Practice Management IRS Urges Tax Professionals to Educate Employees About Data Security, Computing Safeguards Read the Article Open Share Drawer Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on LinkedIn (Opens in new window) Written by Intuit Accountants Team Modified Jul 24, 2020 4 min read The IRS and its Security Summit partners are calling on tax professionals to step up security education for all office employees, including themselves, to better protect taxpayer data and help prevent fraudulent return filings. The warning from the IRS, state tax agencies and the nation’s tax industry follows an increase this year in reports of data thefts from tax professionals. The Security Summit partners remind professionals that their clients’ data and their businesses are only as secure as their least informed employee. This is the seventh in a series called “Protect Your Clients; Protect Yourself: Tax Security 101.” The Security Summit awareness campaign is intended to provide tax professionals with the basic information they need to better protect taxpayer data and to help prevent the filing of fraudulent tax returns. Although the Security Summit is making progress against tax-related identity theft, cybercriminals continue to evolve and data thefts at tax professionals’ offices are on the rise. Thieves use stolen data from tax practitioners to create fraudulent returns that are harder to detect. The IRS continues to see an increase in the number of data thefts reported by tax professionals. Through Aug. 9, there have been 217 tax professionals reporting data thefts this year — a 30 percent increase from 167 through the same period in 2017. All employees should be aware of the dangers related to phishing emails, especially spear phishing emails. An employee does not have to be a tax preparer to accidentally disclose critical password information or download malware that could infect and impact all office computers and risk the theft of client data. All professional tax return preparers must adhere to the “Safeguards Rule” set out by the Gramm-Leach-Bliley Act of 1999 and administered by the Federal Trade Commission. The FTC sets out a series of suggested areas to address, including for employee management and training. The FTC suggests following this list, and the IRS has added some updates specifically for tax professionals: Check references or conduct background checks before hiring employees who will have access to customer information. Ask every new employee to sign an agreement to follow the company’s confidentiality and security standards for handling customer information. Limit access to customer information to employees who have a business reason to see it. For example, give employees who respond to customer inquiries access to customer files, but only to the extent they need it to do their jobs. Control access to sensitive information by requiring employees to use strong passwords that must be changed on a regular basis. (Tough-to-crack passwords require the use of at least six characters, upper- and lower-case letters, and a combination of letters, numbers and symbols.) (IRS suggestion: passwords should be a minimum of eight characters.) Use password-activated screen savers to lock employee computers after a period of inactivity. Develop policies for appropriate use and protection of laptops, personal digital assistants, cell phones or other mobile devices. For example, make sure employees store these devices in a secure place when not in use. Also, consider that customer information in encrypted files will be better protected in case of theft of such a device. Train employees to take basic steps to maintain the security, confidentiality and integrity of customer information, including: Locking rooms and file cabinets where records are kept; Not sharing or openly posting employee passwords in work areas; Encrypting sensitive customer information when it is transmitted electronically via public networks; Referring calls or other requests for customer information to designated individuals who have been trained in how the company safeguards personal data; and Reporting suspicious attempts to obtain customer information to designated personnel. Regularly remind all employees of the company’s policy — and the legal requirement — to keep customer information secure and confidential. For example, consider posting reminders about their responsibility for security in areas where customer information is stored, like file rooms. Develop policies for employees who telecommute. For example, consider whether or how employees should be allowed to keep or access customer data at home. Also, require employees who use personal computers to store or access customer data to use protections against viruses, spyware and other unauthorized intrusions. Impose disciplinary measures for security policy violations. Prevent terminated employees from accessing customer information by immediately deactivating their passwords and user names and taking other appropriate measures. All employees within a tax professional’s office should familiarize themselves with FTC regulations and IRS publications and websites that will help increase security awareness. To improve data security awareness by all tax professionals, the IRS will host a webinar on Sept. 26, 2018. The focus will be on the same topics as this series: “Protect Your Clients; Protect Yourself: Tax Security 101.” Although tax preparers will be eligible for one CPE credit, the IRS welcomes tax professionals and their employees. Protecting taxpayer information takes everyone working together. The Security Summit reminds all professional tax preparers that they must have a written data security plan as required by the Federal Trade Commission and its Safeguards Rule. They can get help with security recommendations by reviewing the recently revised IRS Publication 4557, Safeguarding Taxpayer Data, and Small Business Information Security: the Fundamentals by the National Institute of Standards and Technology. Publication 5293, Data Security Resource Guide for Tax Professionals, provides a compilation of data-theft information available on IRS.gov. Previous Post Important Tools to Help You Manage Your Tax and Accounting… Next Post IRS Reminds Professional Tax Preparers of Data Security Plan Requirements Written by Intuit Accountants Team The Intuit® Accountants team provides ProConnect™ Tax, Lacerte® Tax, ProSeries® Tax, and add-on software and services to enable workflow for its customers. Visit us at https://proconnect.intuit.com, or follow us on Twitter @IntuitAccts. More from Intuit Accountants Team Comments are closed. Browse Related Articles Practice Management IRS Reminds Professional Tax Preparers of Data Security… Practice Management How to create a Written Information Security Plan Tax Law and News IRS Issues Security Summit Alert: New Two-Stage Email S… Practice Management How to protect your firm and taxpayer data from COVID-1… Tax Law and News Tax Professionals Warned of New Scam to “Unlock” Th… Tax Law and News IRS National Tax Security Week Concludes With Strong Me… Tax Law and News IRS Summit Partners Warn Tax Pros to be on Alert and St… Tax Law and News Protect Client Data With the IRS Taxes-Security-Togethe… Tax Law and News IRS Warns Tax Pros of New Scam Posing as Professional A… Tax Law and News Above the Forms: Expanded Security for Tax Professional…