This article is for informational and educational use only. It does not provide legal, financial, or tax advice and does not form an attorney-client relationship. Legal requirements can differ by jurisdiction and may change without notice. A qualified professional can address specific facts and current rules.
Key Facts
- Federal level: The Red Flag Program Clarification Act of 2010 became Public Law 111-319 on December 18, 2010.
- Federal level: Public Law 111-319 amended 15 U.S.C. 1681m(e) by revising the statutory definition of “creditor.”.
- Federal level: The amended “creditor” definition includes regularly and in the ordinary course of business activities involving consumer reports, furnishing information, or advancing funds under specified conditions.
- Federal level: The amended definition excludes advancing funds for “expenses incidental to a service provided by the creditor to that person.”.
- Federal level: Current FTC rules apply to “financial institutions and creditors” and require a written Identity Theft Prevention Program for covered accounts under 16 CFR Part 681.
- Federal level: In May 2010, the FTC announced a delay in enforcement of the Red Flags Rule through December 31, 2010 while Congress considered changes affecting scope.
- Federal level: In December 2010, House remarks described the bill as narrowing the Red Flags Rule scope and referenced that examples like law firms did not come to mind for covered “creditors.”.
Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.
- What the FTC Red Flags Rule requires under today’s regulation
- The statutory mechanism behind the “creditor” debate
- Why the May 2010 enforcement delay mattered during the legislative window
- What House floor remarks actually said in December 2010
- How the FTC implemented the 2010 clarification in rulemaking
- A compact comparison of the 2010 storyline vs the operative framework today
- What the archive episode illustrates for current readers
- Sources
In late 2010, a recurring question in discussions of the FTC Red Flags Rule was whether Congress intended the rule to sweep in lawyers and law firms. This archive recovery treats that question as historical context by focusing on House floor remarks during consideration of S. 3987, the “Red Flag Program Clarification Act of 2010,” where lawmakers used “creditor” scope examples to explain congressional intent rather than by changing the rule’s operative coverage text by itself. For another related archive item from the same broader era of legal-policy discussion, see Anthony Kennedy speech at ABA annual meeting.
What the FTC Red Flags Rule requires under today’s regulation
The current regulation states that 16 CFR § 681.1 applies to “financial institutions and creditors” that are subject to administrative enforcement of the FCRA by the FTC pursuant to 15 U.S.C. 1681s(a)(1). Section 681.1(d)(1) requires each covered “financial institution or creditor that offers or maintains covered accounts” to develop and implement a written Identity Theft Prevention Program designed to detect, prevent, and mitigate identity theft. FTC guidance describes this as requiring many businesses and organizations to implement a written Identity Theft Prevention Program designed to detect warning signs of identity theft.
The statutory mechanism behind the “creditor” debate
The core 2010 change came from Public Law 111-319, which amended 15 U.S.C. 1681m(e). The law revised the definition of “creditor” to cover certain “regularly and in the ordinary course of business” activities, including obtaining or using consumer reports, furnishing information to consumer reporting agencies, and advancing funds under specified conditions. Public Law 111-319 also narrowed the definition by excluding advancing funds for “expenses incidental to a service provided by the creditor to that person.”
The same Public Law addressed how other creditor types could fall within the definition by allowing inclusion of “any other type of creditor” based on an agency determination tied to whether the creditor offers or maintains accounts subject to a “reasonably foreseeable risk of identity theft.”
Why the May 2010 enforcement delay mattered during the legislative window
In May 2010, the FTC announced it was “further delaying enforcement of the ‘Red Flags’ Rule through December 31, 2010” while Congress considered legislation that would affect the scope of entities covered. The FTC also stated that the Rule became effective on January 1, 2008, with full compliance originally required by November 1, 2008. In that historical setting, enforcement timing and coverage scope were moving through the same legislative period.
What House floor remarks actually said in December 2010
House floor remarks during the S. 3987 debate described the bill as clarifying and narrowing the definition of “creditor” for purposes of the FTC’s Red Flags Rule. In the Congressional Record, lawmakers referred to Congress clarifying who counts as a “creditor” under the FACT Act framing and used specific examples to communicate which categories Congress did not have in mind, including remarks that “dentists, accounting firms, and law firms do not come to mind.”
Importantly for modern readers, those statements function as legislative-history intent framing. The operative coverage still tracks the enacted statutory “creditor” definition and the current regulation’s scope and program requirement in 16 CFR Part 681.
How the FTC implemented the 2010 clarification in rulemaking
After the Clarification Act, the FTC issued an interim final rule through a Federal Register notice describing an amendment to implement the Red Flag Program Clarification Act of 2010. That interim final rule was effective February 11, 2013. Separate FTC communications about the amended rule described narrower coverage for covered “creditors” based on regularly performing covered activities such as obtaining or using consumer reports, furnishing information, or advancing funds in certain cases.
A compact comparison of the 2010 storyline vs the operative framework today
The “lawyers exclusion” headlines can compress a more nuanced sequence. The table below keeps the historical and legal layers separate:
| Topic | 2010 discussion in Congress | What controls coverage in the present regulatory structure |
|---|---|---|
| Who gets pulled into the rule | House remarks discussed narrowing the scope of “creditor” coverage and used examples like law firms in intent framing | Current 16 CFR Part 681 applies to “financial institutions and creditors” subject to FTC administrative enforcement and requires a written Identity Theft Prevention Program for covered accounts |
| What the narrowing change means | Public Law 111-319 revised the definition of “creditor” in 15 U.S.C. 1681m(e) and included the “expenses incidental to a service” carve-out | Coverage follows the statute’s definition of “creditor” as implemented in the operative regulatory framework |
| How uncertainty was handled while legislation moved | The FTC delayed enforcement through December 31, 2010 while Congress considered scope changes | Today’s analysis follows the current eCFR regulation text and definitions |
What the archive episode illustrates for current readers
This archive recovery shows why “excluding lawyers” appears in the 2010 record: lawmakers discussed “creditor” scope and gave profession-focused examples to communicate congressional intent. For today’s compliance questions, the controlling point stays with the statutory “creditor” definition and the current regulation’s coverage language in 16 CFR Part 681, rather than with profession-by-profession intent labels from the floor debate.
Sources
- S.3987 on Congress.gov
- Public Law 111-319 text on GovInfo
- House floor remarks in the Congressional Record
- FTC May 2010 enforcement-delay press release
- Current 16 CFR Part 681 in the eCFR
- Federal Register interim final rule implementing the Clarification Act
- FTC November 2012 press release on the amended rule
- FTC guidance page on the Red Flags Rule