money, or service accounts

There is a limited exemption for institutions that maintain information on fewer than 5,000 consumers, but the count includes indirect contacts, so many small firms still fall in scope. If you are unsure, a short assessment settles it.

What FTC Safeguards Rule Compliance Requires

A compliant program must include, at minimum:

Designate a Qualified Individual

Name one person accountable for overseeing and enforcing your information security program.

Conduct a Written Risk Assessment

Identify reasonably foreseeable internal and external risks to customer information, and document them.

Implement Core Technical Safeguards

Encryption of customer data at rest and in transit, multi-factor authentication for anyone accessing customer information, and access controls that limit data to those who need it.

Monitor, Test, and Train

Either continuous monitoring, or annual penetration testing plus bi-annual vulnerability assessments. Provide ongoing security awareness training for staff.

Oversee Your Vendors

Select and monitor third-party service providers that handle customer data, with contractual security requirements.

Maintain an Incident Response Plan

Have a written plan for detecting, responding to, and recovering from security events — and revise it after every incident.

Report to Leadership Annually

Your Qualified Individual must report in writing at least once a year to your board or a senior officer on the state of the program.

The 2024 Breach Notification Requirement

This is the change many businesses have missed. As of May 13, 2024, covered institutions must notify the Federal Trade Commission within 30 days of discovering a breach involving the unencrypted customer information of 500 or more consumers. The FTC has signaled it intends to publish these notifications, adding a direct reputational consequence to any lapse. A compliant program is now your first line of defense against a public disclosure.

Penalties for Non-Compliance

Failure to comply can bring FTC enforcement actions, consent decrees, and substantial civil penalties — on top of the class-action exposure and lost customer trust that follow a breach. For most SMBs, the cost of building a program is a fraction of the cost of a single enforcement action.

How eMDTec Gets You Compliant

As a managed service provider serving healthcare, legal, and professional-services firms across NJ, PA, and NY, eMDTec delivers FTC Safeguards Rule compliance as a managed, end-to-end service:

  • A gap assessment against every element of the Rule
  • A written information security program built for your business
  • Deployment of the required safeguards — MFA, encryption, access control, monitoring, and endpoint protection
  • Ongoing testing, vendor oversight, and staff training
  • Annual reporting support for your Qualified Individual

You get a defensible, documented program — not a template that sits in a drawer.

Book a Compliance Assessment

Find out exactly where you stand. Schedule a Safeguards Rule assessment with eMDTec today.

Frequently Asked Questions

Is FTC Safeguards Rule compliance mandatory?

Yes, for any business that meets the Rule’s definition of a financial institution. Compliance has been enforceable since June 2023.

What is a “Qualified Individual”?

The single person a covered business designates to oversee and be accountable for its information security program. It can be an employee or a qualified third party.

Do I have to report every breach?

You must notify the FTC within 30 days when a breach involves the unencrypted information of 500 or more consumers. Smaller events still require internal response under your plan.

Can an MSP handle this for us?

Yes. Most SMBs lack in-house security staff, and a specialized MSP like eMDTec can deliver assessment, implementation, monitoring, and reporting as a managed service.