Your clients trust you with numbers most of their friends and family will never see. Income, deductions, medical expenses, business losses, the whole financial autobiography. So here is an uncomfortable question worth sitting with before a client asks it first: once that return leaves your office and lands with the IRS, who else gets to look at it?
The answer, according to a recent government report, is more people than most practitioners would guess. The IRS is currently sharing taxpayer data with more than 1,100 outside organizations, and the report found the agency is struggling to keep an accurate, current list of exactly who those organizations are and what they are doing with the information. That is not a conspiracy theory. That is an oversight finding.
Some of this sharing is mundane and legally required. State tax agencies need federal data to cross-check state returns. Certain federal programs verify income for benefits eligibility or student financial aid. Law enforcement gets access under specific statutory triggers. None of that is new, and none of it should alarm anyone.
What should get a practitioner's attention is the gap between sharing that happens for legitimate reasons and an agency that cannot fully account for where the data ends up. If this story gets picked up by mainstream media, and stories about government data handling tend to travel, your phone will ring with a version of one question: is my information safe with you.
You will not be able to answer for the IRS. But you can and should be able to answer for your own firm. Can you tell a client, in plain language, what happens to their data once it hits your systems? Who has access internally? What happens to data from clients you no longer serve? Is your file sharing platform encrypted at rest and in transit? If you outsource any prep or bookkeeping work, does that vendor's data handling meet a standard you have actually reviewed, or one you assumed was fine?
This is a good moment to separate your firm's reputation from the IRS's. Firms that get ahead of data privacy questions, with a short client-facing explanation of their own practices, come across as more trustworthy than firms that go quiet and hope nobody asks. A one-page data handling summary, sent proactively rather than defensively, costs you an afternoon and buys you real credibility.
Keep your WISP up to date and train your team. They should know the answers to these questions too and be able to sign off on your WISP document confident in their ability to follow those procedures.
With more and more firms turning to AI in their work products, clients are paying more attention than ever to the security of their data. The IRS's data sharing problem is not yours to fix. But the trust question it raises absolutely is.
Dr. Christine Gervais is a licensed CPA, using her skills to help businesses grow and achieve their fullest potential. Christine has a Master’s degree in accounting from Southern New Hampshire University in addition to holding her CPA license for over a decade. Notably, Christine is a nationally recognized speaker providing education to other CPAs on how to best serve clients as well as instruction on a wide variety of topics for business owners on how to maximize success. Christine prides herself on the value she can bring to clients with her extensive tax knowledge and provides strategic, forward-thinking financial strategies to help clients grow. When not behind her desk, you can find Christine spending quality time with her daughter and stepson or tending to the family’s excessively loved farm animals.
Like what you're reading?
Subscribe to our FREE newsletter and we'll deliver content like this directly to your inbox.


