The Short Answer
Tax and accounting practices should include hosted VoIP in their Written Information Security Plan whenever the platform creates, receives, stores or transmits customer information. That may include voicemail audio, voicemail transcription, text messages, attachments, eFax files, call notes, integrations and administrator logs. The firm should inventory those data paths, assess risk, control access, oversee providers and document incident and termination procedures.
Key Takeaways
- Tax and accounting professionals are treated as financial institutions under the Safeguards Rule.
- A WISP should include communications platforms that handle customer information.
- Document Tier 1, platform, email, SMS and eFax responsibilities.
- Use unique accounts, least privilege and multifactor authentication where available.
- Define retention, export, deletion, breach notification and termination procedures.
- Compliance remains the firm’s responsibility even when a provider manages technology.
Why the Safeguards Rule Applies
The IRS states that tax professionals must maintain a WISP. Its current guidance says tax and accounting professionals are considered financial institutions under the Gramm-Leach-Bliley Act and must implement a data security plan. The FTC Safeguards Rule requires a written information-security program appropriate to the organization’s size, operations and customer-information sensitivity.
This article is operational guidance, not legal advice. The firm’s qualified individual and counsel should decide scope and required controls.
Inventory the VoIP Data
Voicemail
Audio, transcription, email copies, app copies and exported files.
Business texting
Message bodies, attachments, contact information, consent and opt-out records.
eFax
Received and sent documents, email delivery, portal copies and retention.
Administration
Users, permissions, call records, IP history, support access and integrations.
Access and Authentication
Use individual administrator accounts rather than shared credentials. Restrict roles to the settings and records each person needs. Enable multifactor authentication where the platform offers it and protect the email account used for password resets and voicemail delivery.
Document onboarding, role changes and offboarding. Seasonal users deserve special attention because temporary accounts are easily forgotten after filing season.
Service-Provider Oversight
The firm should document who provides the branded service, underlying platform, messaging, fax, email delivery and any integration. Review contract terms, safeguards, incident notice, support access, data ownership, subcontractors, retention and what happens at termination. The FTC emphasizes that selecting and overseeing service providers remains part of the covered firm’s program.
Encryption and Retention
Ask how signaling, media, stored voicemail, messages and administrative sessions are protected. Encryption should be evaluated together with endpoint security and access; an encrypted file available to an old account is still exposed.
Retention should match an approved business purpose. Keeping every voicemail or message forever increases the amount of customer information exposed during an incident. Define deletion for the platform, email copies, exports and integrated systems.
Incident Response
Document who contacts Tier 1, who preserves relevant logs, who evaluates affected information and who coordinates legal and regulatory reporting. The Safeguards Rule includes notification requirements for certain events involving at least 500 consumers. The firm should have counsel determine whether and when reporting is required.
Tier 1’s Practical Recommendation
Add a one-page communications appendix to the WISP: system owner, administrators, enabled features, stored data, providers, retention, emergency contacts and offboarding steps. That is more useful during an incident than a generic sentence saying “phones are secure.”
Frequently Asked Questions
Does ordinary call metadata count as customer information?
It depends on the information and context. Inventory it and let the firm’s risk assessment determine appropriate safeguards.
Should voicemail transcription be disabled?
Disable it when the business benefit does not justify the additional stored text and email copies.
Can Tier 1 write the firm’s WISP?
Tier 1 can document the communications system, but the firm’s qualified individual and legal advisors must own the complete program.
Are small tax firms exempt?
Some provisions vary for institutions with fewer than 5,000 consumers, but smaller firms still have Safeguards Rule obligations. Obtain advice based on the firm’s facts.
Continue Learning
Build Around the Firm’s Real Workflow
Tier 1 Telecom helps Florida accounting and tax firms map call volume, roles, language needs, sensitive-data boundaries, seasonal staffing, equipment and continuity before recommending a platform.
Review Your VoIP Safeguards
We can review your current numbers, call paths, equipment, internet and client-communication workflow.

























