The honest reality
Let's be straightforward: most SSNs sent over email don't get intercepted. Millions of tax documents are emailed every year, and the vast majority arrive without incident. If you've done it before, you're not alone, and you probably got away with it.
But the risk is asymmetric. The upside of emailing an SSN is convenience. You save a few minutes. The downside is identity theft for your client, regulatory penalties for your practice, and potential malpractice claims against you personally. You're betting your client's financial identity and your professional license on "probably fine."
That's a bad bet. Not because the odds are terrible, but because the stakes are.
What can actually go wrong
These aren't hypotheticals. Every one of these has happened to real firms.
Email sent to the wrong address
Autofill picks the wrong "John Smith." You don't notice until the other John replies asking why he has someone's Social Security number. This is the most common scenario, and it has nothing to do with hackers.
Client forwards the email
Your client forwards your email to their spouse, business partner, or another advisor, and now their SSN is in a forwarded thread sitting in someone else's inbox indefinitely. You had no control over that.
Email server breach
The 2013-2014 Yahoo breach exposed 3 billion accounts. Your email provider is a target. If their servers are compromised, every SSN you've ever emailed is exposed, not just the most recent one, but years' worth.
Phishing attack compromises an inbox
An attacker gets access to your client's email through a phishing link. They now have access to every email in the inbox, including the one with their SSN. This happens far more often than most people realize.
Device theft with cached emails
A laptop or phone is lost or stolen. Most email clients cache messages locally, often without encryption. That SSN you emailed two years ago is now on a device you don't control.
The regulatory consequences
IRS Publication 4557
IRS Pub 4557 ("Safeguarding Taxpayer Data") requires tax professionals to create and maintain a Written Information Security Plan. That plan must include safeguards for protecting taxpayer data, including encryption for data in transit. Emailing an unencrypted SSN is inconsistent with this requirement. Maintaining your PTIN requires compliance.
AICPA Code of Professional Conduct
The AICPA's "Confidential Client Information" rule (ET Section 1.700.001) requires members to protect client information obtained during professional services. While the rule doesn't prescribe specific technical measures, sending unencrypted SSNs via email, when secure alternatives exist, is difficult to reconcile with the obligation to maintain confidentiality.
State board sanctions
State boards of accountancy can take disciplinary action against CPAs who fail to protect client data. A breach resulting from inadequate security practices could lead to reprimand, suspension, or license revocation, depending on the state and the severity of the incident.
Malpractice insurance gaps
Standard professional liability policies may not cover data breaches resulting from negligent handling practices. Insurers increasingly evaluate whether firms followed reasonable security measures when deciding coverage. If industry guidance says "encrypt sensitive data in transit" and you emailed it in plaintext, that's a difficult position to defend.
This is general information, not legal advice. Consult with a data privacy attorney for guidance specific to your practice and jurisdiction.
What to do if it already happened
If you've already emailed an SSN, don't panic. Here are practical steps to take.
Notify the client promptly
Let them know what happened, what information was exposed, and when. Be direct. Clients handle bad news far better than discovering you hid it.
Document the incident
Record what was sent, to whom, when you became aware, and what steps you took in response. This documentation matters if questions arise later.
Consider offering credit monitoring
If an SSN was sent to the wrong person or you have reason to believe it was exposed, offering credit monitoring is a reasonable protective measure for the client.
Review your data security plan
If you have a Written Information Security Plan (WISP), check whether the incident reveals a gap. If you don't have a WISP, this is a strong reason to create one, IRS Pub 4557 provides a template.
Implement secure transfer going forward
Use this as the inflection point to move to encrypted file transfer for all sensitive client documents. It's much easier to prevent the next incident than to remediate this one.
If you believe client data was exposed to an unauthorized party, consider consulting with a data privacy attorney about notification obligations in your state.
How to prevent it going forward
Practical steps that don't require an IT department or a six-figure budget.
Use encrypted file transfer for all client documents
Replace email attachments with a secure transfer tool that encrypts files in transit and at rest. This is the single most impactful change you can make. The tool should be simple enough that clients actually use it, if it's harder than email, people will revert.
Train staff on email security
Make sure everyone in your practice knows not to put SSNs, EINs, or bank account numbers in email. This isn't a one-time memo. It needs periodic reinforcement, especially during busy season when shortcuts are tempting.
Establish a Written Information Security Plan
IRS Pub 4557 expects tax professionals to maintain a WISP that documents your security practices. This should include how you handle client documents, what tools you use, and how you train staff. The IRS provides a template to work from.
Use separate channels for access credentials
If you use password-protected files or secure links with PINs, send the file and the PIN through different channels: the link by email, the PIN by text, for example. If one channel is compromised, the attacker doesn't get both pieces.
Frequently asked questions
Common questions about the risks and obligations around emailing SSNs.
Prevention is easier than remediation
Secure file transfer for client documents. No client accounts, no software installs, no excuses to fall back to email.