Data Breach Response for Tax Professionals
When a breach happens, every minute counts. Know exactly what to do with a plan built for tax professionals.
By the Numbers
What Tax Professional Data Breach Response Covers
Immediate Containment
Isolate affected systems, change credentials, and preserve evidence within the first hour.
IRS Notification (Form 14039)
File Identity Theft Affidavits and notify the IRS Stakeholder Liaison within required timeframes.
Client Notification
Communicate with affected clients using compliant notification templates and provide next steps.
Law Enforcement Reporting
File reports with the FBI IC3, local police, and state attorneys general as required by law.
Forensic Investigation
Conduct or commission a forensic analysis to determine the scope and cause of the breach.
Recovery & Hardening
Restore systems from clean backups and implement additional security measures to prevent recurrence.
How to Get Started
Detect & Contain
Identify the breach, isolate affected systems, and stop ongoing unauthorized access immediately.
Assess & Document
Determine what data was compromised, how many clients are affected, and preserve all evidence.
Notify & Report
Contact the IRS, affected clients, law enforcement, and state regulators per legal requirements.
Recover & Strengthen
Restore operations, implement lessons learned, and update your security plan.
Frequently Asked Questions
Immediately isolate affected systems from your network, change all administrative passwords, and begin documenting everything. Do not turn off computers — preserve forensic evidence.
Contact your local IRS Stakeholder Liaison, report to the Treasury Inspector General (TIGTA), file Form 14039 for each affected taxpayer, and email the IRS at dataloss@irs.gov.
Yes, most states require individual notification to affected clients, typically within 30-60 days. You should provide them with credit monitoring and identity theft protection guidance.
Yes, if the IRS determines inadequate security measures led to the breach, your Electronic Filing Identification Number (EFIN) can be suspended or revoked.
If something may be happening now
Slow the damage, preserve evidence, and get a clear response owner
Do not erase logs, reinstall systems, or keep using a device you believe is compromised. Isolate what you safely can, record what happened, and contact someone who can help you triage the next step.
- Isolate affected access
- Preserve useful evidence
- Assign one response owner
Calm first-response order
- 01
Contain without destroying evidence
Disconnect affected access where safe, but avoid wiping or “cleaning” systems first.
- 02
Record the facts
Capture times, messages, affected accounts, device names, and actions already taken.
- 03
Triage and recover in order
Confirm scope, secure identities, restore safely, and document what changes afterward.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
