IRS Publication 4557: Safeguards, Breach Response, and Penalties

IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS’s guide for tax professionals on how to protect client information from theft and misuse. It doesn’t create new law. It translates two existing federal requirements into practical steps: Internal Revenue Code Section 7216, which restricts how you can use or share taxpayer information, and the FTC Safeguards Rule, which requires every paid tax preparation firm to maintain a written information security program. If you prepare returns for compensation, both apply to you, and Publication 4557 is how the IRS expects you to meet them.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data

What Publication 4557 Actually Requires

The publication pulls from two separate legal sources, and they do different things.

Section 7216 is about confidentiality. It makes it a federal crime for a preparer to disclose or misuse information a client provides during return preparation, and that information is defined broadly: names, addresses, Social Security numbers, income, deductions, and anything else on or connected to the return.2Office of the Law Revision Counsel. 26 USC 7216 – Disclosure or Use of Information by Preparers of Returns

The FTC Safeguards Rule is about mechanical security. It applies to “financial institutions” under FTC jurisdiction and specifically names tax preparation firms as covered entities. Every covered firm must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards. Firms with fewer than 5,000 customers are exempt from certain provisions, but the core obligation to protect client data still applies.3Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know

Publication 4557 puts those two obligations into one operational playbook.

Your Written Information Security Plan

The Written Information Security Plan (WISP) is the document that ties everything together. It describes your firm’s security policies, the people responsible for them, and how you’ll respond when something goes wrong. The IRS published a companion guide, Publication 5708, to help small and mid-size practices build one from scratch.4Internal Revenue Service. IRS Publication 5708 – Creating a Written Information Security Plan for Your Tax and Accounting Practice

At minimum, your WISP needs to cover:

  • A designated security coordinator responsible for the whole program. In a small practice, this is often the firm owner.
  • A risk assessment identifying the client information you handle, where it lives, and the threats it faces. Repeat this regularly.
  • A hardware inventory listing every device that stores or processes taxpayer data, including computers, external drives, printers with internal memory, and mobile devices.
  • Your administrative, technical, and physical safeguard policies.
  • Service provider oversight. If you use cloud tax software, outsource IT, or share data with any third party, your contracts must require appropriate safeguards.
  • An incident response plan for what happens after a breach.

The plan must fit your firm. A solo practitioner working from home faces different risks than a 20-person office with multiple locations. What matters is that the WISP reflects your actual operations.4Internal Revenue Service. IRS Publication 5708 – Creating a Written Information Security Plan for Your Tax and Accounting Practice

Required Safeguards

Publication 4557 sorts security measures into three overlapping categories. Thinking in categories helps you spot gaps.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data

Administrative Safeguards

These are your people-and-process controls. Your security coordinator runs the program, but everyone in the firm needs training on phishing, handling sensitive paper, and reporting anything suspicious. Train regularly, not just at orientation.

Remote work deserves special attention. If employees access client data from home or on the road, they should use company-approved devices and connect through a virtual private network. Working from public Wi-Fi is the kind of everyday lapse that leads to compromised credentials.

Limit data access to the people who need it. Not every staff member needs every client file. Publication 4557 also recommends audit logs that record who accessed what and when.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data

Technical Safeguards

Multi-factor authentication is required for anyone accessing systems that hold client information. Logging in has to require something beyond a password: a code sent to a phone, a hardware token, or a biometric.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data For a small practice, MFA is probably the single most effective step, because stolen passwords are how most breaches start.

Taxpayer data has to be encrypted, whether it’s sitting on a hard drive or moving through email. Anti-malware software belongs on every device, including routers and tablets, set to update automatically. Patch operating systems and tax software promptly when vendors release security updates. Delayed patches leave known vulnerabilities open.

Your network should sit behind a properly configured firewall that blocks unauthorized access and logs suspicious activity. Vulnerability scanning helps you find gaps before someone else does.

Physical Safeguards

Physical security protects against the oldest form of data theft: someone walking off with files. Lock the doors to rooms holding servers or paper records, and restrict access. Alarm systems add another layer.

Paper records with client information belong in locked cabinets when not in use. Publication 4557 recommends a clean desk policy so that no sensitive documents are left out at the end of the day.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data

Disposal is where firms often slip. Shred paper with a cross-cut shredder; a strip-cut model isn’t enough. Old hard drives, USB sticks, and printers with internal memory must be securely wiped or physically destroyed before you sell, donate, or throw them away. Deleting files doesn’t remove recoverable data.

Rules on Using and Sharing Client Information

You can use client information to prepare that client’s return without asking. But if you want to use it for anything else, such as recommending investment products, marketing mortgage services, or sharing data with a third-party vendor, you need the client’s written consent first. The consent document must identify you by name, name the client, describe exactly what information you plan to share or use, explain the purpose, and identify the specific recipient. A single consent form cannot authorize both uses and disclosures; those require separate written documents.5GovInfo. 26 CFR 301.7216-3 – Disclosure or Use Permitted Only With the Taxpayers Prior Consent You also cannot condition your services on the client signing a consent. Doing so makes the consent involuntary and invalid.

Some disclosures are permitted without client consent, including sharing information with the IRS itself, disclosures required by court order, and providing data to other preparers working on the same return.6eCFR. 26 CFR 301.7216-2 – Permissible Disclosures or Uses Without Consent of the Taxpayer

What to Do If You’re Breached

Even well-prepared firms get hit. Your incident response plan should cover the immediate aftermath so you’re not improvising under pressure.

Contain and Investigate

Isolate compromised systems from the rest of your network to stop the bleeding. Then figure out what was accessed, what data was exposed, and how many clients are affected. Preserve logs and evidence for law enforcement and remediation, and run a forensic review to identify the root cause so you can close the vulnerability.

Notify the IRS

Contact your local IRS Stakeholder Liaison immediately. The Stakeholder Liaison notifies IRS Criminal Investigation and other relevant divisions for you. If the IRS learns quickly, it can flag affected clients’ accounts and block fraudulent returns filed in their names.7Internal Revenue Service. Heres Who Tax Pros Should Contact if Their Business Suffers a Data Theft or Loss

Notify the FTC If 500 or More Consumers Are Affected

Under an amendment to the Safeguards Rule, financial institutions, including tax firms, must notify the FTC within 30 days of discovering a breach involving the unencrypted information of at least 500 consumers. The notice must describe the event and the number of consumers affected.8Federal Trade Commission. FTC Amends Safeguards Rule to Require Non-Banking Financial Institutions to Report Data Security Breaches

Notify Affected Clients

State breach notification laws govern client notice, and they vary. States with numeric deadlines generally require notification within 30 to 60 days of discovery; others use open-ended language like “without unreasonable delay.” Your notice should describe what happened, what information was exposed, and what you’re doing to protect the affected individuals.

Review Afterward

Once the crisis is contained, run a post-incident review. What controls failed? Did staff follow the response plan? Document forensic findings, remediation steps, and all communications. That documentation protects you legally and feeds directly into an updated WISP.

Business Identity Theft: When to File Form 14039-B

A data breach doesn’t always produce fraudulent returns, but when it does and your firm’s Employer Identification Number is being used to file fake returns or bogus W-2s, you’re dealing with business identity theft.

Warning signs include:

  • E-filed returns rejected because the IRS already has a return on file for a period you haven’t filed.
  • IRS notices about returns you didn’t file, W-2s you didn’t submit, or balances you don’t owe.
  • Correspondence about a business you never registered.

If any of these happen, file Form 14039-B, Business Identity Theft Affidavit, with the IRS. The form is also used by trusts, estates, and tax-exempt organizations. Include supporting documentation to avoid processing delays.9Internal Revenue Service. Report Identity Theft for a Business If you had a breach but see no evidence of fraudulent filings, Form 14039-B is not required.

Penalties for Non-Compliance

The consequences come from multiple directions and can stack.

Under Section 6713, each unauthorized disclosure or use of tax return information carries a $250 civil penalty, capped at $10,000 per preparer per calendar year. When the violation is connected to identity theft, the penalty rises to $1,000 per violation with a $50,000 annual cap, tracked separately from the standard cap.10Office of the Law Revision Counsel. 26 USC 6713 – Disclosure or Use of Information by Preparers of Returns

A knowing or reckless violation of Section 7216 is a misdemeanor punishable by up to one year in prison and a fine of up to $1,000. When the violation involves identity theft covered by Section 6713(b), the maximum fine rises to $100,000.2Office of the Law Revision Counsel. 26 USC 7216 – Disclosure or Use of Information by Preparers of Returns

Safeguards Rule violations can trigger separate FTC enforcement. As of the January 2025 inflation adjustment, the FTC can seek civil penalties of up to $53,088 per violation, and that figure adjusts each year. Because “per violation” can mean per affected consumer or per day of non-compliance, penalties can grow quickly for firms handling thousands of returns.11Federal Register. Adjustments to Civil Penalty Amounts

For most practices, the most immediately devastating consequence is losing the ability to e-file. The IRS can revoke a firm’s Electronic Filing Identification Number, and any preparer who expects to file 11 or more returns in a year is required to e-file. Losing that privilege essentially shuts down a modern tax practice.12Internal Revenue Service. Internal Revenue Manual 8.7.13 – e-file Cases

Keeping Your Program Current

Publication 4557 is not a set-it-and-forget-it document, and neither is your WISP. The IRS recommends checking your e-file applications and PTIN accounts weekly for unexpected filing activity, deactivating EFINs you’re no longer using, and withdrawing outstanding powers of attorney for clients who have moved on.1Internal Revenue Service. IRS Publication 4557 – Safeguarding Taxpayer Data

Re-evaluate your security program whenever the business changes. New employees, new offices, new software, or a shift to remote work all create risks your original plan didn’t contemplate. The FTC Safeguards Rule specifically requires you to adjust your program in light of changes to business operations or the results of security testing.4Internal Revenue Service. IRS Publication 5708 – Creating a Written Information Security Plan for Your Tax and Accounting Practice Tax season creates tunnel vision, and security reviews tend to get pushed to “after April.” The firms that get breached are almost always the ones that let their plans go stale.