Guide for Tax Professionals

Secure File Transfer for CPAs

CPAs handle some of the most sensitive personal data in existence: Social Security numbers, bank accounts, income records. Understanding your security obligations isn't optional. Here's what you need to know.

Why CPAs need secure file transfer

Secure document handling isn't just a best practice. It's a legal and regulatory requirement for tax professionals.

IRS Publication 4557

The IRS's "Safeguarding Taxpayer Data" guide requires tax professionals to create and maintain a written information security plan (WISP). This includes encrypting taxpayer data in transit and at rest, controlling who can access it, and having a data destruction process.

Gramm-Leach-Bliley Act (GLBA)

The FTC's Safeguards Rule under GLBA applies to tax preparers as "financial institutions." It requires you to develop, implement, and maintain a comprehensive security program for customer information: including encryption, access controls, and secure disposal.

Malpractice & E&O liability

A data breach involving client SSNs, EINs, or financial records creates significant malpractice exposure. Courts have found that failing to implement reasonable security measures, when industry guidance exists, constitutes negligence.

Client trust & retention

Clients are increasingly aware of data security. A CPA who can explain their secure document handling process has a tangible competitive advantage over one who says "just email it to me."

What to look for in a secure transfer tool

Not every "secure" file sharing tool meets the bar for handling taxpayer data. Here's the checklist.

✓

Encryption at rest and in transit

Files should be encrypted with AES-256 (or equivalent) when stored, and all transfers should occur over TLS 1.2+. This satisfies both IRS Pub 4557 and GLBA encryption requirements.

✓

Granular access controls

Only authorized parties should access specific documents. Look for per-link or per-document access restrictions rather than broad shared folder permissions.

✓

Audit trails

IRS Pub 4557 expects you to track who accessed taxpayer data and when. Your transfer tool should log access events: downloads, uploads, and failed attempts.

✓

Automatic data destruction

GLBA requires secure disposal of customer information when it's no longer needed. Tools with automatic expiration and deletion help you enforce retention policies without manual cleanup.

✓

Client simplicity

If clients need to create accounts, install software, or navigate complex interfaces, they'll revert to email. The tool should work with a simple link, no client-side setup.

✓

Compliance documentation

Your WISP needs to reference the specific tools and procedures you use. Look for tools that can help you document your security measures for your written plan.

Common mistakes CPAs make

These are the most frequent security gaps we see in accounting practices, and each one creates real liability.

Emailing sensitive documents

Standard email is not encrypted end-to-end. Emails containing SSNs, W-2s, or bank statements can be intercepted, forwarded, or persist indefinitely in sent folders, recipient inboxes, and email backups. IRS Pub 4557 explicitly recommends against this.

Using consumer-grade tools

Dropbox, Google Drive, and WeTransfer are designed for general file sharing, not handling regulated financial data. They lack automatic expiration, granular access logs, and compliant data destruction, features your WISP needs to reference.

No data retention policy

Many firms collect client documents with no plan for when to delete them. Under GLBA, you're required to securely dispose of customer information you no longer need. Indefinite retention increases your breach surface with no benefit.

Sharing passwords over the same channel

Sending a password-protected file and the password in the same email thread defeats the purpose entirely. If the email is compromised, the attacker has both the file and the key. Passwords and files should travel through separate channels.

How DeadVault addresses these requirements

DeadVault was built for exactly this use case, professionals who need to exchange sensitive documents with clients under regulatory constraints.

RequirementHow DeadVault handles it
AES-256 encryption at restEvery file encrypted with AES-256-GCM using unique per-file keys
Encryption in transitAll transfers over TLS 1.2+, no unencrypted endpoints
Access controlsPer-link access with optional PIN protection, no shared folder permissions
Audit trailLogged access events, who downloaded what and when
Data destructionAutomatic expiration with cryptographic erasure: encryption keys are destroyed, making files permanently unrecoverable
Client simplicityClients use a simple link: no accounts, no software installs

DeadVault helps you implement security measures consistent with IRS Pub 4557 and GLBA requirements. It is not a substitute for legal counsel or a comprehensive WISP.

Frequently asked questions

Common questions about secure file transfer requirements for CPAs.

IRS Pub 4557 ("Safeguarding Taxpayer Data") requires tax professionals to have a Written Information Security Plan (WISP) that includes safeguards for protecting taxpayer data. For file transfers specifically, it recommends encrypting data in transit and at rest, using access controls to limit who can view documents, maintaining audit logs, and securely disposing of data when no longer needed. It does not mandate a specific tool, but it does expect you to document the measures you use.
IRS Pub 4557 and GLBA do not mandate a specific encryption algorithm, but AES-256 is the industry standard for protecting sensitive financial data. It's the same standard used by the U.S. government for classified information. When evaluating tools, look for AES-256 encryption (ideally AES-256-GCM, which provides both encryption and authentication) applied both at rest and in transit.
It depends on the tool. Some platforms require both parties to have accounts, which creates friction and often drives clients back to email. Tools like DeadVault use secure links that clients can access without creating an account. They click a link, upload or download files, and that's it. Reducing friction for clients is important because the most secure system in the world is useless if clients won't use it.
The FTC classifies tax preparers as "financial institutions" under the Gramm-Leach-Bliley Act. This means the Safeguards Rule applies to your practice, requiring you to develop a comprehensive security program that includes risk assessment, access controls, encryption, secure data disposal, and incident response planning. This applies to all tax preparers, not just large firms.
Sending unencrypted emails containing taxpayer PII (SSNs, EINs, financial data) is inconsistent with the safeguards recommended by IRS Pub 4557 and required by GLBA. While the IRS hasn't penalized individual preparers solely for email use, a data breach resulting from unencrypted email would create significant liability exposure and could be cited as evidence of inadequate security measures.
A WISP should document your firm's security policies, including: designated security coordinator, risk assessment results, access control policies, encryption methods for data at rest and in transit, employee training procedures, incident response plan, and data retention/destruction schedule. IRS Pub 4557 provides a template. Your file transfer tool is one component. You should be able to reference it specifically in your plan.

Ready to secure your document workflow?

Start transferring client documents securely in under 2 minutes. No client accounts required.