
If you run hosted QuickBooks, your hosting provider is a service provider your WISP has to account for. The FTC Safeguards Rule requires documented oversight of any vendor that touches client data, and a host clearly does, since your books live on its servers. The practical upside is that a good host makes this easy to satisfy: it can tell you exactly what safeguards it maintains and give you what you need to write it down. This is the actionable version, what to document about your host, and what to ask before you do. It is the vendor most firms forget to record, precisely because hosting feels like infrastructure rather than a handler of client data.
Read the two columns together and the task gets concrete: the left is what your plan needs to show, and the right is what a capable host hands you to show it. Nothing here asks you to become a security expert, only to keep a clear record of the vendor holding your data.
What the Safeguards Rule requires of your vendors
The vendor-oversight piece of the FTC Safeguards Rule is specific, and it has three parts. You are expected to select and retain service providers that are capable of maintaining appropriate safeguards for the client data they handle, to require those safeguards by contract, and to periodically assess your providers based on the risk they present. In plain terms: pick a capable host, get the protection in writing, and check in on them over time rather than treating it as done forever. This sits alongside the rest of your program, which we cover in our guides to the FTC Safeguards Rule and the IRS Publication 4557 checklist. Vendor oversight is the part hosting touches most directly, because your host is often the biggest vendor in your data’s path. Where firms slip is not choosing a bad host, it is naming a good one in the WISP and never documenting the oversight behind it. A listed vendor with no recorded review is exactly the gap an examiner or an insurer notices.
Questions to ask your host
Before you can document oversight, you need answers. These are the questions that give you what your WISP requires, and any host worth using should answer them without hesitation.
- Where is our data stored, and is it in the United States?
- What safeguards do you maintain: encryption in transit and at rest, multi-factor authentication, access controls, and managed backups?
- Do you have independent security audits, such as SOC 2, and can you share the report or a summary?
- What do your contract terms say about protecting our data and notifying us of a security incident?
- Who is our security contact, and how do we reach you if something goes wrong?
- When we leave, how is our data returned or securely deleted?
Write the answers into your WISP’s service-provider section, keep any documentation the host gives you, and note the date you reviewed it. That record is exactly what an examiner, an insurer, or your own Qualified Individual will look for.
Where this goes in your WISP
Your WISP should have a service-provider or vendor-management section, and your host belongs there by name. Record who they are and where your data is stored, the safeguards they maintain, the contract terms covering data protection and breach notification, any independent audit or documentation they shared, and the date you last reviewed them. You do not need pages for this. A short, dated entry does the job.
Then set a reminder to revisit it at least once a year, or whenever your host changes something material, such as where data is hosted. That periodic review is the step firms most often skip, and it is exactly what an examiner, an insurer after a claim, or your own Qualified Individual will ask to see. Keeping it current is far easier than reconstructing it under pressure.
How CloudTop Office answers these
CloudTop Office is built to be a vendor you can document cleanly. Your QuickBooks runs on Microsoft Azure in U.S. regions, with encryption, multi-factor authentication, managed daily backups, and access controls, and we can tell you plainly where your data lives and who to contact. We will answer the due-diligence questions above and provide documentation of our security controls, so you have real material to cite rather than a marketing line. What we cannot do, and what no honest host should claim, is make your firm compliant on our own. You still write the WISP, name your Qualified Individual, run your risk assessment, and review your vendors. Hosting satisfies the technical and oversight pieces of that puzzle, not the whole of it. If you are assembling your WISP, we are used to being on the other end of these due-diligence questions and can turn your list around quickly. You can see how the environment is built on our QuickBooks Desktop hosting page, and common questions are covered in our hosting FAQ.
This article is general information, not legal or compliance advice. Confirm your obligations against the current FTC Safeguards Rule and a qualified advisor.
Vendor oversight questions
Does hosting QuickBooks put my provider in my WISP?
Yes. Any vendor that handles client data belongs in your WISP’s service-provider section with documented oversight, and a host that runs your books qualifies. Recording it is part of meeting the Safeguards Rule.
What does the FTC rule require for service providers?
Three things: select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk it presents. Pick well, get it in writing, and review over time.
Should I ask my host for a SOC 2 report?
It is a fair question to ask any host. Independent audits like SOC 2 are useful evidence of a provider’s controls. Ask what audits and safeguards a host maintains, and keep whatever documentation they can share for your records.
Does a good host make this easier?
Yes. A good host can attest to its controls, provide contract terms, and answer your due-diligence questions, which gives you real material to document. You still do the writing and the periodic review, but the host supplies the evidence.
Does hosting make my firm compliant?
No. Hosting helps satisfy the technical safeguards and the vendor-oversight element, and gives you a provider you can document. Your WISP, Qualified Individual, risk assessment, and training remain your firm’s responsibility.
Need a host you can document in your WISP?
A 15-minute call is enough to get the vendor-oversight answers your WISP needs, from where your data lives to the controls we maintain.
Book a 15-min consult

Leave a Reply