Gary,
You are 100% correct that password protecting a pdf file attachment is not equivalent to sending an encrypted email.
If the governments are requiring encrypted emails, we have some real adventures ahead of us. I looked at a PrivateSky, Voltage, Send and Hushmail and am not sure I would want to use any of them.
Do you have any suggestions?
Disclosure Authorization
Collapse
X
-
Just a quick comment, since my time is limited right now:
"Password protected" is not synonymous with "encrypted." Some bookkeeping software, for example, requires a password to ensure that only the right people make changes, but the underlying data is easily cracked. I don't know whether a password-protected Adobe Acrobat file (using current versions) is encrypted, but my guess is that early versions weren't.
Using PGP or similar products to encrypt the underlying hard drive is an excellent idea. I think the business versions of Windows 7 have that ability built-in. Personally, I consider not doing that for any drive containing client data to be negligent, whether or not it's portable.
I've never seen any authoritative statement that sending customer data through e-mail in the clear would be malpractice. I believe it's an issue and should be avoided, but it's a mixture of perception and real risk. I'm not a lawyer, but I worry that if something is perceived as being a generally accepted practice, then that might raise a negligence argument, even if the underlying practice isn't cost effective.Leave a comment:
-
Doug, thank you so much for your thoughts again. I agree with you, however I am not sure that this is all there is to it.
When these rules came out I was glad at first, thinking that preparers who send tax return info offshore would now need consent and clients at least than know about it. On second thought I realized that any form for signature could be presented to the client and client would sign blindly. Almost all my clients do so with my engagement letter even new ones.
We are so bombarded with forms to sign noadays that we really don't pay much attention. Leave alone understanding every bit of it.
I also thought that clients would be better protected from bad RAL practices but that is not true either since whoever want to do something bad will always find a way.
I believe that all the new regulations are mainly aimed against us hard working, honest tax return preparers. Bigger offices have resources to deal with this or even find a way around things. But we will grow more and more tired of these things and than - one day - a huge number of us are weeded out. Wouldn't be surprised if next thing that happens is big companies going to offices, which are their most fierce competition, incognito, and then being a whistle blower.Leave a comment:
-
Gretel,
In my opinion (yes, I am on my soapbox), the IRS knew exactly what they wanted to say. They wanted to say that we preparers can't keep pushing a RAL every two minutes while preparing the tax return. They focused on preparers as if we are snake oil pitchmen and wanted to protect the clients from our harrassing ways.
They definitely did not consider that we frequently get calls in the middle of the night from clients long after the return is prepared saying, "What do I put on line X of the FAFSA form? I have to submit it tonight!!" This is obviously using tax return information for a purpose other than the completion of a tax return, the state return or estimates. This is not a purpose allowed under 301.7216-2 or the code. The client would not have given us signed authorization to help them like this before the return was signed (or at least if we had a form signed, we probably did not foresee this event occurring or we could have given them that information before it was signed). The IRS did not view us as we might view ourselves; wanting to help our clients, but as evil bloodsuckers who want to connive them out of every cent they have. They just made rules with a particular bias and never considered that these did not cover even half the disclosure situations we actually face.
Then we, especially those of us who want to do the right thing, got frantic. Look through the past posts on §7216 here and on other boards and you will see a repeated message that "we can't even tell clients about an IRA" as part of the interview without first getting consent. We were trying to comply with poorly written regulations that never considered that we might be helping our clients. [Actually, that specific example had been changed from the proposed regulations because in the proposed regulations, the use was specifically to sell an IRA. In the final regulations, they took that out to show that "use" was just "use" (neither good use nor bad use) and then later show that sometimes use is allowed under the code and regulations but other times it needs "prior signed consent."]
Yes, we panicked, but the IRS did nothing to help us. They gave us cryptic examples of verbiage that must be used if we wanted to do this or that, and what to do if someone was in a foreign country, and what to do when we had multiple uses or disclosures or both.
Despite all that, they never told us how to avoid the concerns about knowingly or recklessly using or disclosing tax information when a client initiated the request. Their attitude was that a client would only "consent" if we were "requesting permission" but they never stated that nuance in their definitions or interpretation. Their attitude was that if the client requested something, it is a request not consent (even though you or I may consider their signed authorization to be "consent" too). They could not understand how we could possibly confuse a client's request with a client's consent (remember, these are lawyers). They must have had long internal discussions where it was clear what consent meant, but when it came to documenting the rules, they never told us that consent was only in response to a preparer request.
I tell people, that "these are my opinions and there are others who disagree" even though I think I have done enough due diligence to be correct. However, the IRS has never clarified this much further. The IRS believed the example in my FAQ about a preparer's compliance with their E&O policy was a true oversight. However, that has never been clarified either. I am not sure if they are rethinking the whole process or if they are afraid to upset the apple cart again.
Either way, we are left with a jumbled mess and forced to try to understand this stuff by informal discussions on the street corner based on what we heard that someone was told at some seminar at some time rather than any clarification from the IRS.
(off soapbox)
Thanks for listening.Leave a comment:
-
Doug, thank you for sharing your reasoning. I have to admit that I never was successful to get beyond my confusing, what we tax preparers can and cannot do when it comes to disclosure. The only thing I understood was why this is done. All these reasons, like you point out, have to do with us wanting to use and disclose (mainly aimed at overseas tax return preparation and bank products).
I have heard and read interpretations from a variety of knowledge people who all come to the conclusion that we cannot disclose to anyone, period. I wished the IRS would issue some clear guidance.
I agree with you that the format 7216 mandates cannot possibly used for a client request since the tax return was done already. I sure appears that the use of this Disclosure form hinges on the client approval BEFORE the tax return is started.
I still wonder why so many people do interpret these rules they way they do. Are we all just frantic?Leave a comment:
-
It is not a mandate in my state. I have my knowledge mainly from someone how I call an expert in this particular field. It is Bob Jennings, who not only is a CPA and tax return preparer since quite a while, but also has embraced technology from the start and everything he talks about, he has applied in his own office. He used to be a speaker for Gear-up and then started his own business.Gretel,
I have seen this posted many times and while I routinely password protect any client data attached to emails, I have never found the specific rule that states that not doing so would be malpractice. It is not in Circular 230 and not in the 7216 regulations. I did find it mentioned in publication 4557 and 4600, but not specifically stating that not doing so would be malpractice. It is more along the lines of a suggested practice under the heading, "The following checklist includes many activities that can be included in an information security program. It can help you put in place security procedures and controls to protect taxpayer information. It is important to consider all the safeguards that are applicable to your business."
Is that a state mandate in your state?.
Anyone?
Before people get on my case. I realize that not encrypting data could potentially be construed as being reckless in the the scenario where taxpayer information was inadvertently disclosed to a third party. As I understand it, the penalty for that is potentially a criminal charge, not malpractice. The risk of disclosure would also exist for sending a fax to the wrong party. The IRS sends and receives taxpayer information all day long via faxes.
Protection of client data includes encrypted hard drives (I don't have this since I am a sole practioner). Some of these things are common sense and probably not so much written in stone. It didn't take me much imagination to see someone breaking into my business and stealing my computer. Then putting the hard drive into another computer. I am sure I could be sued by clients for not absolutely protecting the computer from unauthorized use.
The netbook I carry around does not have any data on it, only the programs. The data is on a password protected thumb drive. I have tried to implement PGP encryption and failed. I did not know how to solve the issue between backups the way I want to them and the encryption. I also did and cannot spend a fortune to hire someone to implement.
I also do not want to live in fear all the time, so I am risking to have my computer stolen (probably slim chance), and feel comfortable with my solution for the netbook. I also don't have an office where it would be possible to have an interview with a client and not have another client in the waiting area not be able to listen. If a client would like to turn me in for not ensuring enough privacy so be it. After all this is what it boils down to anyway, being turned in. If that happens I will stop doing tax returns.
I think we all have to find our own level of comfort with all these ridiculous rules and requirements. It's all nice and dandy if one has a firm big enough to have a dedicated IT person, most of us are not part of this.Leave a comment:
-
Boy, am I out of my league here.
My understanding is that encrypted email is different from password protecting an attachment. Is Massachusetts really requiring us to send encrypted emails (a la Hushmail) or are they deeming it necessary just to encrypt and protect sensitive attachments.
After these posts I was looking at hushmail and pgp desktop and this looks like a major change in the way we do things. Looks like a learning curve for clients too.
Anyone familiar with this topic and using encrypted email services or products? Any recommendations for a product that is client friendly?
Product from symantic:
Information from wikipedia:
Leave a comment:
-
MA forbids emailed tax information unless encrypted. Probably other states have followed.Leave a comment:
-
Gretel,
I have seen this posted many times and while I routinely password protect any client data attached to emails, I have never found the specific rule that states that not doing so would be malpractice. It is not in Circular 230 and not in the 7216 regulations. I did find it mentioned in publication 4557 and 4600, but not specifically stating that not doing so would be malpractice. It is more along the lines of a suggested practice under the heading, "The following checklist includes many activities that can be included in an information security program. It can help you put in place security procedures and controls to protect taxpayer information. It is important to consider all the safeguards that are applicable to your business."
Is that a state mandate in your state?.
Anyone?
Before people get on my case. I realize that not encrypting data could potentially be construed as being reckless in the the scenario where taxpayer information was inadvertently disclosed to a third party. As I understand it, the penalty for that is potentially a criminal charge, not malpractice. The risk of disclosure would also exist for sending a fax to the wrong party. The IRS sends and receives taxpayer information all day long via faxes.Leave a comment:
-
similar situation
Is there a specific form a client signs to allow the preparer (me) to speak to their former preparer and current preparer of their S-corp return? Prior to 2011 my clients were 50% owners in the S-corp, and are now the 100% owners. I'm trying to find out exactly what he is doing regarding payroll; what the clients are telling me doesn't seem kosher. And they are now my clients because I don't talk down to them like this guy does. They could also benefit greatly from setting up an accountable plan and other tax planning, plus I think they are located in one of the local enterprise zones and may qualify for hiring credits.
Ok, I'm babbling when I should be doing returns....Leave a comment:
-
Thanks, Gretel,Doug, my understanding is that it does not matter if client wants to disclose to third party or tax return preparer wants to send to third party. Any disclosing of tax return information requires the format set in 7216.
Only difference between client's request and tax return preparer's request is, that if tax return preparer wants to use and/or disclose he must get this form signed before starting the tax return.
Like other posters I will require the client to come in and pick up tax return or I will e-mail, password protected. I just learned that it is considered malpractice to e-mail sensitive information or the tax return and to not encrypt.
I have heard this many times before and am interested in learning your reasoning. I will explain mine below.
I would agree that §7216 rules prohibit knowingly or recklessly disclosing or using tax return information. That was in place before the regulations governing these consent forms, but generally did not prevent preparers from complying with such requests.
Regarding the actual regulations, while you could read them to say that the same form is needed when a client requests a disclosure, the continuing theme in the regulations is that the tax preparer is requesting permission to disclose or use and the client is giving consent. For example, here are the timing rules:The sentiment is repeated in the IRS FAQ:(1) No retroactive consent
. A taxpayer must provide written consent before a tax return preparer
discloses or uses the taxpayer’s tax return information.
(2) Time limitations on requesting consent in solicitation context
. A tax return preparer may not request
a taxpayer’s consent to disclose or use tax return information for purposes of solicitation of business
unrelated to tax return preparation after the tax return preparer provides a completed tax return to
the taxpayer for signature.
(3) No requests for consent after an unsuccessful request
. With regard to tax return information for each
income tax return that a tax return preparer prepares, if a taxpayer declines a request for consent to
the disclosure or use of tax return information for purposes of solicitation of business unrelated to tax
return preparation, the tax return preparer may not solicit from the taxpayer another consent for a
purpose substantially similar to that of the rejected request.
(4) No consent to the disclosure of a taxpayer's social security number to a return preparer outside of
the United States with respect to a taxpayer filing a return in the Form 1040 Series.Clearly, these timing rules do not apply to the client, but if we deem "consent" to not only include consenting to disclose at the initiation of the client, then these timing rules would indicate that you can never comply with a client's request to disclose information if you did not know that prior to completing the return.Q8 When and how does a tax return preparer obtain consent to disclose tax return information?
A8 Tax return preparers must obtain consent to disclose tax return information before returns are provided to the
taxpayer for signature and before tax return information is disclosed. The rules for obtaining consents are found in
Treas. Reg. 301.7216-3 and Revenue Procedure 2008-35.
In fact, many preparers do read that into the regulations.
Likewise, the preparer may not know the full reason why the taxpayer is requesting disclosure and would have to pry into the taxpayer's business to comply with including the following information:More reasons why many of us would not want to comply with an actual form compliant with §7216 and the regulations.If a taxpayer consents to a disclosure of tax return information, the consent must identify the
intended purpose of the disclosure. Except as provided in §301.7216-3(a)(3)(iii), if a taxpayer
consents to a disclosure of tax return information, the consent must also identify the specific
recipient (or recipients) of the tax return information. If the taxpayer consents to use of tax
return information, the consent must describe the particular use authorized. For example, if
the tax return preparer intends to use tax return information to generate solicitations for
products or services other than tax return preparation, the consent must identify each
specific type of product or service for which the tax return preparer may solicit use of the tax
return information. Examples of products or services that must be identified include, but are
not limited to, balance due loans, mortgage loans, mutual funds, individual retirement
accounts, and life insurance.
Regarding using the same form, I would dispute that especially for the paragraph that states,If a client is requesting that you perform the service of mailing a tax return, you are making that service contingent on their providing this consent. However, if you follow the requirements of the IRS for their consent rules and use the same form, you must include this paragraph.You are not required to complete this form. If we obtain your signature on this form by conditioning our services on
your consent, your consent will not be valid. If you agree to the disclosure of your tax return information, your
consent is valid for the amount of time that you specify. If you do not specify the duration of your consent, your
consent is valid for one year.
If you read through the IRS procedures, the repeatedly give examples where "consent is sought" by the tax preparer as opposed to "disclosure is requested by the taxpayer." I spent a lot of time considering these anomalies and whether they were the only situations where these specific requirements apply or whether they were merely a small subset of the situations.
I contacted the Office of the Associate Chief Counsel with my concerns and documented these in a FAQ that they reviewed before I published it. That FAQ is here:
While I can understand from the apparent logical timing contradictions why some practitioners believe that clients cannot allow disclosure of any information that they did not request prior to signing the return, I have difficulty understaning your perspective.
I realize that the rules are complicated and poorly written regardless of what they actually mean, but the clear message I got form the Office of the Associate Chief Counsel was that they were trying to regulate preparer requests to allow disclosure, not client requests to do anything. Their attitude was that a client approaching you to mail a copy of a tax return is different from a client coming to you to prepare a tax return. They were trying to control what you could do as part of a tax preparation engagement as opposed to a file retrieval/copying/printing/mailing/faxing engagement. In the latter, a client could sign a dozen consent forms, but you are not obligated to comply with their request. In my opinion, client requests are not time limited as are preparer requests and the §7216 forms are invalid if used for a tax return that is already completed.Last edited by dtlee; 10-10-2011, 11:45 PM.Leave a comment:
-
Doug, my understanding is that it does not matter if client wants to disclose to third party or tax return preparer wants to send to third party. Any disclosing of tax return information requires the format set in 7216.There is no specific form required by the IRS for this scenario.
I agree with jimmcg that you define the policy in this situation. Due diligence is required to avoid knowingly and recklessly disclosing information to others without prior client consent. Hence, it is easier if you just give the information to the client.
If you do decide to accommodate the client request, you need to be careful. If you mail out the returns, you could recklessly put the wrong label on the envelope. You also need to confirm (and document in your files how you did this) that this was a valid request from your client and not some form of identity theft. You should also somehow confirm any address they give you with the intended recipient (and again document how you did this) so that you don't simply rely on information from the client.
You could create a form based on the forms you use for §7216 disclosure, but they cannot be the same forms and do not require the specific IRS wording (like the part about it being optional and how to turn you in to TIGTA) since those are only valid for scenarios where you are requesting pemission to disclose client information.
Only difference between client's request and tax return preparer's request is, that if tax return preparer wants to use and/or disclose he must get this form signed before starting the tax return.
Like other posters I will require the client to come in and pick up tax return or I will e-mail, password protected. I just learned that it is considered malpractice to e-mail sensitive information or the tax return and to not encrypt.Leave a comment:
-
This is my favorite way of doing it cause then the client can just forward it to whomever they please.
If email isn't possible....then this is exactly what I do...between the two, it pretty much covers 100% of the scenarios I get for requests.Mine also. I just say you have to come and get it and take it to the bank, lender, etc. They don't seem to question it unless they are out-of-state. In that case I can fax it to them. One time a client was at a bank and said I could fax it there. I made the person and my client promise me that my client would stand by the fax machinie and it would go to his hands first. Do you think that would hold up in court? (Rhetorical).Leave a comment:
-
Mine also. I just say you have to come and get it and take it to the bank, lender, etc. They don't seem to question it unless they are out-of-state. In that case I can fax it to them. One time a client was at a bank and said I could fax it there. I made the person and my client promise me that my client would stand by the fax machine and it would go to his hands first. Do you think that would hold up in court? (Rhetorical).Last edited by JG EA; 10-08-2011, 05:43 PM.Leave a comment:
-
Email the copies to the client. Then he/she can be responsible for sending them on. But, the client needs to understand that the email is not secure and encrypted. (unless you can do that).Leave a comment:
Disclaimer
Collapse
This message board allows participants to freely exchange ideas and opinions on areas concerning taxes. The comments posted are the opinions of participants and not that of Tax Materials, Inc. We make no claim as to the accuracy of the information and will not be held liable for any damages caused by using such information. Tax Materials, Inc. reserves the right to delete or modify inappropriate postings.
Leave a comment: