IRS Publication 4557
Safeguarding Taxpayer Data. The IRS guide for preparers, including the six basic protections it expects every practice to have in place.
Managed IT and cybersecurity for accounting and tax practices across Massachusetts & New England — built around a calendar you do not control and data that carries a legal duty.
Generic IT support is built for a business whose worst week is like its best week. Yours is not.
Filing dates are fixed by statute. A failure in March is not the same event as the identical failure in July, and an IT arrangement that treats them alike has misunderstood the business.
Identification numbers, income, payroll, bank detail — for every client on the list. A practice holds concentrated personal data that most businesses never touch.
Protecting that data is not only good practice. For professional tax preparers it is a legal requirement, with a written plan expected to exist and to be followed.
Not advice, and not best practice. A practice that prepares returns is already covered by rules that name a written plan by name — and a Massachusetts practice is covered by one more that most providers never mention.
Safeguarding Taxpayer Data. The IRS guide for preparers, including the six basic protections it expects every practice to have in place.
16 CFR Part 314, under the Gramm–Leach–Bliley Act. It treats a tax preparer as a financial institution, which surprises most practices the first time they read it.
The IRS and the Security Summit publish a template for the written plan itself, so there is no argument about what one is supposed to contain.
The state standard for protecting personal information of Massachusetts residents. It requires a written programme of its own and is specific about encryption on portable devices and over public networks. It applies to you because of where your clients live.
Limits how return information may be disclosed or used. It is a criminal provision, which is why access to it is a technical question as much as a policy one.
The Massachusetts breach notification law. It decides what you must do, and how quickly, on the worst day. Knowing that in advance changes what you build beforehand.
Access control and least privilege. Encryption at rest and in transit. Logging that is retained and actually reviewed. Backup with recovery that has been tested. Awareness training for the people who receive the phishing attempt.
A plan that cannot point at a running control is a document, not a safeguard. We write down what exists, where it runs and who has access, so the plan describes reality rather than intention.
Whether your plan meets your obligations is between your firm and its adviser. We will tell you what is in place and what is not. Anyone promising to make you compliant is selling a guarantee they cannot honour.
The Safeguards Rule is specific about what has to exist. Some of it is ours to build and run. Some of it is yours and cannot be delegated — and a provider who implies otherwise has told you something untrue before the engagement starts.
The rule requires one qualified individual responsible for the programme, and that person is designated by your firm. Responsibility does not transfer to a vendor. What we provide is something to be accountable for: a documented environment and a current statement of which controls are actually running. Yours, with our evidence.
Written down, not discussed in a meeting. It has to say what could go wrong with the data you hold and what is being done about each item. We supply the technical half — the inventory, the data locations, the access paths and what we found exposed. Shared.
Every control downstream depends on this and most practices have never done it. The answer usually includes somewhere nobody listed: a local drive, an old server share, an archive folder, a preparer’s home machine. Ours.
Who can reach client data, from where, and for how long. The removal half is the one that fails: accounts outliving the season are among the most common findings when we first document a practice. Ours.
Disk encryption on anything that leaves the office, and encrypted transfer for anything carrying client data. Massachusetts is more explicit here than the federal rule, and the stricter standard is the one that applies to you. Ours.
On everything that can reach client information, not only on email. It is the single control that stops the most common compromise, and it is also the one most often left switched on for some accounts and optional for the rest. Ours.
Records of who reached what, retained long enough to be worth having. A log nobody kept is evidence that did not exist on the day it was needed, and that day is never scheduled. Ours.
Safeguards have to be tested rather than assumed. That includes the backup: one that has never been restored is an assumption wearing the word backup. We restore it and tell you how long it took. Ours.
For everyone who touches client data, seasonal staff included, because the message arrives at whoever is busiest. Training before the season is a different thing from a policy written in June. Ours, your people.
Who decides, who is called, in what order, and what Massachusetts breach notification requires of you and by when. Written while nothing is wrong, because it is unwritable while something is. Shared.
The rule makes you responsible for everyone else holding your clients’ data — and that includes us. We will put in writing what we access, how, and what happens to it, so you can oversee us with something more than trust. Ours to disclose, yours to review.
The qualified individual reports on the programme to the firm’s leadership. We give them the material it is built from, in language a partner can read without a translator. Yours, with our material.
Not a list of products. The parts that stop a practice working when one of them fails.
UltraTax CS, Lacerte, ProSeries, ProConnect, Drake, CCH Axcess and ProSystem fx — hosted or running on your own server, single-seat or several preparers in the same file. These behave differently in February than in the quiet week they were tested.
QuickBooks Desktop and Online, Sage, Xero, and the payroll systems beside them. Karbon, Canopy and whatever the firm uses to know which return is where. Each keeps its own data store, which is why a backup of documents alone is not a backup of the practice.
SmartVault, ShareFile, the portal built into the tax software, or the shared drive that is quietly doing the job instead. Source documents and signed returns arrive and leave somewhere, and that path is either controlled or it is a gap.
Prior-year data files you still need and the software version that opens them. Concurrent licences that run out at the worst hour. Whether an application is genuinely hosted or just installed on a machine someone calls the server. We ask before the season, not during it.
Secure file exchange through SharePoint and OneDrive instead of returns sent as attachments, links that expire, anti-impersonation rules, enforced MFA, and retention configured so correspondence from three years ago is still findable.
Returns in progress, not only finished files. Practice management and preparation software keep their own data stores, and a backup covering documents but missing those restores a practice that still cannot file.
Temporary preparers given the access the role needs on day one and losing it the day they finish, in one step. Accounts outliving the season are among the most common findings when we first document a practice.
Designed for your busiest Tuesday rather than a quiet afternoon, with remote access for seasonal staff that is controlled and revocable instead of a port opened once and never closed.
Source documents, signed returns and the server usually sit behind one door. Who can open it, and whether that is recorded, belongs in the same risk picture as passwords.
We support these environments. We are not a reseller, partner or certified implementer of any of them, and we will not pretend to be — if your practice runs something we have not met, you will hear that rather than a guess.
Every provider says they understand deadlines. These are the dates, and what each one changes about what we are allowed to do.
W‑2 and 1099 forms are due to recipients by 31 January. From the start of the month nothing structural happens: no migrations, no version changes, no maintenance with a visible moment. Seasonal accounts are created with an end date already set rather than one promised later.
The quiet systems of December are now carrying several preparers at once. Our work here is monitoring and response. Anything that can wait, waits, and we will say so rather than fit it in.
Returns for partnerships and S corporations are due. This is the week where a failed print queue is not an inconvenience, it is a filing problem, and the queue is triaged accordingly.
Individual returns. The only acceptable work is keeping what exists running. A provider proposing an upgrade in this window has told you something about how they plan.
Extended partnership and S corporation returns in September, extended individual returns in October. Two more windows where nothing structural happens — and the two most often missed by a provider who only knows about April.
Hardware, migrations, version upgrades, server replacement, anything with a visible moment. The work gets planned for these months on purpose, so that a lost hour costs an hour rather than a deadline.
The order matters more than the speed, and the season decides when each step is allowed to happen.
What the practice depends on, written down: applications, accounts, devices, data, licences and the connections between them. Most practices have never had this on one page, which is why nobody can answer what happens if a given machine dies.
Whatever is actively costing you — failing backups, unmanaged access, systems nobody patches. This part happens first regardless of the month, because leaving it is the larger risk.
Identity, access, endpoint protection, email controls and the logging behind them. These are the controls a written security plan names, and they are implemented before anything is promised about them.
No migrations, no avoidable maintenance, no visible interruptions. Priority follows the calendar: a preparer who cannot open a return is not the same ticket as a printer.
The work with a visible moment waits for the window where a lost hour costs an hour. That is when hardware, migrations and anything structural get done.
You will not hear
You will hear
A provider who never talks you out of anything is not being agreeable. They are being paid by the yes — and for a profession built on independent judgement, that should be familiar.
Yes, and the question is fair, because most of the pain is in the applications rather than the hardware. We run environments built on QuickBooks, tax preparation software, payroll systems and the document management around them, including the multi-user and terminal-server setups several preparers open at once.
Where a practice runs something we have not met, we say so rather than imply otherwise. What we bring is the environment around it: the server or service it runs on, the identity controlling who reaches it, the backup protecting it, and the vendor relationship when the application itself is the problem.
You can, but in most cases you should not, and we will say so. A transition done properly means documenting the environment, moving identity and access, and testing recovery. None of that belongs in the weeks you cannot afford a surprise.
What we will do mid-season is the urgent part: stabilise what is actively failing, close anything genuinely dangerous, and leave the rest until the calendar allows it. The full transition waits.
No, and nobody can honestly tell you otherwise. We build and operate technical controls — access control, encryption, logging, retention, tested recovery, awareness training — which are the parts a security plan describes.
Whether your plan satisfies your obligations is a determination for your firm and its adviser. A provider offering to guarantee compliance is offering something they cannot deliver, and that promise is worth nothing at the moment it is tested.
They are created with the access the role needs and removed when the engagement ends, as one step rather than two. Accounts that outlive the season are among the most common findings when we first document a practice.
The same applies to building access where we manage it: a returned fob is not evidence it was the only one, so credentials issued for a season expire with it.
Size is not the test. A practice that cannot file, invoice or reach its records during a busy week is not having a small problem because it has few staff.
What changes with size is the shape of the answer, not whether one is needed. A five-person practice is not a scaled-down version of a fifty-person one, and building it that way is how firms end up paying for complexity nobody can operate.
It applies because of what you do, not how large you are. The Gramm–Leach–Bliley Act defines a financial institution broadly enough to include a practice that prepares returns, and the FTC has said so plainly. There is no small-firm exemption from having a plan; there is a narrower set of obligations below twenty-five thousand consumers, which is a different thing from being outside the rule.
A Massachusetts practice has a second obligation regardless: 201 CMR 17.00 applies to anyone holding personal information about a resident of the Commonwealth, with no size threshold at all.
201 CMR 17.00 asks for a written information security programme of its own, and it is more explicit than the federal rule about encryption — personal information on laptops and other portable devices, and personal information sent across public networks or wirelessly, is to be encrypted.
It matters because the stricter standard is the one you are held to. A provider working to the federal rule alone has built to the lower of the two obligations that apply to you, and that gap only becomes visible on the day it is examined.
Often, yes. A co-managed arrangement works when the split is written down: we take the layer needing continuous attention — monitoring, patching, security, backup, identity — and your person keeps the applications and processes specific to the practice.
What does not work is an undefined split where each side assumes the other has something covered.
Let’s identify the gaps before they become expensive problems.
An honest look at the environment your practice runs on, and where it would hurt most if something failed. No obligation, and no pressure to decide on the call.