IR-2019-200, December 6, 2019
WASHINGTON — As National Tax Security Awareness week concludes, the IRS, state tax agencies and the tax industry today reminded tax professionals that federal law requires them to create and follow a written information security plan to protect their clients’ data.
The reminder came as the IRS and its Security Summit partners today completed the fourth annual National Tax Security Awareness Week. The purpose of the week-long educational effort is to encourage individuals, businesses and tax professionals to take steps to protect sensitive data, including their identities and personal information.
“The Security Summit partners have made great progress against tax-related identity theft,” said IRS Commissioner Chuck Rettig. “But we need to do more, and we need the help of taxpayers and tax professionals to continue our momentum. We all have a role to play, especially tax professionals that remain among the most coveted of targets by identity thieves.”
This is part of a larger education effort by the Security Summit partners, a public-private partnership of the IRS, state tax agencies, the nation’s tax industry and tax professionals. This summer, the Summit partners offered tax professionals a Taxes-Security-Together Checklist to consider.
Today, the IRS and Summit partners renewed their call for tax professionals to take time to review the safeguards prior to the start of the 2020 filing season and to take appropriate steps.
With the filing season just weeks away, tax professionals who have a data security plan should review it for updates. Those who don’t have a plan should create one. Having an information security plan is not just a good idea, it’s federal law.
Identity thieves target tax professionals because of the client data they hold. Thieves use stolen data from tax practitioners to create fraudulent returns with more realistic data − that can be harder for the IRS and the Security Summit partners to detect.
To get started on an information security plan, tax professionals can review Publication 4557, Safeguarding Taxpayer Data (PDF). It details critical security measures that all tax professionals should enact. The publication also includes information on how to comply with the FTC Safeguards Rule, including a checklist of items for a prospective data security plan. Tax professionals are asked to focus on key areas such as employee management and training; information systems; and detecting and managing system failures.
The FTC-required information security plan must be appropriate to the company’s size and complexity, the nature and scope of its activities and the sensitivity of the customer information it handles. According to the FTC, each company, as part of its plan, must:
The FTC says the requirements are designed to be flexible so that companies can implement safeguards appropriate to their own circumstances. The Safeguards Rule requires companies to assess and address the risks to customer information in all areas of their operations.
Please note: The FTC currently is re-evaluating the Safeguards Rule and has proposed new regulations. Tax professionals should be alert to any changes in the Safeguards Rule and its effect on the tax preparation community.
WASHINGTON—The Office of the Comptroller of the Currency (OCC) today released enforcement actions taken against…
WASHINGTON – Today, as part of the 30th anniversary celebration of the Community Development Financial…
Treasury imposes sanctions on dozens of Russian banks, securities registrars, and finance officials; OFAC issues…
WASHINGTON—Acting Comptroller Michael J. Hsu today testified on the state of the federal banking system…
As Prepared for Delivery Thank you very much for the opportunity to be here today, and…
As Prepared for Delivery Good afternoon. I’d like to start by thanking our panelists today for…