
Tax data management for U.S. preparers is a legal obligation, not just good practice. IRS Publication 4557 sets out the Security Six framework, and its sixth control requires full-disk AES-256 encryption on every device that stores taxpayer information. The FTC Safeguards Rule, found at 16 CFR Part 314, backs this up for any tax practice that qualifies as a financial institution under the Gramm-Leach-Bliley Act, which covers nearly all paid preparers. This guide walks through how to encrypt client tax data on Windows and Mac workstations, external drives, and cloud-connected systems, plus the recovery key management and audit documentation the IRS and FTC expect to see during a review.
Quick Answer
Encrypt client tax data by turning on full-disk encryption, BitLocker on Windows or FileVault on macOS, set to AES-256 (XTS-AES 256-bit), on every workstation, laptop, and external drive that touches taxpayer information. Store recovery keys somewhere other than the encrypted device itself, such as a password manager or a fire-rated safe. Document each device's encryption status and recovery key location in your Written Information Security Plan (WISP), since IRS Publication 4557 and the FTC Safeguards Rule require the technical control and the paperwork behind it. This satisfies the sixth and final control in the IRS Security Six framework.
The IRS Security Summit, a partnership between the IRS, state tax agencies, and tax software providers, built the Security Six as six controls every tax professional handling federal returns must have in place. Encryption is one piece of that framework, not the whole thing. All six controls need to work together and get written into a WISP that you review at least once a year. Our IRS Security Six checklist for tax professionals walks through each control in more detail.
The IRS Security Six Controls
- Antivirus software: real-time malware detection and removal
- Firewall protection: network traffic filtering and intrusion prevention
- Multi-factor authentication: secondary verification for system and software access
- Automatic security updates: timely patching of operating systems and software
- Data backup and recovery: tested backup procedures with verified restoration
- Drive encryption: full-disk AES-256 encryption on every device with taxpayer data
A stolen laptop loaded with tax software and client files becomes an identity theft kit the moment it leaves your office, unless the drive is encrypted. Physical access to the storage medium bypasses your Windows or Mac login screen entirely, since a thief can pull the drive and read it from another machine. NIST Special Publication 800-111 identifies full-disk encryption as the effective control for this exact scenario: a lost or stolen device where an attacker has physical possession of the storage media.
Encryption Compliance Check Before Filing Season
The IRS Security Six framework requires AES-256 full-disk encryption on every device storing taxpayer data. Firms without documented, verified encryption controls risk FTC enforcement action, state regulatory penalties, and closer scrutiny of PTIN privileges during a review. Encryption has to be enabled and tested, not just purchased, and it needs to be documented in your WISP before the 2027 filing season opens.
The Advanced Encryption Standard with a 256-bit key, AES-256, is the algorithm the IRS Security Six requires for drive encryption. NIST adopted AES in Federal Information Processing Standard 197 (FIPS 197), and 256-bit keys provide such an enormous number of possible combinations that brute-force attacks against a properly implemented AES-256 key are computationally infeasible with current technology. Once you turn on BitLocker or FileVault, encryption runs below the operating system, and tax software such as Drake Tax, Lacerte, ProSeries, and TaxAct works normally on the encrypted drive without any change in how you use it. That is what separates full-disk encryption from password-protecting a single file or folder, which offers little protection against someone with physical access to the drive. For a closer look at how AES compares to other cryptographic methods, see our guide on symmetric vs. asymmetric encryption.
How to Encrypt Client Tax Data: Step by Step
Inventory every device and storage medium
List each workstation, laptop, USB drive, external hard drive, and backup device that stores or has ever stored taxpayer data. This inventory becomes a required section of your WISP.
Enable full-disk encryption on primary systems
Turn on BitLocker (Windows 10/11 Pro) or FileVault (macOS) on every workstation, and confirm the cipher is set to AES-256 or XTS-AES 256-bit rather than a weaker default.
Encrypt external and removable storage
Apply BitLocker To Go to Windows USB drives and external hard drives, or use a FIPS 140-2 validated hardware-encrypted drive for cross-platform use.
Generate and store recovery keys off-device
Create a recovery key for every encrypted device and store it in a fire-rated safe, an enterprise password manager, or Active Directory escrow, never on the encrypted device itself.
Document everything in your WISP
Record each device's encryption status, cipher configuration, recovery key location, and the person responsible for it in your Written Information Security Plan.
Test recovery procedures every year
Confirm at least once a year that recovery keys work and that staff know how to report a lost or stolen device. Log the test date and the outcome.
BitLocker Drive Encryption ships with Windows 10 Pro, Windows 11 Pro, and Windows Enterprise at no added cost, and it integrates with the Trusted Platform Module (TPM) chip built into most business laptops made since 2016. Basic activation is under Settings, Privacy & Security, Device Encryption, or through Control Panel. The default configuration can leave cipher strength at AES-128 on some systems, so verify it and set it to XTS-AES 256-bit through Group Policy: Computer Configuration, Administrative Templates, Windows Components, BitLocker Drive Encryption, Operating System Drives. Require a startup PIN of at least 8 characters in addition to the TPM check. Pre-boot authentication like this stops someone from booting the drive even if they know the Windows account password, and it satisfies both IRS Publication 4557 Section 10 and FTC Safeguards Rule Section 314.4(e) for encryption at rest. Pairing this with multi-factor authentication, covered in our IRS Tax Pro Account MFA setup guide, closes the same login-bypass gap on the software side.
FileVault provides AES full-disk encryption on any Mac running macOS 10.13 or later, and FileVault 2 encrypts the entire startup disk using XTS-AES-128 with a 256-bit total key length, a configuration that meets IRS Publication 4557's Security Six requirements. Apple Silicon Macs (M1 through M4) and older Intel Macs with a T2 chip already encrypt storage at the hardware level, and FileVault adds software-side key management on top. To turn it on, open System Settings, go to Privacy & Security, FileVault, click Turn On, and authenticate as an administrator. Choose a recovery method: an iCloud account works for a solo practitioner, while a local recovery key with a documented storage procedure fits a firm with multiple staff better. Record the 24-character recovery key immediately. For firms running both Windows and Mac systems, document each platform's encryption configuration separately in your WISP, including who is responsible for each device type and where its recovery key lives.
Client Tax Data Encryption Compliance Checklist
- Enable BitLocker (XTS-AES 256-bit) on all Windows workstations and laptops
- Enable FileVault on all macOS systems and verify encryption status
- Encrypt all USB drives and external storage with BitLocker To Go or hardware encryption
- Generate a recovery key for every encrypted device and store it off-device
- Document recovery key storage locations and authorized personnel in your WISP
- Confirm cipher strength is AES-256, not a weaker default
- Include an encrypted device inventory in your WISP
- Test recovery key procedures at least once a year and log the outcome
Security Six encryption requirements cover more than your primary computer. IRS Publication 4557 Section 10 requires encryption on USB drives, external hard drives, portable SSDs, network-attached storage, and any backup media that has ever held taxpayer data. A preparer can have full-disk encryption running on a laptop and still leave an unencrypted USB drive in a car or a bag, and that unencrypted drive is usually the one that goes missing, not the workstation. Hardware-encrypted external drives, such as the Apricorn Aegis Secure Key, Kingston IronKey, or iStorage diskAshur PRO3, run AES-256 through a dedicated chip on the drive itself, so they work across Windows, macOS, and Linux without extra software and often carry FIPS 140-2 or FIPS 140-3 validation that supports your audit documentation. They typically cost more than standard external storage, but they remove cross-platform compatibility problems and add physical brute-force protection.
Recovery keys are the fallback when normal authentication fails: a forgotten PIN, a corrupted TPM chip, or an employee who left the firm and needs their device's data preserved. The FTC Safeguards Rule at 16 CFR 314.4(c)(4) requires documented key management with written procedures, defined access controls, and an audit trail for every encryption key protecting covered consumer information. Store recovery keys in a fire-rated safe with a documented access list, a bank safety deposit box with named authorized signatories, or an enterprise password manager such as those covered in our guide to password security, since these keep an access log that supports the Safeguards Rule's audit trail requirement. Windows-managed environments can also use Active Directory or Microsoft Entra ID escrow, which centralizes recovery keys with administrator access logging. Whichever method you pick, your written procedures should specify who can authorize key retrieval and how to reach that person outside normal business hours, since device failures do not wait for convenient timing.
Key Takeaway
A recovery key stored on the encrypted device it protects provides no real protection. Keep recovery keys in a physically separate, access-controlled location, and document who can retrieve them and when. Without that documentation, an encryption control can fail an audit even when the technical setup is correct.
Cloud storage does not remove the need to encrypt client tax data, it shifts part of the responsibility to your vendor. IRS Publication 4557 and the FTC Safeguards Rule both require encryption at rest and in transit. Tax-specific platforms such as ShareFile, SmartVault, and Canopy generally encrypt stored data with AES-256 and transmit it over TLS 1.2 or TLS 1.3, but confirm those specific controls in each vendor's security documentation and note that verification in your WISP rather than assuming it. Local devices still need their own encryption even when most files live in the cloud, since tax software routinely caches client data locally and downloaded files can persist on a workstation long after the original task is done.
What to Prepare for an IRS Encryption Compliance Review
- Current device inventory with verified encryption status for each system
- Encryption configuration records, such as BitLocker Group Policy exports or FileVault status screenshots
- Written recovery key storage and access procedures
- Annual recovery testing records with dates and outcomes
- Staff training records on encrypted device handling and lost device reporting
Get your encryption controls documented in a WISP
A custom Written Information Security Plan from Bellator starts at $749 for firms with up to 5 users, with larger practices quoted separately, and typically saves 20 to 40 hours of billable time compared with writing one from scratch.
Talk with a cybersecurity expert
Get a straightforward review of your encryption, backup, and WISP documentation gaps before your next filing season.
Frequently Asked Questions
Yes. IRS Publication 4557 lists drive encryption as the sixth control in the Security Six framework, and it applies to every paid preparer with access to taxpayer data, not just large firms.
AES-256, applied as full-disk encryption through tools like BitLocker (XTS-AES 256-bit on Windows) or FileVault (macOS). File-level or folder-level passwords do not meet this requirement.
IRS Publication 4557 Section 10 covers every device that stores or has stored taxpayer data, including USB drives, external hard drives, and backup media, not just primary workstations.
NIST's post-quantum cryptography guidance treats AES-256 as resistant to quantum attacks for the foreseeable future. The algorithms most exposed to quantum computing are asymmetric ones like RSA, which NIST began standardizing quantum-resistant replacements for in 2024. BitLocker or FileVault encryption does not need to change because of this.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



