Working Virtually: make a plan for protecting data and reporting theft

Certified Public Accountant in Houston

The Internal Revenue Service and Security Summit partners reminded tax professionals that federal law requires them to have a written information security plan.

Amid continuing security threats during COVID-19, the IRS, state tax administrators and the nation's tax industry − working together as the Security Summit − also recommended practitioners create an emergency response plan should they experience a data theft. Contacting the IRS is step one in the plan to quickly protect tax professionals and their clients.

Making a plan for protecting data and reporting theft is the last of a five-part series called Working Virtually: Protecting Tax Data at Home and at Work. The special Security Summit initiative spotlights basic security steps for all practitioners, but especially those working remotely or social distancing in response to COVID-19.

"COVID-19 has changed the way many of us work, and more tax professionals are working from home. With these changes, there are new risks from cybercriminals. Our special Security Summit series was designed to give you critical information, protect your clients and protect your business," said IRS Commissioner Chuck Rettig.

"We all have a role in protecting taxpayer data, and the tax professional community is a critical part of that effort," Rettig added. "It's more important than ever to take appropriate security precautions, protect remote work sites, use two-factor authentication and plan ahead for all possibilities."

Tax Pros: Create a Security Plan to meet FTC requirement

Federal law administered by the Federal Trade Commission requires all "professional tax preparers" to create and maintain a written information security plan that is appropriate to the firm's size and complexity.

In addition, the FTC-required information security plan must be appropriate to the nature and scope of the company's activities and the sensitivity of the customer information it handles. A plan for a sole tax practitioner would differ from a multi-partner, global firm.

Tax professionals working from home must ensure that client data is protected just as it would in an office setting.

According to the FTC, each company, as part of its plan, must:

  • designate one or more employees to coordinate its information security program;
  • identify and assess the risks to customer information in each relevant area of the company's operation and evaluate the effectiveness of the current safeguards for controlling these risks;
  • design and implement a safeguards program and regularly monitor and test it;
  • select service providers that can maintain appropriate safeguards, make sure the contract requires them to maintain safeguards and oversee their handling of customer information; and
  • evaluate and adjust the program in light of relevant circumstances, including changes in the firm's business or operations, or the results of security testing and monitoring.

Please note: The FTC currently is re-evaluating the Safeguards Rule and has proposed new regulations. Be alert to any changes in the Safeguards Rule and its effect on the tax preparation community.

IRS Publication 4557, Safeguarding Taxpayer Data, details critical security measures that all tax professionals should enact. The publication also includes information on how to comply with the FTC Safeguards Rule, including a checklist of items for a prospective data security plan. Tax professionals are asked to focus on key areas such as employee management and training; information systems; and detecting and managing system failures.

The IRS also may treat a violation of the FTC Safeguards Rule as a violation of IRS Revenue Procedure 2007-40, which sets the rules for tax professionals participating as an Authorized IRS e-file Provider.

Create a Data Theft Response Plan; Report Data Thefts to the IRS

Tax professionals who experience a data theft should report the crime to the IRS immediately so that actions can be taken to protect taxpayers – and the firm. The Security Summit partners recommend practitioners create a response plan so that actions can be taken quickly, and contact information is readily available.

If a client or the firm are the victim of data theft, immediately:

Find more information at Data Theft Information for Tax Professionals.

In addition to trying to steal client data, thieves may try to steal a tax practitioner's identity as well, using their PTINs, EFINs and CAF numbers to file fraudulent returns or steal even more information. Thieves may even try to impersonate the tax practitioner to obtain tax transcripts or other tax records.

Practitioners should routinely check their IRS e-Services e-file Application to see a weekly count of tax returns filed with their Electronic Filing Identification Numbers or EFIN. Excessive filings are a sign of data theft. E-file applications also should be kept up to date.

Circular 230 practitioners also can review weekly the number of tax returns filed using their Preparer Tax Identification Number or PTIN. Again, excessive filings are a sign of data theft.

Preparers with Centralized Authorization File, or CAF numbers, that enable third party access to tax information or representation should keep those records updated. Practitioners should notify the IRS when they no longer need third-party authorization for clients.

Source: IRS

Alfredo Gaxiola has worked on numerous IRS problem cases and has successfully settled with the IRS to release liens on houses, bank accounts and wages and, if needed, setting a payment installment plan that is not burdensome for the client. He has conducted appeals before the U.S. Tax Court and obtained favorable resolutions in reducing the tax debt of his clients. Mr. Gaxiola served as Treasurer of Camara de Empresarios Latinos, one of the largest and strongest Hispanic organizations in the city of Houston. He has conducted financial and accounting seminars for the Houston Small Business Development Corporation, as well.

16 Certified Public Accountant in Houston

Certified Public Accountant in Houston

CPA in Houston, Alfredo Gaxiola in Houston, Certified Public Accountant in Houston, Bookkeeping in Houston, Certified QuickBooks Proadvisor in Houston, QuickBooks Set Up and Training in Houston, Bank Financing in Houston, Business Tax Returns in Houston, Personal Tax Returns in Houston, Quarterly & Monthly Filings in Houston, Financial Statement Preparation in Houston, Form Preparation in Houston, Payroll Preparation in Houston, Reviews Temporary Bookkeeping Services in Houston, Reducing your taxes in Houston, IRS representation in Houston

 (281) 861-7718  
This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it.  
 Location

 (281) 861-7718  This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it.   Location


© Alfredo Gaxiola, CPA. All rights reserved.
Website designed by LaraNet | Expand Your Business!