Guide for Accountants & Payroll Providers

How to Send W-2s Securely to Clients

W-2s contain Social Security numbers, wages, and employer data, everything needed for identity theft. Here's how to deliver them without email.

What's on a W-2 (and why it matters)

A single exposed W-2 gives a bad actor enough information to file a fraudulent tax return, open credit accounts, and steal an identity. Here's what's on the form:

Social Security Number

Can be used to open credit accounts, file fraudulent tax returns, or steal an identity outright

Employer Identification Number (EIN)

Enables fraudulent business filings and payroll fraud schemes

Wages & compensation

Reveals exact income, used to craft convincing phishing and social engineering attacks

Home address

Combined with SSN, completes the profile needed for full identity theft

Federal & state tax withholdings

Allows a bad actor to file a fraudulent return calibrated to the real numbers, making it harder to detect

The bottom line: A W-2 is one of the most sensitive documents in tax preparation. It's not just wages. It's a complete identity profile. Any delivery method needs to account for this.

Why email isn't safe for W-2s

Email was designed for convenience, not security. It's the most common way W-2s are shared, and the least appropriate.

SSNs visible in plaintext attachments

A standard PDF or Excel W-2 attachment is not encrypted. Anyone with access to the email, including IT administrators, compromised accounts, or a forwarded thread, can open it and read every SSN.

Email is stored on multiple servers indefinitely

Your email server, their email server, any backup or archive system on either side. That W-2 now exists in at least 4-6 places you don't control, with no expiration date.

No way to revoke access after sending

Once an email is sent, it's gone. If you send a W-2 to the wrong address, or a client's email is compromised next month, there's nothing you can do. The document is permanently out of your control.

No audit trail of who opened it

Standard email gives you no confirmation that the right person, and only the right person, accessed the document. Read receipts are unreliable and easily disabled. If a W-2 is leaked, you have no way to trace how.

5 ways to send W-2s securely

Ranked from strongest digital security to most physically secure. The best option depends on your practice size, budget, and how your clients prefer to receive documents.

1

Encrypted file transfer with auto-destruction

DeadVault

Best for practices that want zero data retention after delivery

Advantages

  • AES-256-GCM encryption, SSNs are never stored in plaintext
  • Files self-destruct after the deadline via cryptographic erasure
  • No client accounts needed, just a secure link
  • Audit trail of access without persistent data storage

Limitations

  • Files aren't available indefinitely, clients must download before the deadline
  • Requires a paid subscription (though typically $15-25/month)
  • Not a full document management system: designed for delivery, not storage
2

Secure client portal

ShareFile, SmartVault, Canopy

Best for firms that need ongoing document management alongside delivery

Advantages

  • Persistent document storage: clients can access files anytime
  • Often includes e-signatures, workflow tools, and CRM integrations
  • Established compliance certifications (SOC 2, etc.)
  • Good for firms already using these platforms for other workflows

Limitations

  • Per-user pricing adds up quickly ($30-100+/month)
  • Clients must create accounts and remember passwords
  • Documents persist indefinitely unless manually cleaned up: more data liability
  • Setup complexity: onboarding, permissions, folder structures
3

Password-protected PDF via separate channel

Free, using any PDF tool

Best for occasional use when budget is zero

Advantages

  • Free: no subscription or software required
  • Better than unprotected email attachments
  • Client doesn't need special software to open

Limitations

  • You need to communicate the password through a separate channel (phone, text)
  • Most people use weak passwords or reuse passwords across clients
  • PDF password protection is not true encryption. It can be cracked
  • No audit trail, no auto-destruction, no revocation
  • Doesn't scale well past 10-20 clients
4

Encrypted email service

ProtonMail, Virtru, Zix

Best for firms already using encrypted email for other communications

Advantages

  • End-to-end encryption when both parties use the same provider
  • Virtru and Zix work as plugins with existing email workflows
  • Some offer message expiration and access revocation

Limitations

  • Encryption often breaks when the recipient uses a different email provider
  • No auto-destruction of attachments in most cases
  • Clients may need to create accounts or click through extra steps
  • Cost varies: free (ProtonMail basic) to $5-10/user/month (Virtru, Zix)
5

Secure physical delivery

Hand delivery, USPS Certified Mail, FedEx

Best for high-value situations or clients who distrust digital tools

Advantages

  • No digital exposure: the document never touches a server
  • USPS Certified Mail provides a delivery confirmation
  • Some clients genuinely prefer paper

Limitations

  • Not scalable for dozens or hundreds of clients
  • Physical mail can be lost, stolen, or delivered to the wrong address
  • Slow: days versus seconds
  • No encryption, no access control once the envelope is opened
  • Printing W-2s creates another copy that needs to be secured or destroyed

Using DeadVault for W-2 delivery

If you want encrypted delivery with automatic destruction, no persistent data, no manual cleanup, here's the specific workflow.

1

Create a drop for the client

Set a deadline (e.g., 14 days) and optionally attach a payment gate if you're collecting a prep fee before the client can download.

2

Upload the W-2

The file is encrypted with AES-256-GCM using a unique per-file key. The original filename is never stored on disk, only a UUID-based reference.

3

Share the secure link

Send the link via email, text, or your client communication tool. The client clicks it: no account creation, no password, no app install.

4

Client downloads the W-2

If you set a payment gate, the client pays first. The download is logged so you have an audit trail of who accessed the document and when.

5

Auto-destruction after deadline

When the deadline passes, the encryption keys are destroyed. The W-2 becomes mathematically unrecoverable, no manual cleanup, no lingering copies.

For tax season bulk delivery: Create one drop per client with the W-2 (and any other return documents). If you're collecting prep fees, enable the payment gate so clients pay before downloading. Each W-2 gets its own encryption key, so a compromise of one client's link doesn't affect any other client's documents.

Frequently asked questions

What accountants and payroll providers actually ask about secure W-2 delivery.

The IRS allows electronic delivery of W-2s under specific conditions (IRS Notice 2004-10). Employees must affirmatively consent to electronic delivery, and the document must be accessible through a secure website. The employer must notify the employee when the W-2 is available and provide instructions for accessing it. If an employee doesn't consent, you're still required to provide a paper copy. For third-party delivery to accountants or tax preparers, the W-2 is being shared as part of tax preparation, standard data protection practices (encryption in transit and at rest) apply under IRS Publication 4557.
There's no single mandated encryption standard specifically for W-2s, but IRS Publication 4557 (Safeguarding Taxpayer Data) recommends encryption for all taxpayer data in transit and at rest. AES-256 is the most widely accepted standard: it's what banks, government agencies, and healthcare systems use. For practical purposes, any delivery method that uses AES-128 or AES-256 encryption meets or exceeds what regulators expect. Plain email, password-protected PDFs (which use weaker encryption), and unencrypted cloud links do not meet this bar.
This depends on the tool you're using. With DeadVault specifically, you can extend the deadline once, the extension grants half the original duration (e.g., a 14-day deadline gets a 7-day extension), with a hard cap of 45 days from creation. If the client still doesn't download it, you'd need to create a new drop and re-upload. For other tools like ShareFile or SmartVault, documents persist indefinitely so this isn't an issue, though that persistence is itself a security tradeoff.
For firms delivering dozens or hundreds of W-2s, the workflow depends on your volume. Most secure portals (ShareFile, SmartVault) support batch uploads with per-client folders. With an ephemeral tool like DeadVault, you'd create a drop per client and upload each W-2 individually. This is more work upfront but ensures each client only sees their own document, and each W-2 has its own encryption key and destruction timeline. For very high volume (500+ employees), payroll platforms like ADP, Gusto, or Paychex have built-in electronic W-2 distribution that handles consent and delivery at scale.
It's better than nothing, but it has real limitations. Standard PDF password protection (the kind most tools create) uses weak encryption that can be cracked with freely available tools. Even "strong" PDF encryption (AES-256) only protects the file itself: not the email it's attached to, not the copies on mail servers, and not the version sitting in the client's downloads folder forever. The biggest practical problem is password management: you need a unique, strong password per client, communicated through a separate channel. At scale, most people end up using weak passwords or the same password for everyone, which defeats the purpose.
Yes. Tax preparers and payroll providers have legal obligations to protect taxpayer data under IRS regulations, state data breach notification laws, and in many cases GLBA (Gramm-Leach-Bliley Act). If a W-2 is exposed due to negligent handling, such as emailing it unencrypted. You could face IRS penalties, state regulatory action, and civil liability. The specifics vary by state and the nature of the breach, but the trend is clear: regulators expect reasonable security measures, and "I emailed it" is not considered reasonable for documents containing SSNs.

Stop emailing W-2s

Whether you choose DeadVault or another secure method, the important thing is to stop sending SSNs through unencrypted email. Your clients' data, and your liability, depends on it.