Scope
Who it applies to.
Publication 4557 is written for anyone who prepares tax returns for compensation — sole practitioners, PTIN holders, Authorized IRS e-file Providers, and the accounting firms that employ them. The reach comes from the FTC’s Safeguards Rule, which lists “an accountant or other tax preparation service that is in the business of completing income tax returns” as a financial institution, because tax preparation is a listed financial activity. Firm size does not matter; a one-person shop is covered.
- Written Information Security Plan
- Pub. 4557 states plainly that “Protecting taxpayer data is the law,” and directs you to the FTC Safeguards Rule, under which “tax return preparers must create and enact security plans to protect client data.” The plan must be written and scaled to your firm. Form W-12 Line 11 now asks you to check a box acknowledging awareness of that legal duty at PTIN renewal.
- The Security Six
- The Security Summit’s “Security Six” are the baseline technical controls the IRS urges on every practice: anti-virus software, a firewall, multi-factor authentication, routine backups, drive encryption, and a VPN for remote access. Multi-factor authentication is no longer merely advisory — the amended Safeguards Rule requires it for anyone accessing customer information.
- Consent before disclosure (IRC § 7216)
- Separate from security, § 7216 makes it a crime for a preparer to disclose or use tax return information without authority. Treasury regulations require the taxpayer’s written consent — knowing, voluntary, and obtained before the disclosure — naming the recipient, the information involved, and the purpose. Feeding return data to an outside service not assisting in preparing that return can require consent.
- Service-provider oversight
- The Safeguards Rule makes you answerable for the vendors that touch client data: you must take reasonable steps to select providers capable of safeguarding it, bind them by contract to do so, and periodically reassess them against the risk they present. Cloud storage, tax software hosts, scanning bureaus, and AI tools each add a provider to vet, paper, and monitor.
- Breach reporting
- Pub. 4557 tells you to report a data loss immediately to your IRS Stakeholder Liaison, to contact the FBI and local police, and to notify every state where you file returns using the Federation of Tax Administrators’ breach-reporting directory. Separately, since 13 May 2024 the Safeguards Rule requires notifying the FTC within 30 days of a breach affecting 500 or more consumers.
- Extra duties for e-file Providers
- Authorized IRS e-file Providers carry additional duties under Pub. 1345. Online Providers of 1040-series returns must hold a current Extended Validation certificate, contract for weekly external vulnerability scans by a PCI-approved scanning vendor, and retain the reports for at least a year. The sixth standard, reporting security incidents, now applies to all Providers, not only online ones.
The vendor & sub-processor obligation
What it puts on you.
Like the Safeguards Rule it references, it expects you to vet and oversee any provider that handles taxpayer data — so every cloud or AI tool that touches returns adds a provider to evaluate and monitor.
How self-hosting addresses it
Remove the third party, remove the burden.
Keeping returns, organizers, and source documents on a private appliance means no outside provider handles taxpayer data, removing that oversight obligation for the data.
How FileFerret applies
Two tax-specific angles. A service provider you never engage is one you need not select, contract with, or periodically reassess under the Safeguards Rule. And return information that stays on hardware in your office is not disclosed to an outside recipient, so the § 7216 consent question does not arise for that processing. A WISP is still yours to write. See how it’s built →
Full, current text is maintained at the official source: IRS Publication 4557.
Enforcement
Who enforces it, and how.
Three bodies can act. The FTC enforces the Safeguards Rule and may investigate a firm that never built a plan. The Justice Department prosecutes § 7216, a misdemeanor carrying a fine of up to $1,000, up to a year in prison, or both. The IRS assesses the parallel civil penalty under § 6713 — $250 per improper disclosure or use, capped at $10,000 a year — and can sanction, suspend, or expel an e-file Provider. Both penalties rise steeply where the conduct involves identity theft.
Common questions
Questions firms ask.
Is a WISP actually legally required, or just recommended?
Required. Pub. 4557 is guidance, but it rests on the FTC Safeguards Rule, which obliges financial institutions — a category that expressly includes tax preparation services — to maintain a written information security program. The IRS states that tax professionals are legally required to have a written, accessible plan, and Form W-12 now asks you to acknowledge that duty when you renew your PTIN. Pub. 5708 supplies a template.
Do I need client consent before putting return data into a cloud or AI tool?
Often, yes. Section 7216 limits disclosure and use of tax return information. The regulations permit disclosure to another preparer assisting with that same return, but a general-purpose tool that is not preparing the return may fall outside the exceptions. Where no exception applies, you need the taxpayer’s written, knowing, voluntary consent, obtained beforehand and identifying the recipient, the information, and the purpose.
My firm was breached. Who do I have to tell, and how fast?
Start with your IRS Stakeholder Liaison, so the IRS can take steps to protect your clients from fraudulent returns filed in their names. Report to local police and, if the IRS directs, the FBI; for ransomware, add CISA. Notify each state where you prepare returns through the Federation of Tax Administrators. If 500 or more consumers were affected, the FTC must hear from you within 30 days.