Whitley Penn. Lane Gorman Trubitt. BST & Co. Orrick's $8M settlement. Four incidents that changed the IRS WISP, FTC Safeguards, and class action liability calculus for every Texas accounting practice. 38 verified sources.
| Metric | Value | Source |
|---|---|---|
| Orrick class action settlement (professional services precedent) | $8M | Orrick settlement reporting, 2025 |
| FTC civil penalty per violation per day | $50,120 | FTC 16 CFR Part 314 (enforced Jun 2023) |
| TDPSA civil penalty per violation (TX AG) | $7,500 | TX Data Privacy and Security Act, eff. Jul 1 2024 |
| US average breach cost (all sectors) | $10.22M | IBM Cost of Data Breach Report 2025 (+9% YoY) |
| Average breach dwell time (industry avg) | 241 days | IBM Cost of Data Breach Report 2025 |
| CoreRecon IR SLA (critical incidents) | 30 min | CoreRecon SLA — Sentinel/Fortress/Command |
| Cl0p MOVEit organizations compromised (2023) | 2,000+ | CISA/FBI joint advisory + Emsisoft tracker |
| TX CPA firms serving as HIPAA Business Associates (est.) | ~400 | AICPA PCPS survey + CoreRecon analysis |
| Entity | Date | Attack Vector | Impact | Relevance |
|---|---|---|---|---|
| Whitley Penn LLP Dallas / Houston / FW / Austin, TX |
Oct 2023 | Cl0p — MOVEit CVE-2023-34362 | Client tax returns, audit workpapers, engagement letters exfiltrated. 900+ personnel affected. | TX largest CPA breach 2023 |
| Lane Gorman Trubitt LLC Dallas, TX |
Jan 2024 | ALPHV/BlackCat double-extortion | PE-backed company K-1s, high-net-worth tax returns, ownership structures exfiltrated before encryption. Leak site claim. | Double-extortion — data published |
| BST & Co. CPAs LLP Albany, NY (national precedent) |
2023–2024 | Healthcare client PHI in accounting records | HIPAA Business Associate regulatory action. OCR enforcement against CPA firm directly — not just the healthcare client. | HIPAA BA liability precedent |
| Orrick, Herrington & Sutcliffe Global (professional svcs precedent) |
2023 breach / 2025 settlement | Client confidential record exfiltration | $8M class action settlement. Breach of fiduciary duty + malpractice + contract theory applies identically to CPA firms. | $8M — class action precedent |
| Framework | Authority | Key Requirements | Penalty |
|---|---|---|---|
| IRS Pub 4557 — WISP | IRS Safeguards Program | Written ISP, designated coordinator, risk assessment, technical safeguards, vendor oversight, IR plan, annual training | PTIN revocation, e-file suspension during investigation |
| FTC Safeguards Rule — 16 CFR 314 | FTC | Qualified Individual, written ISP, MFA, encryption, annual pen test, vendor oversight, 30-day FTC breach notification (500+ records) | $50,120/violation/day civil penalty |
| TDPSA — TX Data Privacy Act | TX Attorney General | Data Protection Assessments, 45-day consumer requests, breach notification. GLBA-regulated data partially exempt; marketing/CRM data not exempt. | $7,500/violation civil penalty |
| HIPAA — BA obligations | HHS Office for Civil Rights | Security Rule compliance for CPA firms serving as Business Associates to covered entities. Breach notification to covered entity within 60 days. OCR enforcement direct against BA. | $100–$50,000/violation; $1.9M/year max per category |
Get the complete 2026 Texas Accounting & CPA Firms Cyber Threat Brief — 38 verified sources, all 4 named incident profiles, full 8-control framework, IRS WISP 8-requirement walkthrough, regulatory compliance map, and post-Orrick liability modeling. Sent directly to your inbox.
We'll also send you relevant professional services security alerts. No spam — unsubscribe anytime.