Federal law administered by the Federal Trade Commission requires all “professional tax preparers” to create and maintain a written information security plan that is appropriate to the firm’s size and complexity.
In addition, the FTC-required information security plan must be appropriate to the nature and scope of the company’s activities and the sensitivity of the customer information it handles. A plan for a sole tax practitioner would differ from a multi-partner, global firm.
Tax professionals working from home must ensure that client data is protected just as it would in an office setting.
Please note: The FTC currently is re-evaluating the Safeguards Rule and has proposed new regulations. Be alert to any changes in the Safeguards Rule and its effect on the tax preparation community.
IRS Publication 4557, Safeguarding Taxpayer Data (PDF), details critical security measures that all tax professionals should enact. The publication also includes information on how to comply with the FTC Safeguards Rule, including a checklist of items for a prospective data security plan. Tax professionals are asked to focus on key areas such as employee management and training; information systems; and detecting and managing system failures.
The IRS also may treat a violation of the FTC Safeguards Rule as a violation of IRS Revenue Procedure 2007-40, which sets the rules for tax professionals participating as an Authorized IRS e-file Provider.
Tax professionals who experience a data theft should report the crime to the IRS immediately so that actions can be taken to protect taxpayers – and the firm. The Security Summit partners recommend practitioners create a response plan so that actions can be taken quickly, and contact information is readily available.
If a client or the firm are the victim of data theft, immediately:
Find more information at Data Theft Information for Tax Professionals.
In addition to trying to steal client data, thieves may try to steal a tax practitioner’s identity as well, using their PTINs, EFINs and CAF numbers to file fraudulent returns or steal even more information. Thieves may even try to impersonate the tax practitioner to obtain tax transcripts or other tax records.
Practitioners should routinely check their IRS e-Services e-file Application to see a weekly count of tax returns filed with their Electronic Filing Identification Numbers or EFIN. Excessive filings are a sign of data theft. E-file applications also should be kept up to date.
Circular 230 practitioners also can review weekly the number of tax returns filed using their Preparer Tax Identification Number or PTIN. Again, excessive filings are a sign of data theft.
Preparers with Centralized Authorization File, or CAF numbers, that enable third party access to tax information or representation should keep those records updated. Practitioners should notify the IRS when they no longer need third-party authorization for clients.
Tax professionals also can get help with security recommendations by reviewing the recently revised IRS Publication 4557, Safeguarding Taxpayer Data (PDF), and Small Business Information Security: The Fundamentals (PDF) by the National Institute of Standards and Technology.
Publication 5293, Data Security Resource Guide for Tax Professionals (PDF), provides a compilation data theft information available on IRS.gov. Also, tax professionals should stay connected to the IRS through subscriptions to e-News for Tax Professionals and Social Media or visit Identity Theft Central at IRS.gov/identitytheft.