Data Breach Response Plan for Accounting Firms: What to Do in the First 72 Hours
A practical incident response plan for accounting and tax firms: contain the breach, contact the IRS, meet FTC and state notification rules, communicate with clients and prevent it happening again.
Quick answer: If an accounting or tax firm suspects client data has been stolen, it should contain the incident, preserve evidence, contact its IT provider and insurer, and alert its IRS Stakeholder Liaison so the IRS can help protect affected clients from fraudulent returns. Under the FTC Safeguards Rule, covered firms must notify the FTC of certain security events affecting 500 or more people, generally within 30 days of discovery, as the IRS has reminded tax professionals. State breach notification laws may add further obligations.
Key takeaways
- A written incident response plan is one of the elements of the Safeguards Rule (firms holding data on fewer than 5,000 consumers are exempt, but the IRS still recommends one).
- Speed matters: stolen tax data is often used to file fraudulent returns quickly.
- The IRS Stakeholder Liaison is the IRS contact point for tax professionals reporting data theft.
- FTC notification applies to events affecting 500 or more people; state laws often have lower thresholds.
- Write the plan before you need it, with names and phone numbers filled in.
Signs your firm may have been breached
- Clients' e-filed returns rejected because a return was already filed with their Social Security number
- Clients receiving IRS notices about returns they didn't file
- More returns filed under your EFIN than you prepared
- Computers running slowly, cursors moving on their own or unfamiliar programs installed
- Email accounts sending messages staff didn't write, or new forwarding rules
- Ransomware messages or locked files
IRS Publication 4557 describes these and other warning signs in more detail.
The first 72 hours
1. Contain
- Disconnect affected devices from the network, but don't turn them off or wipe them, which can destroy evidence
- Change passwords and revoke sessions from a clean device
- Disable compromised accounts and remove unauthorized email forwarding rules
2. Call for help
- Your IT or security provider
- Your cyber insurance carrier, which may require prompt notice and may provide breach response specialists
- Legal counsel familiar with data breach laws
3. Contact the IRS
Report the theft to your IRS Stakeholder Liaison. The IRS can monitor affected clients' accounts and help stop fraudulent returns before refunds go out. Publication 4557 explains how to report and lists additional steps. If ransomware is involved, the IRS also points practitioners to the FBI and the Cybersecurity and Infrastructure Security Agency.
4. Contact state tax agencies
The IRS also asks tax professionals to alert state tax agencies by emailing StateAlert@taxadmin.org, and to contact the tax agency in each state where they prepare returns.
5. Preserve evidence and document everything
Keep logs, record what happened when and who did what. You'll need this for regulators, insurers and your own review.
Notification obligations
FTC
Covered financial institutions, which include tax preparers, must notify the FTC as soon as possible, and no later than 30 days after discovery, when unencrypted information about 500 or more consumers is acquired without authorization. The FTC's Safeguards Rule guide explains what counts and how to notify.
States
Every state has its own breach notification law, with different definitions, thresholds and deadlines. Notification may be owed to affected individuals, the state attorney general or both. Get legal advice on which laws apply, based on where affected clients live.
Clients
Even where not strictly required, honest and prompt communication with clients protects them and your reputation. Tell them what happened, what information was involved, what you're doing about it, and what they should do, such as watching for IRS notices and considering an IRS Identity Protection PIN.
After the incident
- Work out how the attacker got in, and close that gap
- Update your risk assessment and written information security plan
- Retrain staff, especially on phishing
- Review who has access to what, and remove anything unnecessary
- Review how much old data you're holding, and apply your retention schedule
Your incident response plan template
Keep this as a one-page document, printed and stored offline as well as digitally:
- Incident lead and backup, with phone numbers
- IT provider, insurer and attorney contacts
- IRS Stakeholder Liaison contact for your area
- State tax agency contacts
- Steps for containment and evidence preservation
- Notification decision process and templates
- Post-incident review checklist
Reduce what can be stolen
The less sensitive data scattered across inboxes and devices, the less a breach can expose. Collecting client documents through one secure, encrypted channel, rather than as email attachments, shrinks your exposure significantly. Correctdocs keeps client uploads in one secure place instead of spread across staff inboxes. See also: Is it safe to email tax documents?
Correctdocs is in early access. The first 10 US accounting, bookkeeping and tax firms get a free 30-day pilot on real client requests. Request early access.
Frequently asked questions
Who should a tax preparer contact after a data breach?
Their IT provider, insurer and legal counsel, plus their IRS Stakeholder Liaison and relevant state tax agencies. FTC and state notifications may also be required.
When must a tax firm notify the FTC of a breach?
Under the Safeguards Rule, covered firms must notify the FTC of certain security events affecting 500 or more people, generally within 30 days of discovery.
Is an incident response plan required?
A written incident response plan is one of the elements the FTC Safeguards Rule requires in an information security program, though firms holding information on fewer than 5,000 consumers are exempt from some provisions. Having one is strongly advisable regardless.
Sources
- IRS, Publication 4557, Safeguarding Taxpayer Data
- IRS, WISP reminder for tax professionals
- FTC, FTC Safeguards Rule: What Your Business Needs to Know
General information only, not legal advice. Consult counsel about your specific notification obligations.