What every paid tax preparer is actually required to have in place, according to the FTC Safeguards Rule (16 CFR Part 314) — plus the preparer-specific guidance IRS Publication 4557 adds on top of it. No jargon, no upsell. Just the list.
This is an educational summary, not legal advice. It's written in plain language to help you understand what the rule and IRS guidance generally cover and where your firm might have gaps. It does not cover every detail of 16 CFR Part 314 or Publication 4557, and it doesn't certify compliance. For a legal determination of your firm's specific obligations, talk to an attorney or compliance professional who handles tax-preparer regulatory matters.
Who this applies to: Any business that handles taxpayer financial data as part of preparing returns — solo preparers and multi-partner firms alike — regardless of who manages your IT. Where it comes from: the first four groups below summarize the FTC Safeguards Rule (16 CFR Part 314), amended in 2023. The fifth group covers guidance specific to tax preparers straight out of IRS Publication 4557 — the IRS's own "Security Six," breach warning signs, and who to call when something goes wrong.
Your firm has designated a specific person — a "Qualified Individual" in the rule's language — responsible for your information security program. For a solo practice, that's usually you. It just needs to be a named person, not an assumption.
A risk assessment, in writing, that names realistic threats to client data — a lost laptop, a phishing email, ransomware, an employee mistake — and roughly how serious each one would be. It gets revisited periodically, not written once and forgotten.
Staff can see the client files relevant to their work — not the entire client base by default, just because it's convenient.
Email, practice management software, cloud storage, remote access — anywhere someone could get to client tax or financial data. This is the single most common gap we see in small firms.
Both while it's being sent (email attachments, file transfers) and while it's sitting on a server, a laptop, or a backup drive.
A real retention and secure-disposal schedule — not keeping every file forever because deleting anything feels risky.
Someone — or something automated — would actually notice if an account started behaving strangely, instead of finding out from a client first.
Ongoing monitoring, or at minimum annual penetration testing plus vulnerability scans twice a year — not a plan that sits in a drawer untested.
Not a one-time "be careful with email" comment years ago. Ongoing security awareness training, and whoever owns your security program stays current on new threats.
Your software vendors, IT provider, and any other outside party that can touch client data are contractually required to protect it — not just assumed to be handling it responsibly.
New software, new staff, a new office, a past incident — any of these should trigger a real review of the plan, not a "we'll get to it" mental note.
A real, specific answer to "what do we do in the first hour after we learn about a breach," decided in advance instead of figured out in a panic.
Even in a small firm, this means actually sitting down once a year and reviewing, in writing, whether the plan is still accurate and whether anything needs to change.
Antivirus software, a firewall, multi-factor authentication, backup software, drive encryption, and a VPN for remote access — the six basic tools the IRS specifically names as the starting point for every preparer, regardless of firm size.
"New client" scams, and emails spoofing your e-Services account, tax software provider, or the IRS asking you to "verify" your EFIN or login. These don't look like generic spam, and they're the leading actual cause of preparer data breaches.
E-Services login credentials aren't shared between staff, and someone actually checks the account periodically for signs it's been used without authorization.
Client e-files rejected because a return was already filed under their SSN. IRS notices about returns you didn't prepare. More transcripts pulled through your account than you actually requested. These are often the first sign something's wrong — before anything else would tip you off.
Beyond your internal incident response plan, the IRS specifically directs preparers to contact their local IRS Stakeholder Liaison immediately, in addition to the FTC and any state tax agencies where you prepare returns.
Indiana and Michigan each have their own data breach notification requirements, separate from federal rules — worth confirming with a professional if your firm operates across both, or if you've simply never checked.
Book a free 25-minute Security Plan Check. Bring whatever plan you have — or nothing at all — and Graham will walk through this exact list with you, in plain English.
Book Your Free Security Plan CheckNo pitch. No obligation. Keep what we find, either way.Ma3SP Technology • Goshen, Indiana 46528 • 574.903.7119 • info@ma3sp.com
This checklist is provided for general educational purposes and summarizes public FTC and IRS guidance. It is not legal advice.