Blog

Is It Safe to Email Tax Documents? Secure Alternatives for Firms and Clients

Why emailing tax documents is risky, what the FTC Safeguards Rule and IRS guidance expect from accounting firms, and safer ways to send and collect sensitive files.

Tax documents are some of the most sensitive files a person owns. A single W-2 carries a name, address, Social Security number and income. Put a few of those together with a copy of a driver's license and you have everything needed to file a fraudulent return or open credit in someone's name.

Yet every tax season, many of these documents still move through ordinary email. This guide explains why that's risky, what accounting firms are expected to do about it, and safer ways to send and collect tax documents.

Is it safe to email tax documents?

Generally, no. Standard email was not designed to protect sensitive files, and there are several ways a document can be exposed along the way:

  • Encryption is not guaranteed. Many email providers encrypt messages in transit between servers, but not all do, and the message usually sits unencrypted in both inboxes once it arrives.
  • Copies multiply. An attachment lives in the sender's sent folder, the recipient's inbox, any device that syncs the account, and backups of all of them, often for years.
  • Accounts get compromised. If either the client's or the firm's email account is breached, every tax document ever sent is exposed at once.
  • Mistakes are easy. Autocomplete sends the file to the wrong person. A forwarded thread carries attachments to people who were never meant to see them.
  • Phishing thrives in tax season. Scammers impersonate accountants and ask clients to email their documents. Clients who are used to emailing tax documents are easier to fool.

The IRS warns about tax-season phishing every year. If your clients are trained to send documents only through one secure channel, a fake request by email stands out.

What accounting firms are expected to do

For tax and accounting professionals, protecting client data is not just good practice. In the US, several rules apply:

  • The FTC Safeguards Rule applies to tax preparers and requires them to maintain an information security program that protects customer data.
  • A written information security plan (WISP) is required by federal law for tax and accounting professionals. The IRS publishes guidance and a template to help small firms create one, in Publication 5708.
  • IRS Publication 4557, Safeguarding Taxpayer Data, lays out practical steps for protecting client information.
  • State laws may add their own data security and breach notification requirements.

This is an overview, not legal advice. Talk to a qualified professional about the specific requirements for your firm.

Safer ways to send and collect tax documents

Secure client portals

A client portal gives each client a private, password-protected space to upload files and download completed returns. Documents are stored encrypted, access is logged, and nothing sits in an email inbox. Most practice management platforms include one.

The downside is friction. Clients have to create an account, remember a password and learn a new interface, which some will avoid by emailing you anyway.

A secure upload link lets clients send files straight to your firm's storage without creating an account. You send the link, they tap it, choose files and upload. It's often the easiest option for clients who only send documents once or twice a year, and it works well from a phone.

Encrypted email

Encrypted email services and plugins protect the message and attachment so only the intended recipient can open them. This is useful for sending finished documents to clients, though clients often find the extra steps to open a message confusing.

In person, with care

Paper handed over at your office avoids many digital risks, but it creates physical ones. If you accept paper, scan it into secure storage promptly and store or shred the originals according to your security plan.

What to avoid

  • Plain email attachments containing Social Security numbers, bank details or full tax forms
  • Consumer file sharing links set to "anyone with the link can view"
  • Text messages with photos of IDs or tax forms
  • Password-protected files where the password is sent in the same email
  • USB drives passed between client and firm

Tips for clients

If you're sending documents to your own accountant, a few habits keep you safer:

  • Ask your accountant how they want to receive documents, and use only that method
  • Be suspicious of unexpected emails asking you to send tax documents or click a link, even if they look like they come from your accountant. When in doubt, call them.
  • Don't reuse the password for your accountant's portal anywhere else
  • Delete tax documents from your email and downloads folder once they've been safely delivered

Tips for firms

  • Choose one secure collection method and point every request to it
  • Explain in your onboarding that you'll never ask for documents by plain email
  • When a client emails a document anyway, move it into secure storage, delete the email, and remind them of the right channel
  • Turn on multi-factor authentication for every system that holds client data
  • Review who on your team has access to what, at least once a year

Security that clients will actually use

The most secure system in the world doesn't help if clients avoid it and email you instead. The goal is a method that's both secure and easier than email.

Correctdocs gives clients a simple, secure link to upload exactly what you've asked for, from any device, without creating yet another account. Each document is checked as it arrives, and reminders go out automatically until everything is in, so there's no reason for anyone to fall back on email.

Correctdocs is in early access. The first 10 US accounting, bookkeeping and tax firms get a free 30-day pilot on real client requests. Request early access.

Read next

Stop opening wrong documents.

Correctdocs checks every client upload the moment it lands, and wrong files go back with a clear fix. The first 10 US firms get a free 30-day pilot.

Request early access