Guide for Tax Professionals

What Happens If a CPA Emails a Client's SSN?

Probably nothing. But when something does happen, the consequences are severe.

The honest reality

Let's be straightforward: most SSNs sent over email don't get intercepted. Millions of tax documents are emailed every year, and the vast majority arrive without incident. If you've done it before, you're not alone, and you probably got away with it.

But the risk is asymmetric. The upside of emailing an SSN is convenience. You save a few minutes. The downside is identity theft for your client, regulatory penalties for your practice, and potential malpractice claims against you personally. You're betting your client's financial identity and your professional license on "probably fine."

That's a bad bet. Not because the odds are terrible, but because the stakes are.

What can actually go wrong

These aren't hypotheticals. Every one of these has happened to real firms.

Email sent to the wrong address

Autofill picks the wrong "John Smith." You don't notice until the other John replies asking why he has someone's Social Security number. This is the most common scenario, and it has nothing to do with hackers.

Client forwards the email

Your client forwards your email to their spouse, business partner, or another advisor, and now their SSN is in a forwarded thread sitting in someone else's inbox indefinitely. You had no control over that.

Email server breach

The 2013-2014 Yahoo breach exposed 3 billion accounts. Your email provider is a target. If their servers are compromised, every SSN you've ever emailed is exposed, not just the most recent one, but years' worth.

Phishing attack compromises an inbox

An attacker gets access to your client's email through a phishing link. They now have access to every email in the inbox, including the one with their SSN. This happens far more often than most people realize.

Device theft with cached emails

A laptop or phone is lost or stolen. Most email clients cache messages locally, often without encryption. That SSN you emailed two years ago is now on a device you don't control.

The regulatory consequences

IRS Publication 4557

IRS Pub 4557 ("Safeguarding Taxpayer Data") requires tax professionals to create and maintain a Written Information Security Plan. That plan must include safeguards for protecting taxpayer data, including encryption for data in transit. Emailing an unencrypted SSN is inconsistent with this requirement. Maintaining your PTIN requires compliance.

AICPA Code of Professional Conduct

The AICPA's "Confidential Client Information" rule (ET Section 1.700.001) requires members to protect client information obtained during professional services. While the rule doesn't prescribe specific technical measures, sending unencrypted SSNs via email, when secure alternatives exist, is difficult to reconcile with the obligation to maintain confidentiality.

State board sanctions

State boards of accountancy can take disciplinary action against CPAs who fail to protect client data. A breach resulting from inadequate security practices could lead to reprimand, suspension, or license revocation, depending on the state and the severity of the incident.

Malpractice insurance gaps

Standard professional liability policies may not cover data breaches resulting from negligent handling practices. Insurers increasingly evaluate whether firms followed reasonable security measures when deciding coverage. If industry guidance says "encrypt sensitive data in transit" and you emailed it in plaintext, that's a difficult position to defend.

This is general information, not legal advice. Consult with a data privacy attorney for guidance specific to your practice and jurisdiction.

What to do if it already happened

If you've already emailed an SSN, don't panic. Here are practical steps to take.

1

Notify the client promptly

Let them know what happened, what information was exposed, and when. Be direct. Clients handle bad news far better than discovering you hid it.

2

Document the incident

Record what was sent, to whom, when you became aware, and what steps you took in response. This documentation matters if questions arise later.

3

Consider offering credit monitoring

If an SSN was sent to the wrong person or you have reason to believe it was exposed, offering credit monitoring is a reasonable protective measure for the client.

4

Review your data security plan

If you have a Written Information Security Plan (WISP), check whether the incident reveals a gap. If you don't have a WISP, this is a strong reason to create one, IRS Pub 4557 provides a template.

5

Implement secure transfer going forward

Use this as the inflection point to move to encrypted file transfer for all sensitive client documents. It's much easier to prevent the next incident than to remediate this one.

If you believe client data was exposed to an unauthorized party, consider consulting with a data privacy attorney about notification obligations in your state.

How to prevent it going forward

Practical steps that don't require an IT department or a six-figure budget.

✓

Use encrypted file transfer for all client documents

Replace email attachments with a secure transfer tool that encrypts files in transit and at rest. This is the single most impactful change you can make. The tool should be simple enough that clients actually use it, if it's harder than email, people will revert.

✓

Train staff on email security

Make sure everyone in your practice knows not to put SSNs, EINs, or bank account numbers in email. This isn't a one-time memo. It needs periodic reinforcement, especially during busy season when shortcuts are tempting.

✓

Establish a Written Information Security Plan

IRS Pub 4557 expects tax professionals to maintain a WISP that documents your security practices. This should include how you handle client documents, what tools you use, and how you train staff. The IRS provides a template to work from.

✓

Use separate channels for access credentials

If you use password-protected files or secure links with PINs, send the file and the PIN through different channels: the link by email, the PIN by text, for example. If one channel is compromised, the attacker doesn't get both pieces.

Frequently asked questions

Common questions about the risks and obligations around emailing SSNs.

It depends on your state and the circumstances. Most states have data breach notification laws, but they typically apply when there's unauthorized access, not every misdirected email necessarily qualifies. That said, if you sent an SSN to the wrong person, many states would consider that a reportable breach. The specific requirements vary significantly by jurisdiction. Consult with a data privacy attorney for guidance specific to your situation and state.
This happens constantly, a client replies to an email with "here's my SSN: XXX-XX-XXXX" before you can stop them. While you didn't initiate it, you now have their SSN sitting in plaintext in your email. Best practice: delete the email, ask the client to send it through a secure channel instead, and use this as an opportunity to set up a secure transfer process for future exchanges. You might also consider adding a note to your engagement letters asking clients not to email sensitive information.
Standard CPA professional liability (E&O) policies vary in their coverage of data breaches. Some include limited cyber liability coverage, while others exclude it entirely or require a separate rider. If you regularly handle sensitive client data by email, and most CPAs do, review your policy's data breach provisions specifically. Many insurers are also looking at whether firms followed reasonable security practices when evaluating claims, which is another reason to have a documented security plan.
IRS Publication 4557, "Safeguarding Taxpayer Data," outlines the IRS's expectations for tax professionals. It requires a Written Information Security Plan (WISP) that covers how you protect client data, including encryption for data in transit and at rest, access controls, employee training, and an incident response process. The IRS also requires tax professionals to comply with the FTC Safeguards Rule under GLBA, which applies to "financial institutions", a category that includes tax preparers. These aren't suggestions, they're requirements for maintaining your PTIN.

Prevention is easier than remediation

Secure file transfer for client documents. No client accounts, no software installs, no excuses to fall back to email.