Stop Identity Theft at Your Tax Practice
Tax-related identity theft costs billions annually. Protect your clients and your practice with proven prevention strategies.
By the Numbers
What Identity Theft Prevention for Tax Professionals Covers
IP PIN Enrollment
Help clients obtain Identity Protection PINs from the IRS for an additional layer of filing security.
Fraud Detection Signals
Recognize red flags including duplicate SSNs, address changes, and suspicious refund requests.
Client Verification
Implement robust identity verification procedures before accepting new clients.
Staff Awareness Training
Train your team to spot social engineering attempts and fraudulent document submissions.
Secure Document Handling
Encrypted storage, secure shredding, and chain-of-custody procedures for sensitive documents.
Rapid Response Protocol
Pre-built response procedures for when identity theft affecting your clients is discovered.
How to Get Started
Verify Client Identity
Use multi-point verification for all new clients — photo ID, SSN validation, and prior year return comparison.
Secure All Data
Encrypt client files, use secure portals for document exchange, and implement access controls.
Monitor for Red Flags
Watch for rejected e-files, duplicate SSN alerts, and suspicious activity patterns.
Respond Immediately
If fraud is detected, file Form 14039, notify the client, and report to the IRS.
Frequently Asked Questions
Criminals target tax pros because they have concentrated access to SSNs, financial data, and filing credentials. Phishing, stolen credentials, and insider threats are the primary attack vectors.
An IP PIN is a six-digit number assigned by the IRS that prevents someone else from filing a tax return using a taxpayer SSN. All taxpayers can now voluntarily opt in at irs.gov/ippin.
File Form 14039 (Identity Theft Affidavit) with the IRS, advise the client to request an IP PIN, submit a paper return, and report the incident to local law enforcement.
Require government-issued photo ID, validate SSN against prior year returns when possible, use knowledge-based authentication questions, and consider third-party identity verification services.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
