Skip to content
Digital Diligence
Tax pros must protect taxpayer data—it’s a legal and ethical responsibility.
The IRS, state agencies, and the tax industry (Security Summit) emphasize shared responsibility.
Gramm-Leach-Bliley Act mandates security plans for data protection.
Key Resources
IRS Publication 4557
– Step-by-step guidance on creating a security plan.
NIST InfoSec Guide
– Small business framework: Identify, Protect, Detect, Respond, Recover.
IRS Publication 1345
– Covers e-file privacy and security responsibilities.
Preventative Actions
Recognize phishing attempts; the IRS never initiates contact via email for sensitive data.
Create and maintain a written data security plan.
Use antivirus/malware protection across all devices; auto-update software.
Apply strong, unique passwords (8+ characters), secure all wireless devices.
Encrypt sensitive files/emails, backup data securely offline.
Review return data—especially banking info—before filing.
Destroy devices that store sensitive data when no longer used.
Monitor IRS e-Services for suspicious filing activity.
Signs of Data Theft
Duplicate filings or suspicious IRS letters (5071C, 4883C, etc.)
Unexpected refunds, transcripts, or online account notices.
Sluggish system performance, unexplained screen actions.
EFIN return volume exceeding expected totals.
Stay Vigilant
Check daily e-File acknowledgements and weekly EFIN/PTIN reports.
Maintain accurate EFIN/PTIN and CAF authorizations.
Use two-factor authentication for IRS online tools.
If Data is Lost
Contact IRS Stakeholder Liaison, law enforcement, and state agencies.
Consult with cybersecurity experts and your insurer.
Stay Informed
Subscribe to IRS e-News, QuickAlerts, and follow social media for scam updates.
Contact Us