What Every Accounting Firm Should Know About Client Data, the Safeguards Rule, and Tax Season Attacks
A single firm’s files hold everything needed to steal hundreds of identities at once. Here’s what regulators actually require, how firms really get hit, and what well run firm IT looks like, in plain English.
Get the Free Accounting Firm Technology Guide
Six plain English pages: your obligations, the attacks, the firm security baseline, and the questions partners should ask. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.
Your Obligations, In Plain English
Between the FTC, the IRS, and confidentiality rules, accounting firms carry real, specific security obligations. They reduce to three themes.
You're a Financial Institution Now
The FTC Safeguards Rule treats tax preparers and accounting firms as financial institutions. That means a written information security program: a named responsible person, risk assessment, access controls, encryption, MFA, vendor oversight, and incident response, documented and maintained.
The IRS Expects a Plan Too
Paid preparers are expected to maintain a data security plan, and the PTIN renewal process asks about it. IRS guidance lays out baseline protections every firm should have, and a breach means prompt contact with the IRS stakeholder liaison and state agencies.
Confidentiality Has Teeth
Tax return information carries strict disclosure rules with serious penalties, and professional standards add their own confidentiality duties. Protecting client data isn’t just good practice in this profession. It’s the license.
How Firms Actually Get Hit
Accounting firm incidents follow the calendar and the money. Four patterns cover most of the damage.
The Fraudulent Return Factory
Criminals don’t steal firm data to read it. They steal it to file with it: fraudulent returns under clients’ identities, refunds rerouted, often within days. The firm learns about it when clients’ real returns start bouncing as duplicates, one after another, in the middle of the season.
The Deadline Squeeze
Ransomware operators know exactly what a locked out firm faces on April 10th, and they schedule for it. Firms with tested, isolated backups restore and keep filing. Firms without them negotiate under the worst possible clock.
The Impersonated Client
An attacker takes over or mimics a client’s email, then asks the firm to update bank details for a refund, redirect a payment, or send copies of documents. Everything looks routine. The defense is procedural: banking changes and document requests verified by phone at a known number, every time.
The Season of Open Attachments
Tax season means new clients, urgent emails, and documents arriving all day, which is exactly the traffic phishing hides in. One convincing “here are my W-2s” attachment can carry the payload that starts everything above. Training, filtering, and a portal shrink the attack surface the season creates.
What Well Run Firm IT Looks Like
Whoever manages your firm’s technology, this is the baseline worth reviewing together. Every item maps to an obligation or an attack above.
A WISP That's Real
A written information security program with a named responsible person, current risk assessment, and evidence behind every claim, because the plan is now a compliance document, not a suggestion.
MFA and Unique Logins
Every account protected with multifactor authentication, including tax software, email, and remote access, with no shared logins anywhere.
A Portal, Not Attachments
W-2s, 1099s, and organizers moving through a secure client portal instead of email, protecting the identities inside every document.
Deadline Proof Backups
Daily backups of tax software, documents, and email with one copy ransomware can’t reach, restore tested and timed against the season’s worst day.
Verification Procedures
Banking changes, refund rerouting, and document requests confirmed by phone at a known number before anything moves, written and trained.
Training and Monitoring
Staff phishing trained before the season, not after, and systems watched around the clock, because the busiest weeks are the most attacked ones.
Common Questions
Do CPA and tax firms really need a written information security plan?
Yes. The FTC Safeguards Rule treats tax preparers and accounting firms handling client financial data as financial institutions, requiring a written information security program with a designated responsible person, risk assessment, access controls, encryption, MFA, vendor oversight, and incident response. The IRS also expects paid preparers to maintain a data security plan, and asks about it in the PTIN renewal process.
Why do criminals target accounting and tax firms?
A single firm’s files contain everything needed to steal hundreds of identities at once: Social Security numbers, income details, bank accounts, and dependents, all verified and current. Stolen client data feeds fraudulent tax filings, and firm credentials like EFINs are valuable on their own. One small firm can be worth more to criminals than thousands of individual victims.
What happens if a tax preparer has a data breach?
Firms are expected to respond quickly: contacting the IRS stakeholder liaison, notifying state tax agencies and, depending on the state, affected clients and regulators, while fraudulent returns may already be moving under clients’ identities. Firms with a written incident response plan and evidence of safeguards navigate this in days. Firms without one navigate it during tax season, in public.
Why is tax season also attack season?
Deadline pressure changes behavior. Staff open attachments faster, new clients appear with documents attached, and a firm locked out of its systems on April 10th faces maximum pressure to pay a ransom. Attackers schedule their campaigns around the same calendar the profession does.
What is in the free accounting firm technology guide?
A six page plain English guide covering your Safeguards Rule and IRS obligations, the three attack patterns that hit firms most, a firm security baseline checklist, tax season readiness, and the questions partners should ask about their IT.
Start With the Guide. Decide From There.
Download the Accounting Firm Technology Guide and review the baseline with whoever runs your IT. If you’d rather have the answers verified for you, a free confidential security assessment for your firm is available too.