How to Create a Data Security Plan for Tax Preparers

Federal law requires every professional tax preparer to build and maintain a written information security plan, and the IRS publishes a free 28-page template (Publication 5708) that walks smaller firms through it section by section.1Internal Revenue Service. IRS, Security Summit Remind Tax Pros They Must Have a Written Information Security Plan to Protect Client Data The requirement comes from the FTC Safeguards Rule, which treats tax preparers as financial institutions under the Gramm-Leach-Bliley Act.2Federal Trade Commission. 4 Gramm-Leach-Bliley Tips to Take From FTCs TaxSlayer Case The plan itself has to cover a written risk assessment, designated leadership, technical controls like encryption and multi-factor authentication, employee training, vendor oversight, and a documented incident response procedure.3eCFR. 16 CFR 314.4 – Elements

Start With the IRS Template

Before you draft anything from scratch, download IRS Publication 5708, “Creating a Written Information Security Plan for your Tax & Accounting Practice.” It is written specifically for smaller firms and lays out the compliance requirements and professional responsibilities in the order you need to address them.1Internal Revenue Service. IRS, Security Summit Remind Tax Pros They Must Have a Written Information Security Plan to Protect Client Data IRS Publication 4557 covers the underlying data-safeguarding expectations for tax professionals and is worth reading alongside it.4Internal Revenue Service. Publication 4557 – Safeguarding Taxpayer Data

Everything below explains what each required section of the plan needs to accomplish. Use it to fill in the template accurately rather than treating the template as a form to sign and file.

Conduct a Written Risk Assessment

The risk assessment is the foundation of the plan and, under the Safeguards Rule, it must be in writing and include criteria for evaluating and categorizing the risks your firm faces.3eCFR. 16 CFR 314.4 – Elements Walk through what could actually go wrong: a laptop stolen from a car, an employee falling for a phishing email, a former staffer whose credentials were never revoked, a breach at your cloud storage provider, ransomware locking your server in the middle of tax season.

For each risk, document the controls you already have and whether they are adequate. A locked filing cabinet is a control, but not if the key hangs on a hook beside it. Rate both the likelihood of each threat and the severity of harm it would cause, then let those ratings drive where you spend money. Categorize your data by sensitivity as well, because a mailing address does not need the same protection as a Social Security number.

Reassess periodically, and always after a material change: new tax software, new hires, a new office, a new client portal.3eCFR. 16 CFR 314.4 – Elements An annual review at minimum keeps the document honest.

Designate a Qualified Individual

The rule requires you to designate a “Qualified Individual” responsible for overseeing and enforcing the program.5Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know That person can be an employee, someone at an affiliate, or a third-party service provider. If you are a solo practitioner, it is you. In a small firm, it is often the managing partner or the outsourced IT provider.

Whoever fills the role needs authority to make security decisions and enough technical knowledge to judge whether the safeguards are working. Outsourcing does not shift ultimate responsibility away from the firm. Build in regular reporting from the Qualified Individual to firm leadership on incidents and test results.

Map Where Client Data Lives

Before you write controls, inventory every place client data exists: tax preparation software, email, cloud storage, physical filing cabinets, portable drives, laptops, and any personal devices employees use for work. Trace the data from the moment a client hands over a W-2 to the moment the record is disposed of. Every system that touches client data falls within the plan’s scope.3eCFR. 16 CFR 314.4 – Elements

Personal phones and home computers are the awkward part. Bring-your-own-device arrangements carry more risk because you have limited control over the hardware. Either prohibit personal devices for client data or impose specific requirements like device encryption, screen locks, and remote wipe.

Implement the Required Technical Safeguards

Access Controls

Each employee should have access only to the systems and files they need for their job.3eCFR. 16 CFR 314.4 – Elements An administrative assistant does not need to open every client return; an associate working individual returns does not need access to unrelated business entity files. Review access rights regularly and revoke them immediately when someone leaves or changes roles. Remote access through VPN or remote desktop is a common attack pathway, so log every session and restrict remote access to approved devices.

Multi-Factor Authentication

The revised Safeguards Rule requires multi-factor authentication for anyone accessing your information systems.3eCFR. 16 CFR 314.4 – Elements That means at least two of three factors: something you know (password), something you have (phone or hardware token), or something you are (fingerprint or face scan). The only way around it is a written approval from your Qualified Individual of an alternative control providing equivalent security. For most firms the practical answer is to turn on MFA everywhere: tax software, email, cloud storage, VPN, and anything else holding client data.

Encryption

Client information has to be encrypted both in transit over external networks and at rest.3eCFR. 16 CFR 314.4 – Elements In transit means current protocols like TLS 1.2 or higher for web connections and encrypted email for messages containing personal information. Older protocols like SSL are deprecated. At rest means full-disk encryption on every laptop and workstation, plus confirmation that your cloud and software providers encrypt stored data on their end. If encryption is not technically feasible for a specific system, the Qualified Individual must approve an alternative in writing.

Monitoring and Patching

Every device should run current anti-malware software, ideally managed from a central dashboard so you can verify coverage. Configure firewalls to block anything not specifically needed. Patching is where small firms tend to fall behind, and attackers know it. Operating systems, tax software, browsers, and PDF readers all need security updates applied promptly. Set automatic updates wherever possible and manually check the systems that do not support them.

Physical Safeguards

Technical controls do not help if someone can walk in and photograph a file left on a desk. Lock rooms containing servers or paper records, limit access to authorized personnel, and enforce a clean-desk policy so sensitive documents are put away when not in use. Cable-lock laptops in the office. Restrict USB drives to approved, encrypted models or prohibit them outright. Maintain a visitor log and do not leave non-employees unattended in areas where client data is accessible.

Train Every Employee

Phishing emails impersonating the IRS, a software vendor, or a client are the most common way attackers get into a tax firm. Every person on staff, including administrative employees, needs security awareness training on recognizing phishing, handling client data safely, and reporting suspicious activity.4Internal Revenue Service. Publication 4557 – Safeguarding Taxpayer Data The Safeguards Rule requires policies and procedures that ensure personnel can carry out the security program and stay current on emerging threats.3eCFR. 16 CFR 314.4 – Elements

Train new hires before they touch client data. Refresh the training at least annually. A short monthly email about a recent scam keeps security visible between formal sessions.

Oversee Your Vendors

Your plan does not end at your network’s edge. The Safeguards Rule requires you to select capable service providers, contractually require them to maintain appropriate safeguards, and periodically assess their performance.3eCFR. 16 CFR 314.4 – Elements That covers your tax software provider, cloud storage service, IT support, document shredding vendor, and anyone else who accesses or stores client data on your behalf.

Before signing, confirm the vendor can demonstrate adequate security practices; a SOC 2 audit report is common evidence. Build in a right-to-audit clause, a duty to notify you promptly of any security incident, and an obligation to cooperate in your breach response. A vendor unwilling to agree to basic security terms is a warning.

Retention and Secure Disposal

The Safeguards Rule sets a specific disposal timeline: securely dispose of client information no later than two years after the last date you used it to provide a service, unless the information is required for ongoing business operations, required by law, or targeted disposal is not reasonably feasible.3eCFR. 16 CFR 314.4 – Elements IRS record retention rules usually override that window: the IRS generally recommends keeping records at least three years after filing, and up to seven years in situations like claims involving worthless securities.6Internal Revenue Service. How Long Should I Keep Records?

Once both windows close, dispose of the records securely. Cross-cut shred paper files. Degauss or physically destroy hard drives rather than reformatting them, because standard deletion does not actually remove data from a disk. Keep certificates of destruction for your audit trail.

Back Up Your Data

The IRS recommends backing up sensitive data to a safe, secure external source that is not connected full-time to your network.4Internal Revenue Service. Publication 4557 – Safeguarding Taxpayer Data Ransomware that encrypts your main systems will also encrypt any backup drive left plugged in. Options include an air-gapped backup, an encrypted external drive connected only during the backup window, or a reputable cloud backup service with its own encryption.

Back up daily during tax season and weekly during slower periods. Test the backups by actually restoring files. An untested backup may not work when you need it.

Write the Incident Response Plan

The Safeguards Rule requires a written incident response plan covering your goals, internal processes, roles and responsibilities, communication procedures, and a process for fixing the vulnerabilities that allowed the breach.5Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know The IRS lays out a specific sequence for responding to a data theft:7Internal Revenue Service. Data Theft Information for Tax Professionals

  • Contact your local IRS Stakeholder Liaison immediately. Speed matters, because the IRS can block fraudulent returns filed with stolen client information only if you report quickly. The liaison notifies IRS Criminal Investigation on your behalf.
  • Contact the FBI through your local field office.
  • File a local police report documenting the breach.
  • Report to the FTC if 500 or more people are affected.
  • Notify state tax agencies for every state where you prepare returns, and determine whether each state’s attorney general also needs to be notified. Most states require it.
  • Engage a cybersecurity expert to identify the cause, stop the breach, and prevent recurrence.
  • Notify affected clients by individual letter, coordinating timing with law enforcement so you do not compromise an active investigation.

Build pre-drafted notification templates into the plan, along with a contact list of phone numbers for each of these entities and clear role assignments so every team member knows what to do during a breach. Run a tabletop exercise at least once a year. Describe a hypothetical breach and walk through the plan step by step; the exercise will expose gaps that are invisible on paper.

All 50 states, the District of Columbia, and U.S. territories have breach notification laws with their own deadlines and definitions of personal information. Your response procedure has to be flexible enough to cover any state where you prepare returns.

Test and Update the Plan

Writing the plan is not the end. The Safeguards Rule requires you to regularly test key controls, and for information systems that means either continuous monitoring or a combination of annual penetration testing and vulnerability assessments at least every six months.3eCFR. 16 CFR 314.4 – Elements Penetration testing hires a professional to try to break into your systems and report what they find. Vulnerability assessments are broader scans for known weaknesses.

Evaluate and adjust the program based on test results, changes to your operations, new risk assessment findings, or anything else that could materially affect security posture.3eCFR. 16 CFR 314.4 – Elements Treat the plan as a living document. If a scan finds an unpatched system, update the plan to reflect the corrective action. If you add a new client portal, expand the plan to cover it.

The Small-Firm Exemption

If your firm maintains client information on fewer than 5,000 consumers, the FTC exempts you from certain provisions of the Safeguards Rule, including the written risk assessment, the formal penetration testing schedule, and incident response plan documentation.5Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know You still must have an information security program. The exemption reduces the paperwork and testing burden; it does not eliminate the obligation to protect client data. Most solo practitioners and small firms fall under the threshold, but building to the full rule is the safer approach and leaves you ready if you ever cross the line.

What Happens If You Don’t Have a Plan

The FTC enforces the Safeguards Rule and can investigate firms that lack a compliant program.4Internal Revenue Service. Publication 4557 – Safeguarding Taxpayer Data Enforcement actions can result in consent orders that impose ongoing monitoring and reporting for years, plus civil penalties for subsequent violations. Separately, the IRS has discretionary authority over the e-file program under its suitability standards, and an IRS investigation can lead to suspension or revocation of your Electronic Filing Identification Number, which effectively shuts down a modern tax practice.

The financial damage from a breach itself often exceeds any regulatory penalty. A firm that loses client data faces state breach notification costs, potential lawsuits, forensic investigators, credit monitoring services for affected clients, and reputational harm that drives clients away. Building the plan before something goes wrong costs a fraction of responding to an incident without one.