Reviewed October 5, 2026 · 12-minute read · Educational guidance for U.S. tax professionals

Quick answer: If you suspect client tax data was exposed, act before every detail is known. Contain the incident without destroying evidence, activate your written response plan, contact your cybersecurity professional and cyber insurer, and report client data theft to your local IRS Stakeholder Liaison immediately. Then determine your state, federal, contractual, and client-notification duties with qualified legal and security advisers.

If this is an active incident: do not rely on this article as your only response resource. Use a clean device to contact your security provider, legal counsel, cyber insurer, and the IRS. Avoid making public statements or promising reimbursement until the facts and applicable obligations are understood.

A data breach at a tax practice is not an ordinary IT problem. Stolen taxpayer information may be used to file fraudulent returns, compromise an Electronic Filing Identification Number (EFIN), take over client accounts, or impersonate the firm. The first few hours matter because fast reporting can help the IRS block fraudulent returns and help investigators preserve evidence.

This tax preparer data breach response plan turns official IRS and Federal Trade Commission guidance into a practical sequence for solo preparers and small firms. It complements your Written Information Security Plan; it does not replace incident-specific legal, forensic, or insurance advice.

What Counts as a Tax-Practice Security Incident?

Do not wait for a confirmed mass theft before activating your plan. Begin documenting and investigating when you discover a credible sign that taxpayer information, credentials, or systems may have been accessed without authorization.

Warning signs identified by the IRS include:

  • Client e-filed returns are rejected because a return using the same Social Security number was already filed.
  • You receive more e-file acknowledgements than the number of returns your firm submitted.
  • Clients respond to messages that your firm did not send.
  • Your computer becomes unusually slow, the cursor moves unexpectedly, or you are locked out of a device or network.
  • You receive IRS notices about clients you do not represent, unrequested transcripts, or a compromised CAF number.
  • A laptop, backup drive, paper file, email account, tax-software account, or cloud-storage account containing client information is lost or accessed by an unauthorized person.

An alert is not proof that every record was stolen. It is a reason to preserve evidence, limit further exposure, and involve the people named in your response plan.

The First 15 Minutes: Stabilize the Situation

1. Record what you observed

Write down the time, device, user, alert, error message, affected account, and person who discovered the incident. Take screenshots or photographs if your security adviser has instructed you to do so. Start an incident log and record every material action, decision, call, and instruction.

2. Stop additional loss without destroying evidence

The FTC advises businesses to secure affected operations quickly. Disconnect a compromised device from the network if it is safe to do so, but do not automatically shut it down, wipe it, reinstall software, or delete suspicious files. Those actions can destroy evidence that a forensic investigator may need. If ransomware, an active intruder, or unsafe equipment is involved, follow the instructions of your security provider or emergency responder.

3. Move communications to a clean channel

If email or the office network may be compromised, do not use them to coordinate the response. Use a known-clean device and a trusted phone number to contact your incident lead, technology provider, attorney, and insurer. Confirm identities before sharing incident details.

4. Activate the response section of your WISP

Your tax preparer WISP should identify who has authority to make decisions, which vendors must be contacted, where clean backups are stored, and how the firm will continue time-sensitive filing work.

The First Hour: Assemble the Response Team

A solo practice may have a small response team, but the functions are the same. Contact the people who can help you contain the event, understand legal obligations, preserve insurance coverage, and communicate accurately.

Contact Why to involve them Information to prepare
Cybersecurity or forensic provider Contain the incident, preserve evidence, determine entry point and scope, and support safe restoration. Timeline, affected devices and accounts, alerts, logs, vendors, and recent changes.
Cyber insurer or broker Open a claim or incident notice and identify approved counsel, forensics, notification, and recovery vendors. Policy number, discovery time, known facts, affected systems, and immediate containment steps.
Privacy or breach counsel Assess notification duties, privilege, contracts, state laws, regulator communications, and client notices. States involved, data types, client count, contracts, service providers, and insurance information.
IRS Stakeholder Liaison Notify the IRS of tax-professional client data theft so appropriate IRS functions can respond. Your contact information, PTIN and EFIN details, discovery facts, and the documentation requested by the IRS.

Before hiring an outside vendor, check your insurance policy. Some policies require the insurer’s consent or the use of approved providers. Coverage, notice deadlines, sublimits, and consent requirements vary.

The First 24 Hours: Report and Define the Scope

Report client data theft to the IRS immediately

The IRS instructs tax professionals who believe their firm is a victim of data theft to contact their local IRS Stakeholder Liaison. The IRS says speed is critical because early reporting can help it block fraudulent returns filed in clients’ names.

The IRS may request a written incident narrative, firm and representative contact information, the date and discovery method, information about multifactor authentication, affected EFINs or PTINs, and a list of affected taxpayer identification numbers. Follow the IRS’s current secure process. Do not email client names, Social Security numbers, tax returns, or other sensitive records to an address that has not been verified for that purpose.

Determine which data and credentials are involved

Work with qualified responders to answer these questions:

  • Which devices, mailboxes, cloud applications, tax platforms, portals, and backups were accessed?
  • What was the first known unauthorized activity, and how long could access have existed?
  • Did the incident expose Social Security numbers, ITINs, EINs, bank information, identity documents, tax returns, payroll data, authentication codes, PTINs, EFINs, or CAF numbers?
  • How many individuals and businesses may be affected, and in which states do they reside?
  • Did a vendor or subcontractor control the affected system?
  • Is the attacker still active, and have stolen credentials been used elsewhere?

Do not declare the incident contained merely because a password was changed. Your team may need to revoke active sessions, reset tokens, review forwarding rules, rotate API or portal credentials, inspect administrator accounts, and monitor for persistence. Perform these steps from clean systems and under professional direction.

Contact state tax agencies and assess other reporting duties

The IRS advises tax professionals to contact relevant state tax agencies. State breach-notification laws also vary by residence, data type, number of affected people, and other facts. Your attorney should determine whether state attorneys general, consumer-protection agencies, credit bureaus, business partners, professional boards, or other regulators must be notified and by what deadline.

IRS guidance also states that firms should file a report with the FTC if 500 or more people are affected. Confirm the current requirement and the correct filing channel with counsel because other federal or state rules may apply to a particular incident.

The Next 24 to 72 Hours: Communicate Without Creating More Risk

Coordinate client notification

Clients need timely, accurate information, but a rushed notice can contain wrong facts, interfere with law enforcement, or omit legally required language. Coordinate timing and content with counsel, your insurer, investigators, and law enforcement.

A useful notice generally explains what happened, when it happened, what information may be involved, what the firm has done, what the recipient can do, and how to obtain help. The FTC provides a model letter in its Data Breach Response guide. State law may require specific headings, delivery methods, regulator filings, or credit-monitoring offers.

Give tax-specific client instructions carefully

The IRS cautions that a client generally should complete Form 14039, Identity Theft Affidavit, only when the IRS sends a notice or letter or an e-filed return is rejected because of a duplicate Social Security number. Clients may also consider an IRS Identity Protection PIN when appropriate. Use current IRS guidance rather than issuing one blanket instruction to every client.

Prepare a consistent communications record

Keep copies of approved notices, mailing lists, delivery confirmations, call scripts, frequently asked questions, regulator submissions, and client responses. Identify one spokesperson. Staff should not speculate about the cause, attacker, number of victims, or insurance coverage.

Protect Your Cyber Insurance Claim

Cyber and professional liability policies are not interchangeable. A cyber policy may include breach counsel, forensic investigation, notification, credit monitoring, data restoration, business interruption, ransomware response, and certain third-party claims. Actual coverage depends on the policy, endorsements, exclusions, retention, limits, and facts.

To protect the claim process:

  • Give notice as soon as the policy requires, even if scope is still uncertain.
  • Ask whether prior approval is required before retaining counsel, forensic firms, notification vendors, or public-relations support.
  • Preserve invoices, time records, correspondence, forensic reports, notices, and business-interruption calculations.
  • Do not admit liability, promise payment, or agree to a settlement without advice and any required insurer consent.
  • Continue complying with policy conditions and responder instructions.

If your current policy does not clearly address client tax data, credential theft, regulatory proceedings, fraudulent-return response, or vendor incidents, use the next renewal to compare those gaps. Our broader tax preparer insurance guide explains how E&O and cyber coverage address different parts of a firm’s risk.

What Not to Do After a Suspected Breach

  • Do not keep using a suspected device for email, banking, tax software, or client communication.
  • Do not wipe, reformat, or discard equipment before investigators advise you that evidence has been preserved.
  • Do not use compromised email to send passwords, incident plans, client lists, or regulator reports.
  • Do not hide the incident or delay an IRS report while waiting for perfect certainty.
  • Do not notify clients with speculation. Separate confirmed facts from facts still under investigation.
  • Do not publish client identifiers. Use secure reporting channels approved by the receiving agency.
  • Do not assume your software vendor will handle every obligation. Your firm may retain independent duties.

Tax Preparer Data Breach Response Checklist

Keep this condensed checklist with your WISP and offline emergency contacts.

  1. Record the discovery time, symptoms, affected user, device, and account.
  2. Disconnect affected systems when safe; avoid powering off or wiping without professional direction.
  3. Use a clean device and channel to activate the incident-response team.
  4. Notify the cyber insurer or broker and confirm approved response vendors.
  5. Engage qualified forensic and privacy counsel resources.
  6. Report client data theft to the local IRS Stakeholder Liaison immediately.
  7. Identify affected PTINs, EFINs, CAF numbers, systems, vendors, data types, people, and states.
  8. Contact relevant state tax agencies and determine every notification deadline.
  9. Preserve logs, images, devices, communications, receipts, and the incident timeline.
  10. Coordinate accurate client notices and tax-specific protective instructions.
  11. Restore only from known-clean systems and backups after the entry point is addressed.
  12. Complete a lessons-learned review and update the WISP, training, vendor controls, and insurance.

Frequently Asked Questions

How quickly should a tax preparer report a data breach to the IRS?

The IRS says tax professionals should contact their local Stakeholder Liaison immediately and that speed is critical. Do not wait to finish a complete forensic investigation before making the initial report. Provide confirmed facts, clearly identify what is still unknown, and follow the liaison’s instructions.

Does every suspicious email require a breach notification?

No. A phishing email that was never opened is different from confirmed unauthorized access. However, credible indicators should still be recorded and investigated under your WISP. Legal notification duties depend on the incident, information involved, location of affected people, and applicable law.

Should every affected client submit Form 14039?

Not automatically. IRS guidance says clients should generally use Form 14039 when instructed by an IRS notice or when an e-filed return is rejected because of a duplicate Social Security number. Direct clients to current IRS instructions based on their individual situation.

Is an incident-response plan the same as a WISP?

No. An incident-response plan is one operational component of the broader Written Information Security Plan. The WISP also covers risk assessment, access controls, employee training, vendor oversight, testing, data retention, and periodic review.

Will cyber insurance pay every breach expense?

No. Coverage depends on the policy and the facts. Common limitations can include waiting periods, sublimits, excluded systems or events, security-control representations, prior-knowledge provisions, notice requirements, and consent requirements. Review the actual policy with a qualified insurance professional.

Bottom Line

The best time to build a tax preparer data breach response plan is before tax season and before an alert appears. Put verified phone numbers, insurer instructions, secure reporting methods, decision authority, backup communications, and an incident log template inside your WISP. Then test the sequence at least annually and whenever systems, vendors, staff, or services change.

If an incident is already underway, prioritize containment, evidence preservation, professional help, and immediate IRS Stakeholder Liaison contact. Fast, documented, accurate action protects clients more effectively than improvising under pressure.

Primary Sources

Editorial note: This article provides general educational information and is not legal, cybersecurity, tax, or insurance advice. Incident duties and coverage vary. Consult qualified professionals about your facts.

Share.

The Small Business Insured Editorial Team publishes independent, source-led guidance for U.S. tax preparers, bookkeepers, accountants, and other small-business professionals. Our work follows a documented editorial and corrections process and is reviewed against primary government and industry sources.

Comments are closed.

Exit mobile version