← All Compliance Insights

CPA & Accounting

Your EFIN Is a Privilege, Not a Property Right: What Tax Preparers Should Understand

For a tax-preparation firm, electronic filing is not a convenience.

It is part of the firm's ability to operate. That makes an Electronic Filing Identification Number, or EFIN, one of the most operationally important credentials a tax practice has.

But a recent federal case demonstrates something tax professionals should understand clearly:

A firm's dependence on its EFIN does not give it a protected right to keep it.

Zirin Tax Company: The IRS Suspended the Firm's EFINs

Zirin Tax Co., Inc., doing business as Steven-Louis Income Tax Centers, was a relatively small New York tax-preparation business that had participated in IRS e-file for decades and electronically filed approximately 2,000 returns per year. In February 2024, the IRS suspended the firm's EFINs after a criminal investigation determined that fraudulent tax returns had been filed using them.

The impact on the business was significant enough that Zirin went to federal court seeking to have its e-file access restored. The firm argued, in part, that participation in IRS e-file effectively functioned as a business license and that continued possession of its EFINs therefore amounted to a constitutionally protected property interest.

The court disagreed.

The Court: E-File Participation Is a Discretionary Privilege

The federal court ultimately held that participation in the IRS e-file program is not a constitutionally protected property right. The IRS retains discretion to grant, deny, suspend or revoke participation based on its suitability standards.

The practical consequence is difficult for a tax firm to ignore:

EFIN ACCESS MAY BE ESSENTIAL TO YOUR BUSINESS.
CONTINUED ACCESS IS NOT GUARANTEED.

A firm may depend on electronic filing to serve virtually every tax client it has, while the IRS still retains substantial authority over whether that firm remains eligible to participate in the program.

Why This Matters for a Firm's Security and Compliance Program

The Zirin case matters even though the immediate issue before the court was the IRS's authority over participation in the e-file program. It demonstrates something every tax firm should understand:

A firm's dependence on its EFIN does not guarantee continued access to it.

Security incidents can occur even in organizations that have invested seriously in cybersecurity. No WISP, risk assessment or technical safeguard can promise that a firm will never be breached. But when a security failure does occur, the firm's overall security and compliance posture becomes much more important.

A firm should be able to demonstrate that it had already taken reasonable steps to safeguard taxpayer information, including:

  • maintaining a current Written Information Security Plan;
  • assessing risks to taxpayer and client information;
  • implementing appropriate administrative and technical safeguards;
  • controlling access to tax-processing systems;
  • using multifactor authentication where appropriate and available;
  • training employees;
  • monitoring and responding to suspicious activity;
  • maintaining an incident-response process; and
  • documenting that these safeguards were actually being maintained.

A breach by itself does not necessarily mean those obligations were ignored. But a breach combined with missing safeguards, outdated documentation, weak access controls or an inability to demonstrate that the firm's security program was actually being maintained can create a much more difficult regulatory and operational position.

The better position is to be able to show:

We understood the risk.
We had a program.
We implemented safeguards.
We maintained them.
And when something happened, we followed the process we had already established.

That does not guarantee a particular regulatory outcome. It does put the firm in a fundamentally stronger position than trying to build the evidence after the incident has already occurred.

Publication 4557: Guidance, but Guidance Tax Professionals Should Not Ignore

IRS Publication 4557, Safeguarding Taxpayer Data, is not itself a statute or regulation. A tax preparer is not fined, prosecuted or stripped of an EFIN simply for “violating Publication 4557.” But that does not make the publication unimportant.

The IRS publishes it specifically to tell tax professionals how taxpayer information should be safeguarded and to explain the broader security responsibilities that apply to the profession. It addresses security planning, access controls, employee practices, protection of stored information, phishing, incident response and the FTC Safeguards Rule. For a tax professional, that makes the expected security practices increasingly difficult to characterize as unknown or unforeseeable.

Publication 4557 is also explicit about the importance of a written security plan.

What Does a CPA Firm's WISP Actually Need to Include?

The WISP should not exist simply because the firm downloaded a template. It should describe the security program the firm is actually operating.

The FTC Safeguards Rule Adds Binding Security Requirements

Publication 4557 also directs tax professionals to the FTC Safeguards Rule. For covered firms, the Safeguards Rule is not guidance. It establishes requirements for developing, implementing and maintaining an information-security program designed to protect customer information.

The FTC Safeguards Rule for CPA Firms: What It Means in Practice

The important point is that these pieces should not live in separate compliance silos. The firm's WISP, FTC Safeguards program, IRS safeguarding practices and actual technical environment should describe the same operating security program.

There Are Also Separate Federal Laws Governing Tax Return Information

Security-program requirements are not the only federal obligations surrounding taxpayer data. Internal Revenue Code §7216 creates a separate criminal prohibition applicable to tax return preparers who knowingly or recklessly disclose tax return information, or use it for an unauthorized purpose, except where disclosure or use is permitted by law or regulation.

A violation is a federal misdemeanor and can carry a fine of up to $1,000, imprisonment for up to one year, or both. For certain improper disclosures or uses connected to taxpayer identity theft, the maximum criminal fine can increase to $100,000.

IRC §6713 establishes a related civil penalty for unauthorized disclosure or use of tax-return information.

The standard penalty is:

$250 per unauthorized disclosure or use, up to $10,000 per calendar year.

When the disclosure or use is connected with a crime involving taxpayer identity theft, the penalty increases to:

$1,000 per disclosure or use, up to $50,000 per calendar year.

These statutes address a different legal issue from simply failing to maintain a WISP or suffering a cybersecurity breach. A breach does not automatically establish a §7216 crime. But the existence of these separate statutory protections illustrates how seriously federal law treats information entrusted to a tax preparer.

A Security Failure and a Missing Security Program Are a Bad Combination

No security professional can promise that implementing a WISP, multifactor authentication, employee training or any other safeguard will make a breach impossible. Its purpose is to identify foreseeable risks, reduce those risks where reasonably possible, establish processes for detecting and responding to incidents, and document what the firm is doing to protect sensitive information.

Consider the difference between two firms experiencing comparable security incidents. One can produce:

  • its current WISP;
  • its documented risk assessment;
  • evidence of multifactor authentication and access controls;
  • security-awareness training records;
  • vulnerability-management records;
  • incident-response procedures;
  • logs showing security monitoring;
  • records of prior remediation; and
  • documentation showing that the program was periodically reviewed.

The other has little more than an antivirus subscription and an outdated policy document. The occurrence of the breach may be similar.

The evidence each firm can produce about what it did before the breach is very different. That is one reason compliance documentation should never be separated from actual security implementation.

Circular 230 Adds a Professional-Responsibility Dimension

For practitioners subject to Circular 230, taxpayer-information obligations can also intersect with professional discipline. Circular 230 identifies willful unauthorized disclosure or use of tax-return information as a form of disreputable conduct.

That does not mean every data breach becomes a Circular 230 disciplinary case. It does demonstrate that protection of taxpayer information is not simply an IT-department concern. It touches cybersecurity, federal tax law, professional responsibility and the firm's ability to continue serving taxpayers through IRS systems.

Protecting an EFIN Means Protecting the Environment Around It

An EFIN does not exist in isolation. A modern tax-preparation environment may involve:

  • tax-preparation software;
  • employee credentials;
  • administrator accounts;
  • workstations and laptops;
  • Microsoft 365 or other cloud services;
  • client portals;
  • remote-access tools;
  • email;
  • document-management systems;
  • third-party applications; and
  • employees authorized to prepare and transmit returns.

The firm should be asking:

  • Who can access tax-preparation and e-file systems?
  • Does every person have an individual account?
  • Where is multifactor authentication enabled?
  • Who has administrator privileges?
  • Are former employees removed promptly?
  • How is remote access controlled?
  • Are endpoints protected and monitored?
  • How are suspicious sign-ins investigated?
  • Are employees trained to recognize credential theft and phishing?
  • What happens when the firm suspects an account has been compromised?
  • Who contacts the IRS?
  • Who contacts legal counsel?
  • Who contacts the cyber-insurance carrier?
  • Who coordinates the technical investigation?

Too Small to Need a Security Program? What Real Cases Show Small Firms

Cybersecurity Is Also Business-Continuity Protection

The Zirin case adds another perspective that is easy to overlook. Cybersecurity protects more than confidentiality. For a tax firm, it protects the infrastructure the business depends upon to operate.

If the firm's ability to electronically file returns is disrupted, tax deadlines do not stop. The firm may still have:

  • returns due;
  • extensions to file;
  • payroll obligations;
  • estimated-tax deadlines;
  • client commitments; and
  • the intense workload of filing season.

That makes security of the tax-processing environment part of the firm's business-continuity planning.

Compliance Does Not Guarantee That Nothing Will Go Wrong

A functioning security program does not buy immunity from cyberattacks, and it does not guarantee that a regulator, insurer or the IRS will reach a particular conclusion following an incident.

What it does is put the firm in a better position before, during and after one. The firm has identified its risks, implemented safeguards, assigned responsibility, documented its processes and established how an incident will be escalated.

It also has evidence showing that security was being actively managed rather than addressed for the first time after something went wrong.

The Lesson From Zirin

Zirin challenged the loss of its e-file participation in federal court. It lost. The court concluded that the IRS has sufficient discretion over e-file participation that possession of an EFIN does not constitute a constitutionally protected property interest.

That does not mean every cybersecurity incident will lead to EFIN suspension. It means the ability to e-file is too important for a tax practice to treat the systems, accounts and data surrounding it casually.

The IRS has substantial authority over something the firm may depend upon every day to conduct its business.

That alone should make protection of the tax environment a management priority.

How GO InfoTek Can Help

GO InfoTek helps CPA firms and tax professionals build security programs around the systems and information their businesses actually depend upon. That can include:

  • security risk assessments;
  • Written Information Security Plan development and maintenance;
  • FTC Safeguards Rule support;
  • implementation and validation of technical safeguards;
  • identity and access-management review;
  • multifactor-authentication implementation and verification;
  • endpoint and network security;
  • vulnerability management;
  • employee security-awareness training;
  • incident-response planning;
  • breach-notification planning;
  • cyber-insurance response planning;
  • policy and documentation development; and
  • ongoing vCISO support.

The objective is not to promise that a security incident will never happen. It is to reduce the likelihood and impact of one—and make sure the firm can demonstrate that protecting taxpayer information was an established business process before the incident occurred.

Because for a tax firm, cybersecurity protects more than data.

It helps protect the firm's ability to operate.

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation