Skip to content
Bellator Cyber Guard
Tax16 min readDeep Dive

Tax Document Encryption Requirements: What the IRS Expects

GLBA and IRS Publication 4557 require TLS 1.2+ encryption on every tax document transmission, including scan-to-email. See the 2026 compliance checklist.

By Bellator Cyber Guard Security Team
Tax Document Encryption Requirements: What the IRS Expects - tax document encryption requirements

Tax document encryption requirements come from two federal sources: the IRS Publication 4557 security standards and the Federal Trade Commission's Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA). Together they require every tax preparer to encrypt client data at rest and in transit, including documents sent through the scan-to-email feature built into office copiers and multifunction printers. The GLBA scan-to-email encryption requirements are simple: any device that scans a W-2, a driver's license, or a Social Security card and emails it must route that transmission through TLS 1.2 or higher, the same standard that applies to every other email and cloud connection in the practice. Social Security numbers, bank account numbers, and completed tax returns are exposed the moment they leave an unencrypted scanner relay, long before the file ever reaches an inbox.

Quick Answer

GLBA scan-to-email encryption requirements fall under the FTC Safeguards Rule and IRS Publication 4557: any scanner, copier, or multifunction printer that emails a scanned tax document must send that email over TLS 1.2 or higher, and the resulting file must carry the same AES-256 protection as any other taxpayer data once it lands on a server or workstation. Neither rule carves out an exception for scanners. A multifunction printer left on its default unencrypted SMTP relay creates the same compliance exposure as an unencrypted email server.

These requirements aren't abstract. According to the IRS Security Summit, more than 370 data breach incidents affected tax professionals in 2025, compromising roughly 458,000 client records. IBM's Cost of a Data Breach Report puts the average cost of a breached record in the financial services sector at $374, which means a breach touching just 200 client records runs about $74,800 in response costs alone, before any FTC penalty applies.

Tax Cybersecurity By The Numbers

370+
Breach incidents in 2025

Tax professionals affected, per the IRS Security Summit

$374
Average cost per breached record

Financial services sector, IBM Cost of a Data Breach Report

$50K
Maximum FTC penalty per violation

Civil penalty under the FTC Safeguards Rule

Encryption converts readable data into coded ciphertext that only someone with the correct decryption key can read. For a tax practice, two standards do almost all of the work.

Advanced Encryption Standard with 256-bit keys (AES-256) is the symmetric encryption algorithm the IRS and the National Institute of Standards and Technology (NIST) recommend for data at rest, meaning anything stored on a server, workstation, laptop, backup drive, or inside a scan-to-email device before it sends the file. A single shared key encrypts and decrypts the data, which is why AES-256 can protect an entire disk or database without a noticeable slowdown.

Transport Layer Security (TLS), the protocol that encrypts data while it moves across a network, covers everything in transit. IRS Publication 4557 sets TLS 1.2 as the floor and recommends TLS 1.3. This is the setting that determines whether a scan-to-email transmission, a cloud sync, or a client portal upload is readable if it's intercepted. Asymmetric encryption, used in tools like S/MIME email certificates, plays a smaller supporting role, typically handling key exchange and identity verification rather than encrypting bulk files. See our guide to symmetric versus asymmetric encryption for a full comparison.

2026 PTIN Renewal Ties to Encryption

IRS Publication 4557, updated January 2026, makes encryption a condition of PTIN eligibility rather than a recommended practice. Preparers who can't show compliant encryption during an IRS examination risk PTIN suspension or revocation, plus potential penalties under Internal Revenue Code Section 7216 for unauthorized disclosure of taxpayer information.

IRS Publication 4557, Safeguarding Taxpayer Data, lists the specific controls examiners check for: encryption of all electronic taxpayer data at rest, AES-256 or equivalent strength with documented key management, TLS 1.2 minimum on every transmission channel, full-disk encryption on any device that touches taxpayer data (including scan-to-email capable printers and mobile devices), encrypted backups with keys stored separately from the backup media, and written documentation covering all of it. See our breakdown of the IRS Security Six checklist for the complete list of required controls.

The FTC's Safeguards Rule, issued under the Gramm-Leach-Bliley Act, classifies tax preparation firms as financial institutions and requires a Written Information Security Plan (WISP) documenting how the firm encrypts customer information. The FTC amended the rule in 2021, with full enforcement beginning in 2023, and as of 2026 civil penalties run up to $50,000 per violation, with potential criminal exposure for willful violations that cause client harm. A WISP that doesn't name specific algorithms, key management steps, and the devices they cover, including scanner and copier email relays, won't satisfy either regulator. For the specific role the rule assigns inside a firm, see our guide to the FTC Safeguards Rule qualified individual requirement.

Need a WISP that documents this correctly?

Bellator Cyber Guard builds a custom Written Information Security Plan starting at $749 for up to 5 users, with a custom quote for larger practices. Most firms save 20 to 40 billable hours compared to drafting the encryption and key management language from scratch.

Tax Document Encryption Compliance Checklist

  • Confirm every scanner, copier, and multifunction printer that emails documents uses TLS 1.2 or higher, not an unencrypted SMTP default
  • Enable full-disk encryption (BitLocker or FileVault) on every workstation, laptop, and mobile device that accesses taxpayer data
  • Enable AES-256 database encryption on servers and practice management systems storing client information
  • Disable SSL and TLS 1.0/1.1 on email servers and web applications, and confirm TLS 1.2+ with the SSL Labs Server Test
  • Replace unencrypted email for tax document delivery with a secure client portal or S/MIME certificate-based email
  • Encrypt all backups with AES-256 and store the encryption keys separately from the backup media
  • Document every encryption method, key management procedure, and covered device in the Written Information Security Plan
  • Audit encryption status on all devices, including scan-to-email hardware, at least once a quarter

Tax Document Encryption: Implementation Roadmap

1

Inventory every device that touches taxpayer data

List workstations, servers, cloud platforms, backup systems, and any scanner or copier with a scan-to-email feature. This inventory is the foundation of both the encryption plan and the WISP.

2

Turn on full-disk encryption

Activate BitLocker on Windows 10/11 Pro or FileVault 2 on macOS for every workstation and laptop, and store recovery keys separately from the encrypted device.

3

Fix the scan-to-email relay setting

Check the SMTP configuration on every multifunction printer and copier. Most default to an unencrypted relay; reconfigure them to use TLS 1.2 or higher, or route scans through a secure portal instead.

4

Lock down every other transmission channel

Configure TLS 1.2+ on email servers and cloud connections, then test public-facing servers with the SSL Labs Server Test and aim for an A or A+ rating.

5

Document and review quarterly

Write the specific algorithms, key management procedures, and covered devices into the WISP, then verify encryption status on all devices each quarter.

Encryption is only as strong as the key management behind it. IRS Publication 4557 expects documented procedures for how keys are generated, stored separately from the data they protect, rotated (annually for most systems and quarterly for high-value databases), restricted to authorized staff, and destroyed when a system is retired. An enterprise password manager or a cloud key management service gives most small practices the access logging examiners look for without building anything custom.

Scan-to-email devices deserve the same scrutiny as a server. Many multifunction printers ship with an unauthenticated SMTP relay pointed at an internal mail server, which satisfies neither the TLS 1.2 minimum nor the access logging the FTC Safeguards Rule expects from a financial institution's customer information system. Check the device's network settings against the mail provider's encrypted relay requirements, and if the printer can't support TLS 1.2 or higher, route scanned documents through a secure client portal instead.

Key Takeaway

A compliant tax practice treats every device that touches client data the same way, including scanners and copiers with a scan-to-email feature. Full-disk encryption, TLS 1.2 or higher in transit, and documented key management are the three elements examiners check, and all three belong in one Written Information Security Plan.

Encryption isn't a one-time project. IRS examiners expect proof of continuing compliance as a practice adds devices, staff, and software through the year, so build a quarterly check into the calendar: confirm device encryption is still active, retest the TLS configuration, review key access logs, and verify that any new scanner or printer meets the same TLS 1.2 standard as the rest of the network. For a broader seasonal checklist that covers more than encryption, see our tax season cybersecurity checklist, and review what a gap can cost in our breakdown of WISP penalties.

Talk with a cybersecurity expert

Bellator Cyber Guard can review your firm's encryption setup, including scan-to-email devices, against IRS and FTC requirements.

Frequently Asked Questions

Not by name. The Gramm-Leach-Bliley Act and the FTC Safeguards Rule require encryption for any transmission of customer information, and a scanner or copier emailing a tax document is a transmission like any other, so the same TLS 1.2 minimum applies.

Older copiers and printers sometimes lack firmware support for TLS 1.2 or higher. Disable the scan-to-email feature and route scanned documents through a secure client portal or an encrypted email client instead, then document the change in the WISP.

No. A password-protected PDF doesn't satisfy the IRS or FTC encryption requirement on its own, because the email carrying it may still travel unencrypted and the password is often sent through that same channel. TLS 1.2 or higher on the transmission itself, not a file password, is what Publication 4557 and the Safeguards Rule require.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.