An Evergreen Reminder of Requirements Regarding Securing Client Data

Cyberthieves target firms year-round. Review your WISP, update safeguards, and stay IRS compliant to protect client data. Read more on TXCPA.org.

William Stromsem, CPA, J.D., George Washington University School of Business 

 

Cyberthieves are trying to get your information year-round. Now that October 15 is behind us and year-end tax planning is not here yet, this might be a good time to review requirements for securing client information. If you have a data breach, this can ruin client relationships and even end your practice. 

The IRS requires a Written Information Security Plan (WISP) to protect your firm and clients from cyberattacks. Ensure that your plan is valid, up to date and in compliance with the IRS requirements. IRS Publication 5708 is a brief document that details what is required and how to customize your plan for your practice. AICPA Tax Section members can download a copy of AICPA's WISP template

Also, the Federal Trade Commission requires practices to use multifactor authentication in accessing client information that is stored on computers or on networks (including cloud storage). This would include return preparation records when vendor software is used. Multifactor identification involves using two or more items that only the user would know, like username and password, or if available, facial recognition, fingerprints or other means of verifying that the person accessing the information is authorized to do so.   

Hopefully, your firm has this fully implemented. 


Topics:

You May be Interested in

  • The IRS May Owe Your Clients Money from the COVID Period
    Recent court decisions have opened a largely overlooked opportunity for significant tax refunds based on mandatory disaster relief under IRC Section 7508A during the federally declared COVID-19 disaster period. As a result, interest and penalties assessed during this period may be invalid and refundable, and some taxpayers who received refunds may also be entitled to unpaid overpayment interest. While uncertainty remains and the IRS may resist such claims, timely protective refund filings are critical to preserve clients rights as the statute of limitations continues to run.
  • TXCPA Advocates for Accounting’s Recognition in Definition of Professional Degrees for Student Loan Eligibility
    TXCPA submitted a formal comment to the U.S. Department of Education urging recognition of accounting as a professional degree program to protect graduate-level federal loan access and strengthen the future CPA pipeline.
  • The Verdict is In. The Texas Franchise Tax is GILTI, Raising New Questions and Potential Issues
    Beginning with the 2026 report year, the Texas Comptroller will align the franchise tax with the current Internal Revenue Code, likely requiring GILTI to be included in total revenue. This change raises sourcing, statutory and potential constitutional questions for businesses with foreign operations, creating new uncertainty and possible tax impacts.

Get Involved

Share your expertise and shape the future of the profession—volunteer with TXCPA and make a meaningful impact in your community.