IRS Identity Theft Response for Tax Practitioners: Data Breach Protocol and Form 14039 Guide

Since 2001

25 years continuous operation

IRS Authorized

E-File Transmitter

All 50 States

Federal and state e-file

TaxWise Reseller

CCH TaxWise authorized dealer

A tax preparation firm holds a concentrated inventory of what identity thieves need most: Social Security numbers, EINs, bank account and routing numbers, health coverage details from Form 8962, and prior-year filing data that makes a fraudulent return look credible. When that inventory is compromised, the practitioner faces two simultaneous obligations: report to the IRS and protect the clients whose data was exposed. Neither obligation waits. The FTC Safeguards Rule client notification requirement is triggered by unauthorized access, not by a confirmed breach after investigation. The IRS Stakeholder Liaison network expects contact within hours, not days. The practitioner who understands the response sequence before an incident keeps the exposure manageable. The practitioner who figures it out in real time under pressure typically misses one of the windows.

This guide is written for EROs, PTIN holders, AFSP participants, enrolled agents, and CPA tax preparers who operate their own practices or small offices. It does not address the taxpayer experience of being an identity theft victim; it addresses the practitioner's specific response obligations when the firm itself has been breached or when a client's return is rejected because someone else filed first using that client's Social Security number. Both situations require action. This guide covers both.

All IRS program references, form version numbers, and regulatory citations in this guide should be verified at IRS.gov and through applicable legal counsel before relying on them in your practice. IRS programs, form revisions, and applicable state law requirements are subject to change. This guide is informational and does not constitute legal, regulatory, or tax advice.

Why Tax Firms Are High-Value Targets: The Practitioner's Unique Exposure

An identity thief who breaches a single tax preparation firm may walk away with everything needed to file fraudulent returns for dozens or hundreds of taxpayers in a single tax season. That density of high-value data in one place is what makes tax practices disproportionately attractive targets compared to, say, a retail business of comparable size.

What a breach at a tax firm exposes

A well-maintained client file at a tax preparation office typically contains the following categories of sensitive data, any of which can be exploited independently or in combination:

  • Social Security numbers and EINs. The primary inputs for filing a fraudulent federal return. An SSN paired with a prior-year AGI figure (also in the file) allows a fraudulent return to pass initial IRS validation filters.
  • Bank account and routing numbers. Refund direct deposit credentials. A thief who files a fraudulent return with the client's SSN but a controlled bank account number receives the refund before the legitimate taxpayer files.
  • Health coverage information from Form 8962. Premium tax credit reconciliation data that includes household income, family size, and marketplace plan details, all of which can be used to complete fraudulent returns with plausible-looking healthcare data.
  • Prior-year return data. AGI figures, prior-year refund amounts, filing status history, and dependent SSNs. Each of these passes a different IRS validation check and makes a fraudulent return harder for the IRS to detect automatically.
  • Employer information and W-2 data. Employer EINs, wages paid, and withholding figures that allow a fraudulent return to fabricate a realistic wage income picture.

The dual obligation: protect clients and report to the IRS

Tax preparation firms are financial institutions for purposes of the FTC Gramm-Leach-Bliley Act Safeguards Rule. That classification carries affirmative obligations. When a breach occurs or is suspected, the practitioner has obligations running in two directions at once: toward the IRS (report the breach through the Stakeholder Liaison channel and protect the federal tax administration system from fraudulent filings) and toward affected clients (provide required notification under the Safeguards Rule and applicable state law, and assist those clients in protecting their tax accounts going forward).

These are not optional obligations that can be deferred until the full scope of the breach is known. The Safeguards Rule notification requirement is triggered by unauthorized access, not by a completed investigation. The IRS response process similarly rewards early contact. Practitioners who wait for certainty before acting typically lose the window for the most protective interventions.

See the WISP data security guide for tax preparers for the Written Information Security Plan requirements that govern how tax firms must protect client data before a breach occurs.

The First 24 Hours: IRS Data Theft Response Kit Checklist

DO NOT CLEAN OR RESTORE AFFECTED SYSTEMS BEFORE PRESERVING EVIDENCE

Restoring a compromised system before documenting its state destroys forensic evidence. Disconnect affected systems from the network first. Do not wipe or reimage until you have documented what was on the system, what accounts had access, and what data those accounts could reach. Law enforcement and your cyber insurance carrier will need this information.

The IRS Data Theft Response Kit is the IRS's recommended framework for tax professionals responding to a data theft event. It is a structured response checklist, not a mandatory regulatory filing with fixed deadlines. The distinction matters: the FTC Safeguards Rule client notification obligation IS a binding regulatory requirement with timing dimensions; the IRS Data Theft Response Kit describes what the IRS recommends practitioners do in the hours and days after discovery. Follow both tracks simultaneously.

Isolate and disconnect affected systems

The moment a breach is suspected or confirmed, remove affected workstations, servers, and devices from your network by unplugging network cables and disabling Wi-Fi. Do not turn the machines off. Powering down a compromised system may destroy volatile memory artifacts that investigators need. Leave the machines in their running state, unplugged from the network, until forensic review can occur. If you have a managed service provider or IT support, contact them immediately. If you do not, document the current state of each affected machine (what was open, what accounts were logged in, what files were recently accessed) before anything else is touched.

Preserve evidence: document before you remediate

Write down everything you know about the incident at the time you discover it: when you first noticed the problem, what behavior was unusual, what systems were involved, who had access to those systems, and what client data those systems could reach. If you received a phishing email that you or a staff member clicked, preserve that email. If you noticed unusual login activity on an IRS e-Services account, screenshot the activity log. This contemporaneous documentation protects you in any subsequent investigation, insurance claim, or regulatory inquiry. The practitioner who can produce a written timeline of discovery and response is in a materially better position than one who cannot.

Contact the IRS Stakeholder Liaison (not the general IRS phone line)

The IRS Stakeholder Liaison for your area is the correct first contact, not the general IRS taxpayer helpline. The Stakeholder Liaison network exists specifically to serve tax professionals and can coordinate IRS-side protections for affected clients that the general helpline cannot. See Section 3 of this guide for how to locate the Stakeholder Liaison for your area and what information to have ready when you call.

Notify the FTC at IdentityTheft.gov

Report the breach to the FTC at IdentityTheft.gov. The FTC maintains this reporting portal for identity theft events and uses the data to coordinate with law enforcement and to track fraud patterns. Filing a report does not automatically satisfy any of your client notification obligations, but it creates a record and gives the FTC data to work with. The FTC can also provide guidance specific to business identity theft and data security incidents.

Begin your client notification assessment

Identify every client whose data was or may have been accessible on the compromised systems. This is the starting point for your client notification obligation assessment under both the FTC Safeguards Rule and any applicable state law. You do not need to wait for a complete forensic investigation before beginning notification; the Safeguards Rule triggers on unauthorized access, not on confirmed misuse of data. Consult a licensed attorney as early as possible in the response process to confirm the applicable notification requirements in your state.

Consider filing a report with local law enforcement

A police report creates a formal record of the incident and may be required by your cyber liability insurance carrier. Some state data breach notification laws explicitly reference law enforcement notification as part of the response process. Even if none of these apply, a police report documents the event in a way that can be useful if affected clients or regulators later question the timeline and scope of your response.

The IRS Stakeholder Liaison: Who They Are and How to Reach Them

The IRS Stakeholder Liaison is not a help desk. It is a network of IRS employees assigned to work directly with tax professionals, professional associations, and government entities in specific geographic areas. Stakeholder Liaisons understand the practitioner-side context of a data breach in a way that the general IRS helpline does not, and they have access to IRS-side resources that general phone agents cannot initiate.

How to find your area's Stakeholder Liaison

The IRS publishes a current list of Stakeholder Liaison contacts organized by state and geographic area at IRS.gov. Search for "IRS Stakeholder Liaison contacts" on IRS.gov to find the current directory. Contact information changes when liaison personnel change, so always use the current IRS.gov listing rather than a saved number from a prior year or a third-party compilation.

Your area may also be served by an IRS Taxpayer Advocate Service office that works alongside the Stakeholder Liaison on practitioner matters. The Stakeholder Liaison contact list at IRS.gov is the primary reference; the TAS is a secondary escalation channel for cases where IRS normal processes are causing hardship to affected clients.

What to have ready before you call

When you contact the Stakeholder Liaison, have the following information available:

  • Your EFIN and PTIN (or your firm's EFIN and your individual PTIN if you are an employee of a firm).
  • A description of what happened: when you discovered the incident, what systems were affected, and what you know so far about the scope of the data exposure.
  • An estimate of the number of clients potentially affected.
  • Whether you have already received any reject notices or unusual IRS correspondence suggesting that fraudulent returns may have been filed using your clients' SSNs.
  • Your contact information and the best way and time to reach you during the response process.

What the Stakeholder Liaison can do

The Stakeholder Liaison can act as a direct channel between your firm and the relevant IRS functions during a data breach response. Specifically, the Liaison can:

  • Help coordinate IRS-side monitoring and flagging for affected client SSNs to detect fraudulent filing attempts.
  • Facilitate expedited processing options for affected clients whose returns have been rejected or are caught in identity theft processing queues.
  • Connect you with the appropriate IRS function for specific issues that arise during the response (for example, if a client's refund has already been diverted, or if a fraudulent return has already been accepted).
  • Provide guidance on IRS processes specific to practitioner data theft scenarios that differ from taxpayer self-reported identity theft cases.

The Stakeholder Liaison does not replace legal counsel. Regulatory compliance questions about your specific notification obligations should be addressed with a licensed attorney.

Client Notification Obligations: FTC Safeguards Rule and State Law

CONSULT A LICENSED ATTORNEY FOR YOUR SPECIFIC STATE OBLIGATIONS

State data breach notification laws are subject to amendment. This guide does not state specific state notification timelines as fixed statutory requirements, because those requirements change and vary materially across jurisdictions. A licensed attorney in your state is the appropriate resource for confirming your current, specific obligations after a data breach. The information below is a framework; it is not legal advice.

FTC Safeguards Rule Section 314.4(h): the federal floor

Tax preparation firms are "financial institutions" for purposes of the Gramm-Leach-Bliley Act and its implementing rule, the FTC Safeguards Rule (16 CFR Part 314). The 2023 amendments to the Safeguards Rule, including Section 314.4(h), added an explicit notification requirement. Under that provision, a financial institution must notify the FTC as soon as possible, and no later than 30 days, after discovery of a security event involving the unencrypted information of at least 500 customers. Separately, notification to affected customers is required; the timing and content requirements are set out in the rule itself and should be reviewed against the current rule text at the FTC's website.

The key phrase in the notification trigger is "unauthorized acquisition of" unencrypted customer information. You do not need confirmed evidence that a thief actually used your clients' data. If there was unauthorized access to systems that held unencrypted client financial information, the notification assessment begins at that point. Waiting for proof of fraud before notifying clients or the FTC is inconsistent with how the rule is structured.

What "unauthorized access" means in the practitioner context

Unauthorized access includes phishing-based credential theft that gave an outsider login access to your tax software, a ransomware attack on systems holding client data, an unauthorized remote access session, or a physical breach of a device holding unencrypted client files. It does not require that the attacker actually exfiltrated data in a way you can confirm. If an unauthorized party had access to systems that held client financial information, the Safeguards Rule assessment is triggered.

State data breach notification laws

As of 2026, all 50 states have enacted data breach notification laws. Many of these laws apply to businesses that hold financial information about state residents, which means your obligations under state law may be triggered by the residency of your affected clients, not just the state in which your firm is located. A firm in one state that serves clients in multiple states may face notification obligations under the laws of each state where affected clients reside.

Notification window requirements, content requirements, and covered categories of information vary across states. Many states have notification windows in the range of 30 to 45 days, but this is not universal, and state legislatures amend these laws with some regularity. Do not rely on any third-party compilation of state notification deadlines, including this guide, as a substitute for reviewing current law. The FTC and the National Conference of State Legislatures (NCSL) maintain resources on state data breach notification laws at their respective websites; use these as starting points, then verify current requirements with a licensed attorney in each relevant state.

Assisting Affected Clients: Transcript Checks and Form 14039

Once you have reported to the IRS Stakeholder Liaison and begun the notification process, the next obligation is to your clients directly. For any client whose data may have been exposed, your role is to determine whether their tax account has already been compromised, and if so, to help them take the corrective steps.

Detecting fraudulent filings: transcript check via TDS

The first diagnostic step for any potentially affected client is pulling their tax account transcript and return transcript through the IRS Transcript Delivery System (TDS). A return transcript will show you whether a return has already been filed for the current or prior tax year under the client's Social Security number. If a return appears in the transcript that the client did not file, that is a confirmed fraudulent filing.

The account transcript may also show activity such as refund issuances, address changes made to the account, or notices issued that do not match activity the client is aware of. Any of these can signal that someone else has been operating on the client's tax account. Accessing TDS requires an authorized third-party authorization from the client; see the Form 2848 Power of Attorney guide for tax preparers for the authorization and submission workflow, and the IRS transcripts guide for practitioners for how to access and read transcripts through TDS.

Form 14039: who files it, and how you help

FORM 14039 IS FILED BY THE TAXPAYER (YOUR CLIENT), NOT BY THE PREPARER

The Identity Theft Affidavit on Form 14039 is a sworn statement by the individual whose identity was stolen. The preparer does not file it on the client's behalf. The preparer's role is to explain the form to the client, walk the client through what information to include, and advise on how and where to submit it. This is a meaningful distinction: the form contains a perjury certification, and the taxpayer is the person making the sworn statement, not you.

Form 14039, Identity Theft Affidavit, is the form a taxpayer files with the IRS to report that their identity has been used to file a fraudulent tax return or to commit other tax-related fraud. The current revision of Form 14039 is Rev. 2-2026. Always confirm the current revision at IRS.gov before guiding a client through the form, as revision dates are updated periodically and the IRS expects the current version.

When walking a client through Form 14039, cover the following:

  • Section A of the form asks the taxpayer to describe why they are submitting the affidavit. The most common situation in a practitioner data breach scenario is that the client received an IRS notice saying that a return was already filed, or that the e-file was rejected with a duplicate filing error. The client marks the box that matches their situation.
  • Section B asks for a description of the identity theft event. This is where the client explains what happened: their preparer's data was compromised and the client's information was exposed. The client should be factual and specific without speculating about what may or may not have been stolen.
  • Submission. If the client needs to file a paper return for a year where a fraudulent return was already accepted, Form 14039 is submitted with that paper return. For clients who have not yet been affected but want to proactively place the IRS on notice, Form 14039 can be submitted as a standalone document. The current form instructions at IRS.gov include submission instructions that should be verified at the time of filing.

IP PIN as Remediation: Protecting Affected Clients Going Forward

The IP PIN (Identity Protection Personal Identification Number) is the most effective single preventive measure available to a taxpayer whose Social Security number has been exposed. A six-digit number that the taxpayer enters on their return, the IP PIN tells the IRS not to accept any return filed under that SSN without the matching PIN. A thief who has the client's SSN but not the current IP PIN cannot file a fraudulent return that passes the IRS's electronic filing validation.

The IP PIN program is now available to all eligible taxpayers, not just confirmed identity theft victims. A client whose data was exposed in your firm's breach is a strong candidate for IP PIN enrollment even if no fraudulent return has been filed yet. Proactive enrollment is the practitioner-recommended response for any client whose SSN was on systems that were compromised.

Enrolling through IRS Online Account

The primary enrollment route is the IRS Online Account at IRS.gov. The client creates or logs into their IRS Online Account, accesses the IP PIN section, and completes the enrollment process, which includes identity verification through ID.me. The client receives a new IP PIN each January for use in that filing season. The IP PIN is not shared with the preparer; it is the taxpayer's credential and is used on the return at filing time.

For clients who cannot complete online ID.me verification (for example, clients without a smartphone or without acceptable identification documents for online verification), the IRS has alternative enrollment options published on the IP PIN information page at IRS.gov. These alternatives may involve an in-person visit to an IRS Taxpayer Assistance Center with identity documentation. Review the current options at IRS.gov because the IRS updates these enrollment pathways periodically.

The practitioner-side workflow for IP PIN clients

Once a client has enrolled in the IP PIN program, the practitioner's workflow changes for that client's returns: the current-year IP PIN must be entered on the return before it can be e-filed. The client retrieves their current-year IP PIN from their IRS Online Account each January. If the client loses or forgets the IP PIN, the current retrieval options are published at IRS.gov. A return e-filed without the correct IP PIN for an enrolled client will be rejected.

See the IP PIN guide for tax preparers for the full enrollment workflow, the practitioner's role in the IP PIN process, and how to handle IP PIN entry in tax software for affected clients.

Filing Year Recovery: When a Client's E-File Is Blocked

When an identity thief files a return using a client's SSN before the client files their legitimate return, the IRS's systems will reject the legitimate e-file with a duplicate filing error. The client cannot e-file for that tax year. The return must be filed on paper. This is disruptive, but it is a defined process with a known resolution path.

Filing the paper return

Prepare a complete, accurate paper return for the affected tax year. Attach Form 14039 (completed and signed by the client, not by you) to the paper return. Mail the package to the IRS mailing address specified in the current Form 14039 instructions for returns that include a Form 14039. Confirm the correct mailing address at IRS.gov at the time of filing; mailing addresses for identity theft returns can differ from the standard filing addresses.

Mail the return via a trackable shipping method (USPS Certified Mail or a private carrier with tracking) so you have documentary evidence of the mailing date and delivery. Keep the tracking record in the client's file.

The IRS Identity Theft Victim Assistance process

Once the IRS receives the paper return with Form 14039, the case enters the IRS Identity Theft Victim Assistance (IDTVA) process. This is a specialized IRS unit that handles the complex work of sorting out a legitimate return from a fraudulent one: confirming identity, reversing the fraudulent return's tax account effects, processing the legitimate return, and issuing any refund owed to the actual taxpayer.

The IDTVA process takes longer than standard return processing. The IRS publishes current processing time estimates for identity theft cases on the "Identity Theft Central" section of IRS.gov. Set client expectations accordingly at the outset: a refund on an identity theft return will not arrive on a normal return processing timeline, and the resolution process involves multiple IRS steps that take time to complete. The IRS will typically issue a written update to the taxpayer as the case progresses.

What to tell clients about processing delays

Be direct with clients about what to expect. The legitimate return will eventually be processed. Any refund the client is owed will be issued once the IRS completes its review and reverses the fraudulent return. The process takes time because it involves manual verification steps that automated return processing does not. Clients should not call the IRS general helpline repeatedly to check status; the current status tools and contact options for identity theft cases are available on the IRS Identity Theft Central page. The Taxpayer Advocate Service is available for cases where the processing delay is causing genuine financial hardship.

If the client owes taxes rather than expecting a refund, payment deadlines are still real even while the identity theft case is being resolved. Advise the client to make timely estimated payments or arrangements to avoid additional penalties and interest on the legitimate tax owed, separate from the resolution of the fraudulent return.

Proactive Practice Hardening After a Breach

The response to a data breach is not complete when the incident is contained and the clients are notified. A breach is also a diagnostic: it tells you where the security posture of the practice failed. The work done after a breach to prevent the next one is, in practice, the more important half of the response.

Review and update your Written Information Security Plan (WISP)

Every tax preparation firm subject to the FTC Safeguards Rule is required to have a Written Information Security Plan. If a breach occurred, the WISP needs to be reviewed against what actually happened: the gap between your documented controls and the actual incident is where the plan needs to be strengthened. If you did not have a WISP in place at the time of the breach, creating one now is both a legal requirement and the starting point for preventing the next incident. See the WISP data security guide for the required elements and a practitioner-specific framework.

Staff training on phishing recognition

The majority of successful tax practitioner data breaches begin with a phishing email. A credential harvesting email that looks like a message from the IRS, a tax software vendor, or a bank gives the attacker authenticated access to your systems without needing to overcome any technical defenses. Staff training on phishing recognition is the highest-return security investment available to a small tax office. Training should cover how to identify suspicious email addresses, how to verify unexpected requests for credentials or sensitive information through a secondary channel, and what to do when something looks wrong (report it before clicking). Annual training is a minimum; quarterly brief refreshers during the months leading up to tax season are better.

Multi-factor authentication on all IRS e-Services accounts

Multi-factor authentication (MFA) on IRS e-Services, TDS access, and your tax software's online components means that a stolen password alone is not enough to access those systems. An attacker who obtains your e-Services credentials through a phishing attack cannot log in without also controlling the second factor, typically a code sent to your phone or generated by an authenticator app. Enable MFA on every IRS e-Services account, every tax software portal, and every email account that receives client communications. If your tax software does not offer MFA, that is a selection criterion for your next software review.

Annual security assessment

The FTC Safeguards Rule requires covered financial institutions, including tax preparation firms, to conduct periodic risk assessments of their information security posture. An annual security assessment should cover: a review of which systems hold client data and who has access to them, a review of access controls and credential hygiene, a test of backup and recovery procedures, a review of vendor and third-party access to your systems, and a tabletop walk-through of the breach response sequence so that every staff member knows the first steps before an incident occurs. The assessment does not need to be conducted by an outside firm, but the findings and any remediation actions taken should be documented in writing as part of your WISP compliance record.

Encryption of client data at rest and in transit

Many state data breach notification laws and the FTC Safeguards Rule analysis of notification scope turn on whether the accessed data was encrypted. Encrypted data that is acquired without the decryption key is substantially less useful to an attacker and may not trigger notification obligations in some jurisdictions. Encrypt laptops and removable storage devices, encrypt email attachments containing client financial information, and ensure that cloud storage solutions used for client files use encryption at rest and in transit. Verify that your tax software vendor encrypts client data both in their systems and in the files transmitted to the IRS.

State Data Breach Notification: What Practitioners Need to Know

STATE LAW REQUIREMENTS ARE NOT STATED AS FIXED TIMELINES IN THIS GUIDE

State data breach notification laws change regularly. This guide does not state specific state notification windows as fixed statutory requirements, because doing so would create a false impression of permanence. The framework below describes the general structure of how state laws work. For the specific, current requirements applicable to your firm and your affected clients, consult a licensed attorney and review current law at official state and federal sources.

The 50-state landscape

As of 2026, every U.S. state has enacted a data breach notification law. There is no federal preemptive statute that sets a single national standard for breach notification across all industries (the Safeguards Rule establishes a floor for financial institutions, but state laws can and do impose additional requirements). For tax preparation firms, this means the notification analysis after a breach involves both the Safeguards Rule at the federal level and the applicable laws of every state where affected clients reside.

How state notification windows generally work

Many state breach notification laws use notification windows in the range of 30 to 45 days from the date of discovery or determination that the breach occurred. However, this is a generalization, not a rule. Some states have shorter windows; others allow longer periods or tie the clock to a different triggering event. Some states have different thresholds for when notification is required at all (number of affected residents, type of data involved). Some states require notification to a state regulator in addition to notification to affected individuals.

The content requirements for notification letters also vary by state: some states require specific disclosures (description of the incident, type of data compromised, steps the firm is taking, contact information for further inquiries, credit monitoring offer). Others set a more general standard. Notification that satisfies the most stringent state requirement in the set of affected states generally satisfies less demanding requirements, but verify this with counsel before adopting that approach.

Where to find current state law requirements

Two starting points for reviewing state data breach notification laws:

  • National Conference of State Legislatures (NCSL): The NCSL maintains a regularly updated comparison of state data security breach notification statutes at its website. This resource summarizes the key elements of each state's law in a side-by-side format. Use it as a research starting point, not as legal authority; verify any requirement at the applicable official state source.
  • FTC resources on data security: The FTC publishes guidance for businesses on breach notification obligations, including references to applicable law, at FTC.gov. The FTC site also includes the text of and guidance on the Safeguards Rule.

The most reliable resource for your specific obligations is a licensed attorney with data privacy practice experience in the relevant states. Given the multi-state client base many independent tax firms carry, retaining that counsel before a breach occurs is a more cost-effective approach than finding it in the immediate hours after one.

Regulated Claims and Verification Requirements

The following items in this guide require verification before relying on them in practice: (1) Form 14039 current revision: referenced as Rev. 2-2026 as of publication date; verify the current revision at IRS.gov before guiding any client through the form. (2) FTC Safeguards Rule Section 314.4(h): notification requirements cited as of the 2023 rule amendments; verify current rule text at FTC.gov before advising clients or making compliance decisions. (3) IRS Data Theft Response Kit: a recommended practitioner response framework, not a mandatory regulatory filing with fixed deadlines. (4) State data breach notification timelines: common windows are in the 30-45 day range but vary by state and are subject to legislative amendment; consult a licensed attorney for specific current requirements. (5) IP PIN program availability: described as available to all eligible taxpayers as of the current date; verify current enrollment options and eligibility at IRS.gov. (6) IRS IDTVA processing timelines: not stated as specific figures; verify current estimates on the IRS Identity Theft Central page at IRS.gov. This guide is informational and does not constitute legal, regulatory, or tax advice.

Frequently Asked Questions

What should I do immediately if my tax firm's data is stolen or compromised?

The first priority is stopping the breach: isolate and disconnect affected systems from the network before taking other steps. Do not attempt to clean or restore systems until forensic evidence is preserved. Then contact the IRS Stakeholder Liaison for your area, not the general IRS phone line, and notify the FTC at IdentityTheft.gov. The IRS Data Theft Response Kit describes a recommended response sequence. The FTC Safeguards Rule Section 314.4(h) has client notification requirements triggered by unauthorized access to client financial information, so begin your notification assessment at the same time you are reporting to the IRS. Consult a licensed attorney regarding the specific notification obligations in your state.

How do I contact the IRS Stakeholder Liaison after a data breach?

The IRS Stakeholder Liaison network is a set of IRS employees assigned to geographic areas who serve as direct contacts for tax professionals, industry associations, and government entities. After a practitioner data breach, you contact the Stakeholder Liaison for your area, not the general IRS helpline. The current list of Stakeholder Liaison contacts, organized by state and area, is published at IRS.gov. Search for "IRS Stakeholder Liaison contacts" on IRS.gov to find the current listing. The Liaison can coordinate expedited processing options for affected clients and serve as your point of contact for the IRS side of the response.

Who files Form 14039, the Identity Theft Affidavit: the practitioner or the client?

Form 14039 is filed by the taxpayer, meaning your client, NOT by the tax preparer on the client's behalf. The affidavit is a sworn statement made by the individual whose identity was stolen. The practitioner's role is to explain the form to the client, help the client understand what information to include, and advise on how to submit it. The current revision of Form 14039 is Rev. 2-2026; always confirm the current revision at IRS.gov before guiding a client through the form.

How do I help a client whose e-filed return was rejected because a fraudulent return was already filed?

When a client's e-file is rejected because the IRS has already accepted a return using that Social Security number, the client must file a complete paper return for the tax year, mailed to the IRS, with Form 14039 attached. The paper return goes into the IRS Identity Theft Victim Assistance process, which involves manual review and has longer processing timelines than a standard electronically filed return. Tell the client upfront that IRS identity theft case resolution can take significantly longer than a normal return cycle; the IRS publishes current processing time estimates on its website. Practitioners should pull a transcript via the Transcript Delivery System to confirm what return the IRS currently has on file for the client's Social Security number.

Can I help a client enroll in the IP PIN program after my firm's data breach?

Yes. The IRS IP PIN program is now available to all eligible taxpayers, not just confirmed identity theft victims. An IP PIN is a six-digit number that the taxpayer includes on their return; the IRS will not accept a return for that Social Security number without the matching IP PIN. Clients who have been exposed in a practitioner data breach are strong candidates for IP PIN enrollment. The primary enrollment route is the IRS Online Account at IRS.gov, which requires identity verification through ID.me. For clients who cannot complete the online verification, there are alternative verification paths; the IRS publishes current enrollment options on the IP PIN information page at IRS.gov.

Does the FTC Safeguards Rule require me to notify clients after a data breach at my tax firm?

Yes. The FTC Safeguards Rule, 16 CFR Part 314, Section 314.4(h), requires financial institutions (which include tax preparation firms) to notify affected customers when there has been unauthorized access to, or unauthorized acquisition of, unencrypted customer information maintained by the firm. This is a binding regulatory requirement with notification timing obligations. The notification obligation is distinct from the IRS Data Theft Response Kit, which is a recommended response framework rather than a mandatory filing. In addition to the Safeguards Rule, all 50 states have enacted data breach notification laws, many of which apply to financial services firms. Specific state law requirements change frequently; consult a licensed attorney in your state to confirm your current obligations.

Practice Security Starts With the Right Software and CE Foundation

IRS e-Services access, Transcript Delivery System, and e-file transmission all run through your EFIN and credentials. Keeping those accounts protected and keeping your security practices current is the practitioner's core obligation under the Safeguards Rule. ATP's partnership with CCH TaxWise gives independent preparers a professional-grade platform with the security controls, e-file infrastructure, and IRS e-Services integration that practice security requires. ATP's CE partnership with GSTTI provides IRS-approved continuing education that covers data security, Circular 230, and annual updates for AFSP, EA renewal, and general preparer compliance. If your practice is building out its security posture after a breach, or building it right before one, contact ATP to discuss how TaxWise and CE together support your obligations.