You know the week we mean. Second week of March, the phone will not stop, and a client texts a photo of a K-1 because it was faster than scanning. A spouse forwards last year’s return with a question attached. A brand new client emails a PDF of their entire brokerage statement to whatever address they found on your website. By mid April your inbox has quietly become the largest unsecured filing cabinet in the county. Nobody decided that. It happened one urgent message at a time.
Underneath all of it sits a requirement plenty of preparers have never heard of: a written information security plan. Before we go further, here is the caveat, and we mean it sincerely. This is general information, not legal, tax, or compliance advice. Requirements change, and how they apply to your firm depends on facts we do not know. A qualified advisor, your own counsel, or your professional liability carrier has to confirm what actually applies to you. What we can do is point you at the primary sources and translate the technology side into plain language.
What the IRS and the FTC Expect, in General Terms
Start with the IRS’s own publication. IRS Publication 4557, Safeguarding Taxpayer Data, states that protecting taxpayer data is the law, and explains that federal law gives the Federal Trade Commission authority to set data safeguard regulations for various entities, including professional tax return preparers. It adds that under the Safeguards Rule, financial institutions must protect the consumer information they collect, and that the Gramm-Leach-Bliley Act requires companies defined as financial institutions to ensure the security and confidentiality of that information. The definition, the publication says, includes professional tax preparers. The copy we reviewed was revised in June 2024, so check the IRS site for the current revision.
IRS Security Summit guidance on written information security plans describes what the FTC expects a firm to do. In its words:
- Designate someone to own it. Designate one or more employees to coordinate the information security program.
- Find the risks. Identify and assess risks to customer information in relevant areas.
- Build and check the safeguards. Create, implement, and regularly monitor and test security safeguards.
- Vet your vendors. Select service providers that can maintain appropriate safeguards.
That same IRS guidance says a plan should focus on three areas: employee management and training, information systems, and detecting and managing system failures. It also points preparers to IRS publications written for the purpose, including Publication 4557 and Publication 5708 on creating a written plan.
On the FTC side, the agency’s business guidance on the Safeguards Rule describes the elements of an information security program: a qualified individual to run it, a written risk assessment, access controls with a regular look at whether people still have a legitimate business need, encrypting customer information on your system and in transit, multi-factor authentication, secure disposal, change management, monitoring, an incident response plan, service provider oversight, and a written report at least annually to the board. That guidance also notes an exemption from certain provisions for institutions maintaining customer information concerning fewer than five thousand consumers. Whether that applies to you is a question for a qualified advisor, not for a blog post.
Why Tax Season Makes Your Firm Interesting
This is not about being important enough to target. It is about what you happen to be holding. A tax file contains exactly what someone needs to file a fraudulent return in another person’s name: Social Security numbers for the whole household, dependents, prior year figures, and bank routing details for the refund. One preparer’s client list is worth far more than one taxpayer’s mailbox.
Season conditions make it worse in ordinary ways. Everyone is tired. Attachments from strangers are normal in February in a way they are not in August, which is a gift to anyone sending convincing fake emails. Seasonal staff arrive and get access quickly. Deadlines make people click first and think second. That is the honest mechanism, and it is why we wrote about why phishing keeps getting through even at firms with good filtering.
The Email Problem
Sending a completed return as an attachment feels like service. It is fast and the client already knows how to open it. It is also the hardest habit to walk back, because once that file leaves you have no control over where it goes and no record of who opened it. Autocomplete picks the wrong Johnson. The client forwards it to a lender who forwards it again. And your sent folder slowly becomes a searchable archive of everyone’s finances.
Publication 4557 recommends encrypting all sensitive files and emails, especially those with the taxpayer’s personally identifiable information. For most small firms the workable version is a secure client portal: you send a link rather than the document, access can be revoked, and you get a record. Two things make it stick. The portal has to be simple enough that clients will use it, so test it on your least technical client first. And tell every client plainly that you will never email their return as an attachment. That is a security control and a marketing message at once, and it makes an impersonation attempt obvious.
Multi-Factor Authentication, Everywhere
Publication 4557 recommends implementing multi-factor authentication for anyone accessing customer information on your system. FTC business guidance describes it as requiring verification of at least two types of factors: something you know such as a password, something you have such as a token, and something you are such as a biometric.
Everywhere really means everywhere. Email first, because email is the reset path for everything else. Then your tax preparation software, the client portal, remote access, cloud storage, payroll, and the bank. In our experience the account that gets skipped is the account that gets used, usually because turning it on was mildly annoying for one partner. If you want to compare app codes, passkeys, and hardware keys before deciding, we covered it in YubiKey vs Passkey vs MFA.
How to Start Instead of Being Paralyzed
Firms without a plan are usually stuck for the same reason: it feels like a project requiring a specialist, so it never gets a start date. Work in this order, in a plain document.
- Put one name at the top. A person, not a committee. This is the coordinating role the IRS guidance describes.
- List where taxpayer data lives. Tax software, email, the server, cloud storage, the portal, laptops, the scanner, and every outside vendor who touches returns.
- Write down who can reach each of those. Then remove anyone who no longer needs it, starting with last season’s temporary staff.
- Record what you already do. Most firms have more in place than they think: anti-virus, a firewall, backups, locked doors. It counts.
- Give each gap a date and an owner. A gap with a date is a plan. A gap without one is an anxiety.
- Use the IRS templates instead of a blank page. Publication 5708 exists specifically to help firms create a written plan.
- Set a review date and have a qualified advisor read it. Off-season, when you can think.
The Bottom Line
A written plan is not a document you buy and file. It is a short honest description of what you hold, who can reach it, what protects it, and what you will do when something goes wrong. Firms that write it down almost always find two or three fixes worth making that week, and they stop wondering whether they are behind. Turning on multi-factor authentication and getting returns out of email attachments would put most small practices ahead of where they were last season.
Once more, plainly: this is general information, not legal, tax, or compliance advice, and a qualified advisor has to confirm what applies to your firm. We handle the technology half for professional practices around Denton County, and we are glad to work alongside your advisor so the plan on paper matches the systems in the office. Contact us today.
Sources:
Comments are closed