Skip to content

Section 4. Incident Management Program

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

10.5.4 Incident Management Program

Manual Transmittal

Purpose

(1) This transmits revised IRM 10.5.4, Privacy and Information Protection, Incident Management Program.

Exceptions & meaning →

Material Changes

(1) IRM 10.5.4.1, Program Scope and Objectives - In (3), updated the "Office of the Deputy Commissioner for Operations Support (OS)" to "Chief Operating Officer (COO)" .

(2) IRM 10.5.4.1.3, Responsibilities - In (1), updated the "Office of the Deputy Commissioner for Operations Support (OS)" to "Chief Operating Officer (COO)" ; in (2), updated Cybersecurity’s Safeguarding Personally Identifiable Information Data Extracts (SPIIDE) application to the Cybersecurity Information Protection Enhancement Controls (CIPEC) application; in (2)a) third bullet, updated "SPIIDE" to "CIPEC" ; and in (3) b) Table, added verbiage in the Then column to clarify the examples.

(3) IRM 10.5.4.1.4, Program Management and Review - In (2)a), last sentence, added "CIPEC" (formerly "SPIIDE" ); spelled out "Unauthorized Access" for "UNAX" ; and added "Unauthorized Disclosure (UNAD)" .

(4) IRM 10.5.4.1.6, Terms - Added OMB Circular No. A-130 in (6) as an additional source for the definition of "personally identifiable information (PII)" and in (9) added the Cybersecurity Information Protection Enhancement Controls (CIPEC) application which replaced "SPIIDE" .

(5) IRM 10.5.4.1.7, Acronyms - Added "CIPEC" , "OFDP" , "TCS" , "TS" , "UNAX" , and "UNAD" to the acronym list.

(6) IRM 10.5.4.1.8, Related Resources - Added new (3) with a link to the OMB Circulars and new (3)a) listing OMB Circular No. A-130 as a resource. Subsequent paragraphs after new (3) renumbered.

(7) IRM 10.5.4.3, Reporting Losses, Thefts and Disclosures - In (1), added an additional Note about incidents involving Classified National Security Information (CNSI) and a reference to IRM 10.9.1, Classified National Security Information (CNSI), as requested by FMSS.

(8) IRM 10.5.4.3.2, Intentional Unauthorized Access (UNAX) and Disclosure (UNAD) of Tax Information - Updated the title from "Intentional Unauthorized Disclosures of Tax Information" to "Intentional Unauthorized Access (UNAX) and Disclosure (UNAD) of Tax Information" to clarify that the subsection pertains to "intentional unauthorized accesses" as well as "intentional unauthorized disclosures" ; added the word "accesses" to the first sentence of the paragraph; clarified that the procedures in this subsection apply to current, as well as former, IRS employees and contractors; deleted the citation to IRM 11.3.38.5 and added a citation to IRM 10.5.5, Privacy and Information Protection, Unauthorized Access, Attempted Access or Inspection of Taxpayer Records (UNAX) Program Policy, Guidance and Requirements.

(9) IRM 10.5.4.3.3, Inadvertent Unauthorized Disclosures and Losses or Thefts of IT Assets, BYOD Assets and Hardcopy Records/Documents - At the end of (2)a), added the following additional criteria which require reporting to PGLD/IM: "or SBU data, including PII and tax information, shared with, or input or uploaded to, Artificial Intelligence (AI) or other internet tools or sites used for translation, document conversion, etc." ; added a new Note to (2)a) and IRM references as a reminder to employees of the procedures to follow when a call about erroneous taxpayer correspondence is received; added the PII Breach Reporting Form Guide (PDF) and its’ location as an additional resource to the existing Note in (2)a) (now the second Note); in the third Note in (2)a), clarified the reporting requirement to SPDER; deleted the reference to "legacy ID cards" in (2)b) as the term is no longer valid; and in (5)a), updated the United States Computer Emergency Readiness Team (US-CERT) to the Cybersecurity and Infrastructure Security Agency (CISA).

(10) IRM 10.5.4.4, PGLD/Incident Management Intake, Risk Assessment, Mitigation, and Notification - Subsection re-titled from "PGLD/Incident Management Intake, Risk Assessment and Notification" to "PGLD/Incident Management Intake, Risk Assessment, Mitigation, and Notification" .

(11) IRM 10.5.4.4.1, PGLD/Incident Management Intake - In (1)c), deleted the reference to "legacy ID cards" as the term is no longer valid; in (3), added an example of the additional information that PGLD/IM may request in order to fully assess the data breach to complete the risk assessment, and in (3) Note, added a reminder that the reporting employee/POC must retain the SSNs/EINs of the potentially impacted individuals until they are sent to PGLD/IM.

(12) IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation - Subsection retitled from "PGLD/Incident Management Risk Assessment" to "PGLD/Incident Management Risk Assessment and Mitigation" . In (1), added a Note stating: "Data breaches associated with a business are not automatically categorized as low risk. All data breaches, including those that involve businesses, are unique, and when making determinations, all facts and circumstances must be considered." In (2), clarified the risk assessment codes and added information about the risk assessment color categories. In (3), added information about the factor ratings and the categorization or classification of the data breach. In (4)a), added a Note about information related to businesses. In (6), added information about the factor rating points. In (7), added a Note stating that notification can only be accomplished if the reporting employee/POC is able to provide the SSNs of the potentially impacted individuals.

(13) IRM 10.5.4.4.6, PGLD/Incident Management Data Breach Notification - Letter 4281C - Added new (1), (2), and (3) to address data breach notification rules for individuals and businesses and a new (3) Note about businesses and what is considered "public information" . Subsequent paragraphs after new (3) renumbered. In (5), added "and businesses" to the sentence and a new (5) Note stating that notification can only be accomplished if the reporting employee/POC is able to provide the SSNs/EINs of the potentially impacted individuals/businesses. In (6), added new verbiage concerning the addition of History Items to CC ENMOD for individuals who have been sent a data breach notification letter (only if the account is on the Master File (MF)). Added a new (7) concerning notifying potentially impacted businesses of an IRS data breach and the addition of History Items to CC ENMOD to alert anyone looking at the account that business information has been exposed and to add a heightened awareness of any unusual activity. Subsequent paragraph renumbered. In (8), added a Note stating that the need for transparency must be balanced with concerns about over-notifying individuals.

(14) IRM 10.5.4.4.6.1, Contents of the Data Breach Notification Letter - Added new (3) stating that Letter 4281C with specialized (open) paragraphs may be used for data breaches where, based on the risk assessment, it appears the individual isn’t likely to be at risk of identity theft, but is likely to be subject to other risk of harm. Added new (4) stating that Letter 4281C with specialized (open) paragraphs may also be used for data breaches involving businesses where there is a potential risk of harm and notification is recommended. Added new (5) stating that generally, individuals potentially impacted by data breaches caused by IRS employees and contractors will be notified of the data breach and offered identity protection/identity monitoring unless the facts and circumstances of the data breach do not warrant notification. Added new (6) stating that generally, individuals potentially impacted by intentional unauthorized accesses or disclosures (UNAX/UNAD) caused by IRS employees and contractors which results in proposed disciplinary or adverse action will be notified of the data breach and offered identity protection/identity monitoring unless the facts and circumstances of the data breach do not warrant notification. Added new (7), stating that generally, individuals potentially impacted by IRS data breaches will not be notified of the data breach if the data breach occurred 36 months or more before being reported to PGLD/IM unless the facts and circumstances warrant notification, e.g., if the PII was targeted. Subsequent paragraph renumbered.

(15) IRM 10.5.4.4.6.2, Data Breach Notification Signature - Added "or designee" to the end of (1).

(16) IRM 10.5.4.4.6.3, Timeliness of the Data Breach Notification - In (1), added "(and businesses as necessary)" and to the end of (1) Note, added "or businesses" .

(17) IRM 10.5.4.4.6.4, Means of Providing Data Breach Notifications - In (1), added "(or business’)" after "individuals" and in (2) and (3)d), added "(or businesses) " after "individuals" .

(18) IRM 10.5.4.4.7, Ongoing Support - In (1), first sentence, and (2) second sentence, added "and businesses" and in (1)c), added "or business’" .

(19) IRM 10.5.4.4.7.1, Handling Inquiries About IM Data Breach Notification Letters - In (2) and (3), added "business" or "businesses" where necessary.

(20) IRM 10.5.4.4.7.2, IMF Identity Check - AM IDT Toll-Free (App 161/162) Telephone Overview - In (2) and (4), added a reference to IRM 10.10.3, Centralized Authentication Policy – Centralizing Identity Proofing for Authentication Across All IRS Channels. Re-worded (4) for clarity and added a new a) and b) with information previously located in (4). Added a new (4) Note stating that the Breach Number and Breach Date can be found on CC ENMOD in the History Item section including specifics as to how they will appear on CC ENMOD.

(21) IRM 10.5.4.4.7.3, BMF Identity Check - AM IDT Toll-Free (App 161/162) Telephone Overview - In (1) and (2), added a reference to IRM 10.10.3, Centralized Authentication Policy – Centralizing Identity Proofing for Authentication Across All IRS Channels. Re-worded (2) for consistency and added a new a) and b) with information previously located in the bullets. Added a new Note in (2)b) stating that the Breach Number and Breach Date can be found on CC ENMOD in the History Item section including specifics as to how they will appear on CC ENMOD.

(22) IRM 10.5.4.4.7.9, Undelivered Letter 4281C - Added a new Note to (3) to explain Classified Waste and moved the old Note regarding POAs to new (4).

(23) IRM 10.5.4.5.1, IRS Data Breach Tracking Indicator - Development and Implementation - Added new (2) stating that the IRS data breach tracking indicator allows the IRS to track the number of individuals who may experience identity theft as a result of IRS data breaches. It also allows for tracking and analysis in order to identify how an IRS data breach impacts individuals and tax administration. Added new (3) stating that the presence of an IRS data breach tracking indicator on an account alerts IRS customer facing staff/CSRs that the individual is potentially impacted by an IRS data breach.

(24) IRM 10.5.4.5.1.1, Applying the IRS Data Breach Tracking Indicator to IRS Data Breaches - Added a Note to (2)b) stating the Get Transcript Online (GTO) application was decommissioned in December, 2024.

(25) Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms - Added terms and definitions for the following Potential Levels of Risk: No Impact, Low Impact, Moderate Impact, and High Impact; deleted the last term in the Exhibit, "US-CERT" , and added "CISA" ; added the term "CIPEC" ; updated the definition of federal tax information (FTI) to match Exhibit 10.5.1-1, Glossary and Acronyms; updated the definition of Form 14164, Personally Identifiable Information (PII) Analysis, and Form 14164-A, Personally Identifiable Information (PII) Breach Reporting, to include "or SBU data, including PII and tax information, shared with, or input or uploaded to, Artificial Intelligence (AI) or other internet tools or sites used for translation, document conversion, etc." ; added terms and definitions for "Hardcopy" and "Sensitive Information" from Exhibit 10.5.1-1, Glossary and Acronyms; added terms and definitions for the four Risk Assessment Codes (Red, Green, Blue and Orange); added the term and definition for "Routine" Data Breach; added OMB Circular No. A-130 in the definition of "Personally Identifiable Information (PII)" as an additional source for the definition of PII; and added a definition for "Classified Waste" .

(26) Throughout, made editorial changes to add clarity where necessary; deleted references to "BlackBerry" as the "BlackBerry" is a discontinued brand of smartphones; reviewed and updated links and citations, website addresses, legal references and IRM references as necessary; corrected capitalization, spelling, typos, grammar, and "Terms of Art" as necessary; incorporated plain language writing techniques; updated references to "Wage and Investment" , "Wage & Investment" and "W&I" to "Taxpayer Services" or "TS" as appropriate; updated "Office of Taxpayer Correspondence (OTC)" to "Taxpayer Correspondence Services (TCS)" ; updated "TSSSOC" to "TSOC" as per Treasury’s Departmental Incident Response Plan (IRP) (dated October 2024); removed all internal and external naked links (links that expose a URL/web address of a page or website) as per the August 28, 2024 IMD News & Updates, Updating Naked Links in IRMs; updated broken whitehouse.gov links as per SPDER’s direction; and updated content related to gender neutrality to comply with the January 2025 Executive Orders and OPM guidance.

Exceptions & meaning →

Effect on Other Documents

Audience

Effective Date

Thomas E. Burger Director, Privacy Policy and Compliance Privacy, Governmental Liaison and Disclosure

Exceptions & meaning →

Program Scope and Objectives

Purpose. This IRM provides procedural guidance for reporting IRS data losses, thefts, and inadvertent unauthorized disclosures involving sensitive but unclassified (SBU) data, including personally identifiable information (PII) and tax information.

Audience. The provisions in this manual apply Servicewide whenever SBU data, including PII and tax information, is collected, created, transmitted, used, processed, stored, or disposed of, in support of the IRS mission. This manual also applies to individuals and organizations having contractual arrangements with the IRS, including contractors, subcontractors, vendors, Volunteer Income Tax Assistance/Tax Counseling for the Elderly volunteers, and any other outsourced providers doing business with the IRS. This manual also applies to all flexiplace (telework) employees (frequent, recurring and ad hoc) as well as mobile employees.

All IRS employees, contractors/vendors, and persons with authorized access to SBU data, including PII and tax information, are responsible and accountable for complying with federal and IRS privacy, information protection, and data security, policies and procedures. Safeguarding and preventing the unauthorized disclosure of SBU data, including PII and tax information, is a responsibility that is shared by all IRS employees, contractors/vendors, and persons with authorized access to SBU data, including PII and tax information. Lost, stolen, or disclosed SBU data, including PII and tax information, may be used to perpetrate identity theft or other forms of harm, if the information falls into unauthorized hands. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm.

All tax, privacy, and security clauses must be included in contracts as required by IRM 11.3.24, Disclosure of Official Information, Disclosures to Contractors, and IRM 10.5.6.2, Privacy Act General Provisions. Contractor employees must be trained about SBU data protection requirements, including PII and tax information, as required in Treasury Regulation 301.6103(n)-1(d).

IRS Acquisition Policy (IRSAP) Part 1004, Administrative Matters, and IRSAP Part 1024, Protection of Privacy and Freedom of Information, provide instructions with respect to procedures to be followed where contractual procurement will be subject to the Privacy Act, the provisions of IRC 6103(n), or where access by a contractor to sensitive but unclassified material is contemplated.

For additional information about security controls, see IRM 10.8.1, Information Technology (IT) Security, Policy and Guidance, and Pub 4812, Contractor Security and Privacy Controls.

Policy Owner. The Privacy Policy and Compliance (PPC) Director is responsible for the policy in this IRM. PPC is under the Office of Privacy, Governmental Liaison and Disclosure (PGLD), which is under the Chief Operating Officer (COO).

Program Owner. The Incident Management Office under PPC is the program office responsible for this IRM.

Primary Stakeholders. All employees and contractors of the IRS, in all divisions and functional units, including flexiplace (telework) employees (frequent, recurring and ad hoc) and mobile employees, are affected by the procedures in this IRM.

Contact Information. To recommend changes to this IRM section, email the *PII mailbox.

Exceptions & meaning →

Background

Overview. This IRM defines the mission, objectives, and governance structure of the Privacy Policy and Compliance Incident Management Program. It provides the organizational framework for carrying out specific policies and procedures aimed at timely reaction and appropriate responses to occurrences of IRS data losses, thefts, and inadvertent unauthorized disclosures involving SBU data, including PII and tax information.

Privacy, Governmental Liaison and Disclosure (PGLD). PGLD, previously known as Privacy, Information Protection and Data Security (PIPDS), is responsible for ensuring consistency in all processes and procedures affecting the ways the IRS handles privacy information protected by statute, regulation, Executive Order, or internal policy.

PGLD works with other business units to provide the IRS with the tools and resources necessary to protect sensitive taxpayer and employee data from potential identity theft due to IRS incidents involving the loss or theft of IRS IT assets and Bring Your Own Device (BYOD) assets containing SBU data, including PII and tax information; the loss or theft of physical and electronic documents that include SBU data, including PII and tax information; and inadvertent unauthorized disclosures of SBU data, including PII and tax information.

PGLD also leads IRS privacy and records policies, coordinates privacy protection guidance and activities, responds to privacy complaints, and promotes data protection awareness throughout the IRS.

PGLD Incident Management (IM) Office. IM was established to ensure Servicewide implementation of federal directives to protect taxpayers and government employees against IRS data losses and misuse of sensitive personal data.

Since September 2007, the IM Office (previously known as the ITIM Office) in PGLD (previously known as PIPDS) has been responsible for administering and managing IRS program requirements by ensuring IRS incidents involving the loss or theft of IRS IT assets and BYOD assets containing SBU data, including PII and tax information; the loss or theft of physical and electronic documents that include SBU data, including PII and tax information; and inadvertent unauthorized disclosures of SBU data, including PII and tax information, are investigated, analyzed and resolved by PGLD/IM.

IM is dedicated to assisting taxpayers and government employees potentially impacted by IRS incidents involving SBU data, including PII and tax information, by working quickly and thoroughly to investigate the incidents to decrease the possibility that the information will be compromised and used to perpetrate identity theft or other forms of harm. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm.

IM manages the reporting, risk assessment, and tracking of IRS incidents involving SBU data, including PII and tax information, as well as notification to potentially impacted individuals.

Exceptions & meaning →

Note:

IM isn’t responsible for any disciplinary actions that can result from an employee’s or manager’s failure to protect IT equipment or information, employee data, SBU data, or PII, nor is IM responsible for contacting Labor Relations regarding a manager’s or employee’s failure to protect IT equipment or information, employee data, SBU data, or PII.

Exceptions & meaning →

Authority

Federal agencies have been instructed by the Office of Management and Budget (OMB) and the Department of the Treasury to address the increasing occurrence of identity theft and to safeguard personally identifiable information (PII).

Executive Order 13402, May 10, 2006, established the President’s Identity Theft Task Force. The Task Force recommended that Federal agencies reduce the incidence and impact of identity theft and improve their capacity to respond to data breaches. The Task Force recognized that any comprehensive information security program - whether in the public or private sector - must include policies for responding to a data breach. Although every breach is different, experience has shown that having policies in place in advance is critical to ensuring a proper response. Such policies must address whether, how, and when to inform potentially impacted individuals of the loss of their data, and whether to offer services such as free credit monitoring to those individuals. The Task Force developed guidance that OMB issued to all agencies and departments on September 20, 2006, on responding to data breaches that pose a risk of identity theft. The guidance provided agencies with a framework for conducting an analysis of the breach to determine whether the breach posed a significant risk of identity theft and offered practical advice on implementing a breach response plan, including how and when to provide notice to potentially impacted individuals. To further the goals of the Task Force guidance, in May 2007, OMB issued Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, which emphasized agencies’ responsibilities under existing laws, such as the Privacy Act of 1974, to safeguard PII, and instructed Federal agencies to enhance their safeguards for PII and to enact data breach handling and data breach notification policies. The President’s Identity Theft Task Force Report of September 2008, documented the Task Force’s efforts to implement the Strategic Plan’s recommendations.

In January 2017, OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, rescinded and replaced OMB Memorandum M-07-16, updated existing OMB data breach notification policies and guidelines in accordance with the Federal Information Security Modernization Act of 2014 (FISMA), and implemented recommendations included in OMB Memorandum M-16-04, Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government.

See IRM 10.5.4.1.8, Related Resources, for a list of other relevant OMB Memoranda, Federal Guidance, and IRMs, and details about where to locate them.

The Incident Management Program was created in response to OMB directives and the President's Identity Theft Task Force recommendations, and to ensure IRS compliance with OMB requirements for data breach management and data breach notification. Consistent with the OMB directives, the IRS notifies potentially impacted individuals when the data breach risk assessment results in a likelihood of harm to the potentially impacted individuals. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm.

Exceptions & meaning →

Responsibilities

Incident Management Program Oversight. The Privacy Policy and Compliance (PPC) Director is the executive responsible for oversight of this program. PPC is under PGLD, which is under the Chief Operating Officer (COO). The Incident Management and Employee Protection (IMEP) Associate Director reports to the PPC Director, and oversees the IMEP program.

Incident Management Program. The Incident Management Program includes the management of the IRS data breach reporting process, as well as the risk assessment and tracking of IRS data breaches and notification to individuals potentially impacted by IRS data breaches. The Incident Management Program also includes output from the Cybersecurity Information Protection Enhancement Controls (CIPEC) application (formerly Safeguarding Personally Identifiable Information Data Extracts (SPIIDE). IM receives events for investigation, addresses applicable receipts within established procedures, and collaborates on referred events not meeting IM’s criterion.

IM has the following responsibilities related to administering the Incident Management Program in the IRS:

Interpreting federal laws, regulations, and policies relating to the protection of personally identifiable information (PII). See IRM 11.3.1, Disclosure of Official Information, Introduction to Disclosure, for more information about the Disclosure program and the protection of official information including personal information and tax records.

Coordinating with other program areas in the IRS to ensure compliance with OMB Memorandum M-17-12 and related directives.

Receiving CIPEC (formerly SPIIDE) events for investigation and addressing accordingly when received.

Conducting risk assessments of IRS data breaches and determining how to best mitigate the identified risks, such as providing identity protection/identity monitoring services, or offering guidance on how the potentially impacted individuals can mitigate their own risk of harm, such as setting up fraud alerts or credit freezes, changing or closing accounts, etc.

Analyzing and tracking IRS data breaches reported to the IM office as well as contacting the BU data owner or reporting employee/point of contact (POC) for additional information concerning the incident or data breach.

Notifying potentially impacted individuals (if the data breach risk assessment results in a likelihood of harm, such as the potential for identity theft).

Reporting weekly to the Records and Information Management (RIM) Program Office any incidents of lost, stolen, or destroyed records.

Identifying risks associated with IRS data breaches and collaborating with the BU data owner on mitigating the risks.

Preparing all reporting documentation pertaining to IRS data breaches.

Making notification recommendations about potentially impacted individuals based on assessed risk and consulting with appropriate law enforcement officials and other offices or authorities if necessary.

Identifying emerging trends and developing appropriate strategies and responses.

Improving procedures to reduce the occurrence of IRS incidents and data breaches.

Developing, defining, monitoring, and executing IM policies and procedures.

Overseeing the maintenance, publication, and conveyance of the Privacy and Information Protection Incident Management IRM.

Communicating and coordinating with internal stakeholders to ensure consistency about data breach policy and issues.

Exceptions & meaning →

Note:

IM isn’t responsible for any disciplinary actions that can result from an employee’s or manager’s failure to protect IT equipment or information, employee data, SBU data, or PII, nor is IM responsible for contacting Labor Relations regarding a manager’s or employee’s failure to protect IT equipment or information, employee data, SBU data, or PII.

Reporting Employees/Point of Contact (POC) and Business Unit (BU) Data Owners. In addition to timely reporting (immediately upon discovery) so PGLD/IM can begin its risk assessment process, reporting employees/POCs and/or BU data owners have other responsibilities such as containment, mitigation, prevention, providing information requested by PGLD/IM within two business days of request, taking disciplinary actions, and contacting potentially impacted individuals to request replacement documents. See a) thru f) below for a description of the reporting employee/POC and/or BU data owner responsibilities. Also see IRM 10.5.4.3.1, Timely Reporting: Immediately Upon Discovery, for additional information about timely reporting.

Containment. The BU data owner must take immediate action to contain the incident or data breach to prevent any further PII exposure, e.g., if employee or taxpayer data is inadvertently exposed on the internet, the BU data owner must immediately take steps to remove the data and/or close the access; or, if DVDs have been shared with material that should have been redacted, the BU must take steps to immediately recover them and request the recipient remove public access (if the information was made publicly available) and replace it with the proper data. The BU must contact Cybersecurity’s Online Fraud Detection and Prevention Office if assistance is required to contain a data breach involving an electronic transmission such as email or a data breach involving the posting of information on the internet. Additional actions related to containment will depend on the nature of the breach and may involve other BUs as needed.

Exceptions & meaning →

Note:

If the employee reporting the data breach is not the BU data owner, the reporting employee/POC must collaborate with the BU and PGLD/IM to determine the best approach for managing containment.

Exceptions & meaning →

Note:

The BU data owner will ensure PGLD/IM is apprised of any containment actions taken. PGLD/IM will document the containment actions taken by the BU on e-Trak.

Mitigation. The reporting employee/POC and/or BU data owner must analyze the event circumstances to mitigate or lessen the impact of the incident or data breach. Necessary actions by the reporting employee/POC may include requesting the person who erroneously received a notice, letter, or transcript, to return or destroy it; asking the incorrect recipient of a fax, EEFax, email, etc., to destroy or delete it; or asking the person who received an erroneously addressed or misdelivered shipment to secure the shipment and await collection by an IRS employee. Necessary actions by the BU may also include physically recovering hardcopy documents or coordinating with TIGTA to ensure all recovery options are considered.

If

Then

If a notice, letter, or transcript is sent in error to the wrong person and not the last known address of record, or multiple correspondence for different taxpayers are included in one envelope

The reporting employee/POC must ask the person who incorrectly received the notice, letter, or transcript to return the document to the IRS in a sealed envelope with Not at this address and Return to Sender written on the envelope. If the person refuses to return the document, ask him or her to destroy it. See IRM 21.3.1.2.1 , Erroneous Correspondence Procedures, and IRM 21.1.3.2.2 , Authorized and Unauthorized Disclosures.

If a fax, EEFax, email, or other electronic transmission is sent to the wrong addressee

The reporting employee/POC must ask the person who incorrectly received the fax, EEFax, email, or other electronic transmission, to delete it, or destroy it (if printed).

If a shipment is erroneously addressed or misdelivered, and the recipient contacts the IRS regarding the erroneously received shipment

The reporting employee/POC or BU data owner must ask the person who received the erroneously addressed or misdelivered shipment to secure the shipment and await collection by an IRS employee. The BU data owner must also take steps to recover the shipment or hardcopy documents or coordinate with TIGTA to ensure all recovery options are considered.

Exceptions & meaning →

Note:

The BU data owner must ensure PGLD/IM is apprised of any mitigation actions taken. PGLD/IM will document the mitigation actions taken by the BU on e-Trak.

Prevention. The BU data owner must determine the necessary steps to prevent similar incidents or data breaches in the future. This could entail investigating the cause of the incident or data breach and developing a prevention plan if necessary. A prevention plan may include a security audit of both physical and technical security, a review and/or development of policies and procedures, and a review of employee training.

Exceptions & meaning →

Note:

The BU data owner must ensure PGLD/IM is apprised of any prevention actions taken. PGLD/IM will document the prevention actions taken by the BU on e-Trak.

Providing Requested Information. The reporting employee/POC or BU data owner must provide all information requested by PGLD/IM, e.g., complete, unredacted SSNs, names, dates, etc., within two business days of request to ensure timely reporting and taxpayer notification. If a delay is likely, the reporting employee/POC or BU data owner must contact IM at 267-466-0777 to facilitate next steps.

Exceptions & meaning →

Note:

If the unredacted (not truncated) SSNs for the potentially impacted individuals involved in the data breach are not readily available, the reporting employee/POC or BU data owner must research to determine the complete SSNs. After due diligence, if the unredacted SSNs for the potentially impacted individuals cannot be determined, the reporting employee/POC or BU data owner must email the *PII mailbox or contact IM at 267-466-0777.

Disciplinary Actions. Discipline can result for failure to protect equipment or information, as well as for a manager’s failure to supervise and train as it pertains to PII information. A BU data owner whose employee experiences a data loss, theft, or disclosure, or asset loss or theft, because the employee did not properly safeguard the data or asset, must contact the servicing Labor Relations Specialist to discuss the appropriateness of any disciplinary action. For disciplinary actions related to losses or thefts of laptops or other electronic devices, or the loss, theft or disclosure of SBU data, including PII and tax information, and improperly safeguarding electronic or paper records, see Document 11500, IRS Manager’s Guide to Penalty Determinations, and IRM 6.751.1, Discipline and Disciplinary Actions: Policies, Responsibilities, Authorities, and Guidance.

Exceptions & meaning →

Note:

PGLD/IM isn’t responsible for any disciplinary actions that can result from an employee’s or manager’s failure to protect IT equipment or information, employee data, SBU data, or PII, nor is IM responsible for contacting Labor Relations regarding a manager’s or employee’s failure to protect IT equipment or information, employee data, SBU data, or PII.

Contacting Potentially Impacted Individuals to Request Replacement Documents. Although PGLD/IM notifies the potentially impacted individuals of an IRS data breach if it’s determined there’s a potential risk of harm to the individuals as a result of the data breach (such as the potential for identity theft), the reporting employee/POC and/or BU data owner is responsible for contacting the potentially impacted individuals if an original document, or remittance (such as a personal check), was lost, stolen, or destroyed, to explain that the original document or remittance was lost, stolen, or destroyed, and to request that the individual resend the document or remittance. Established functional taxpayer contact processes must be followed when requesting replacement documents or remittances from the potentially impacted individuals. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm.

Exceptions & meaning →

Note:

In addition to requesting replacement documents or remittances, contact with the potentially impacted individuals may include a brief, general explanation of the data breach, e.g., "a package containing your document (or remittance) was lost in shipment." If the reporting employee/POC, and/or the BU data owner, has any questions about contacting the potentially impacted individuals about the data breach, the BU data owner may call PGLD/IM at 267-466-0777 or email the *PII mailbox. Do not share the telephone number or mailbox address with the potentially impacted individuals.

Breach Response Team (BRT). In the event you or your business unit is called upon to participate as part of a Breach Response Team (BRT), there are specific activities you may be required to conduct based on your specific business unit and/or role in the organization. See the High-Risk Data Breach Quick Reference Guide listed in the Other Related Resources section of the Report Losses, Thefts or Disclosures page in the Disclosure and Privacy Knowledge Base Site and Document 13347, Data Breach Response Playbook, for additional information on the activities you may be required to conduct. Also see IRM 10.5.4.4.2, High-Risk Data Breaches, for additional information concerning high-risk data breaches.

For the definition of Reporting Employee/Point of Contact (POC) and business unit (BU) Data Owner, see IRM 10.5.4.1.6, Terms, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms.

Exceptions & meaning →

Program Management and Review

PGLD/IM has established Business and Organizational measures to measure the timeliness of IRS data breach notifications to potentially impacted individuals of IRS data breaches. See IRM 10.5.4.4.6.3, Timeliness of the Data Breach Notification.

PGLD/IM provides reports on Business Performance as it relates to IRS data breaches to Points of Contact within each business unit. The reports can be used by PGLD/IM as well as the BUs to identify trends as well as training and outreach opportunities.

Quarterly Scorecard Report. The Quarterly Scorecard Reports (in PDF format) list the number of reported data breaches received by PGLD/IM per quarter per Business Operating Division (BOD). The Reports, which are shared with each respective BOD, provide an analysis of all reported data breaches identified as a loss, theft, or inadvertent unauthorized disclosure based on the type of asset, location, and risk assessment code. The Quarterly Scorecard Report is also shared with the Privacy Compliance office in PGLD to determine if there are any processes for which a Business PII Risk Assessment (BPRA) can be performed. The BPRA is used to identify vulnerabilities and make recommendations for changes to improve IRS security and privacy policies and practices. A separate Quarterly Scorecard Report capturing the performance of the IRS overall is also provided to each BOD. The IRS Quarterly Scorecard Report provides an analysis of all reported data breaches identified as a loss, theft, or inadvertent unauthorized disclosure as well as those identified as other, such as Private Debt, CIPEC (formerly SPIIDE), Unauthorized Access (UNAX)/Unauthorized Disclosure (UNAD), etc.

Quarterly E-Trak Data Extract Report. The e-Trak Data Extract Reports (in Excel format), which list the losses, thefts, and inadvertent unauthorized disclosures reported to PGLD/IM per BOD, is usually provided quarterly but can be provided more frequently (such as monthly) upon request by the BOD. The extract provides an analysis of all reported data breaches identified as a loss, theft, or inadvertent unauthorized disclosure based on the type of asset, location, reporting employee/POC, and risk assessment code.

Weekly Code Red Recommendations Reports. The Code Red Recommendations Report lists data breaches potentially impacting individuals likely to be at risk of identity theft or other harm due to the loss, theft, or disclosure of PII. The Report is presented to the PII Working Group weekly by PGLD/IM for information only; no concurrence or approval by the PII Working Group (PIIWG) is required.

Exceptions & meaning →

Program Controls

Program controls developed to oversee the Incident Management Program include the following:

PGLD/IM conducts quarterly Operational Reviews to evaluate key performance measures to ensure agency program requirements are met.

PGLD/IM uses established Business and Organizational measures to measure the timeliness of IRS data breach notifications.

PGLD/IM uses the Quarterly Scorecard Report which contains information from e-Trak (a web interface for case tracking) to assess business unit and IRS performance.

PGLD/IM reconciles redeemed identity protection/identity monitoring codes monthly to ensure the codes assigned to potentially impacted individuals via Letter 4281C were redeemed by the individuals to whom they were assigned before the monthly invoice is paid.

PGLD/IM generates a Code Red Recommendations Report weekly listing the data breaches deemed to be Code Red (data breaches requiring notifications) to notify the PPC Director and the IMEP Associate Director of the data breaches pending notification.

PGLD/IM reviews all PII Breach Reporting Forms and alerts the Records and Information Management (RIM) Program Office if official records have been reported as lost, stolen, or destroyed on the PII Breach Reporting Form in accordance with IRM 1.15.3.4, Unauthorized Disposition of Records, and 36 CFR 1230, Unlawful or Accidental Removal, Defacing, Alteration, or Destruction of Records.

Exceptions & meaning →

Terms

Incident. OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, defines an incident as an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

An incident involving the loss or theft of an IRS IT asset or BYOD asset containing PII, or the loss or theft of a physical document that includes PII, or the inadvertent unauthorized disclosure of PII, is known as a data breach. See the Data Breach definition below. Often, an occurrence may be first identified as an incident, but later identified as a data breach once it is determined that the incident involves PII, as is often the case with a lost or stolen laptop or electronic storage device.

Data Breach. A data breach is a type of incident involving a loss, theft, or inadvertent unauthorized disclosure of PII. OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information, defines a data breach as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or, (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

A data breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A data breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose. Often, an occurrence may first be identified as an incident, but later identified as a data breach once it’s determined that the incident involves PII, as is often the case with a lost or stolen laptop or electronic storage device.

Some common examples of a data breach include:

A laptop or electronic storage media containing PII is lost or stolen.

A document containing PII is lost or stolen, or lost or stolen during shipping.

A verbal disclosure of PII to an individual not authorized to receive it.

An email containing PII is sent to the wrong person or not properly encrypted.

An IT system that maintains PII is accessed by a malicious actor.

An inadvertent disclosure of PII on a public website.

An authorized user accesses PII for other than an authorized purpose.

Major Incident. OMB Memorandum M-25-04, Fiscal Year 2025 Guidance on Federal Information Security and Privacy Management Requirements, defines a "major incident" as:

Any incident that is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people; or,

A breach that involves personally identifiable information (PII) that, if exfiltrated, modified, deleted, or otherwise compromised, is likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States, or to the public confidence, civil liberties, or public health and safety of the American people.

Exceptions & meaning →

Note:

OMB-M-25-04 requires a determination of major incident for any unauthorized modification of, unauthorized deletion of, unauthorized exfiltration of, or unauthorized access to the PII of 100,000 or more individuals.

Potentially Impacted Individual. Individuals, as defined by the Privacy Act of 1974, potentially impacted by occurrences of IRS data losses, thefts, and inadvertent unauthorized disclosures involving sensitive but unclassified (SBU) data, including personally identifiable information (PII) and tax information, are known as "Potentially Impacted Individuals." Consistent with OMB directives, the IRS notifies potentially impacted individuals when a data breach involves the loss, theft, or inadvertent unauthorized disclosure of PII, and the result of the risk assessment indicates there is a potential risk that the compromised data may be used by someone other than the owner of the information to commit a crime or fraud.

Records Loss."Records loss" is defined as the theft or unauthorized destruction, deletion, or removal of any record (or device containing records) under an employee’s control, which cannot be recreated or restored.

Records. The term "records" includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them. (44 USC 3301).

Unauthorized Destruction. Unauthorized destruction is the removal from the legal custody of the Federal Government or the alienation, alteration, or mutilation of records without regard to the provisions of IRS Records Control Schedules (RCS 8 through 37) located in IRS Document 12990, Records Control Schedules (Catalog 57910D), and General Records Schedules (GRS) located in IRS Document 12829, The General Records Schedules (Catalog 54713E).

Reporting to NARA. Per 36 CFR 1230.14, How do agencies report incidents?, all federal agencies must report promptly any unlawful or accidental removal, defacing, alteration, or destruction of records in the custody of that agency to the National Archives and Records Administration (NARA). The IRS Records Officer reports any IRS incidents of erroneous records destruction to NARA.

Personally Identifiable Information (PII). The definition of personally identifiable information is provided by OMB in OMB Circular No. A-130, Managing Information as a Strategic Resource and OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information.

The term PII refers to information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.

Some examples of PII are: name, such as full name, maiden name, mother’s maiden name, alias, or name control (first four letters of last name); address information, such as street address or email address; a unique set of numbers or characters assigned to a specific individual, such as telephone numbers, Social Security number (or last four digits of SSN), passport number, driver’s license number, email or Internet Protocol (IP) address, or Standard Employee Identifier (SEID); personal characteristics and data, such as date and place of birth, age, height, or weight; and biometric information such as x-rays, fingerprints, retina scan, or DNA.

For more information about PII and additional examples, visit the Personally Identifiable Information page in the Disclosure and Privacy Knowledge Base Site; and see IRM 10.5.1.2.3, Personally Identifiable Information (PII) and IRM 10.8.1.4.16.1.3, Personally Identifiable Information (PII).

Sensitive But Unclassified (SBU) Data. Any information which if lost, stolen, misused, or accessed or altered without proper authorization, may adversely affect the national interest or the conduct of federal programs (including IRS operations), or the privacy to which individuals are entitled under the Privacy Act.

SBU data includes, but is not limited to: tax information (also known as federal tax information (FTI)), personally identifiable information (PII), protected health information (PHI), certain procurement information, system vulnerabilities, case selection methodologies, systems information, enforcement procedures, and investigation information.

SBU data includes categories of protected information which many IRS personnel handle daily, such as PII and tax information. It also includes other categories, such as procurement (which can include general procurement and acquisition, small business research and technology, and source selection) and system information (which can include critical infrastructure categories like information systems vulnerability information, physical security, and emergency management).

For more information about SBU, visit the Sensitive But Unclassified (SBU) Data page in the Disclosure and Privacy Knowledge Base Site and IRM 10.5.1.2.2, Sensitive But Unclassified (SBU) Data.

Federal Tax Information (FTI). The term tax information, or federal tax information (FTI), refers to a taxpayer’s return and return information protected from unauthorized disclosure under IRC 6103, Confidentiality and Disclosure of Returns and Return Information.. The law defines return information as any information the IRS has about a tax or information return, liability, or potential liability under Title 26. See IRC 6103(b)(2) which defines the term return information.

Return information includes, but is not limited to, a taxpayer’s: identity; income, payments, deductions, exemptions, or credits; assets, liabilities, or net worth; and tax liability investigation status (whether the IRS ever investigates or examines the return).

Redacting, masking, truncating, or sanitizing tax information does not change its nature. It’s still tax information.

Tax information in IRS business processes comes under many names, such as FTI, IRC 6103 protected information, taxpayer data, taxpayer information, tax return information, return information, case information, SBU data, and PII.

Tax information is SBU data. IRC 6103 protects tax information from unauthorized disclosure. When tax information relates to an individual, that SBU data is also PII.

Release of tax information (whether of an individual or business) is restricted by the confidentiality provisions of IRC 6103(a).

For more information about federal tax information (FTI), see IRM 10.5.1.2.4, Federal Tax Information (FTI).

Exceptions & meaning →

Note:

Generally, any response provided by the IRS about a tax return is protected information. Confirming the existence of a tax return (whether a return was or was not filed), or confirming the SSN or EIN of a taxpayer, is prohibited - even a Yes/No response is protected information unless the disclosure is authorized by IRC 6103 and the recipient is authorized to receive it.

Cybersecurity Information Protection Enhancement Controls (CIPEC) application (formerly Safeguarding Personally Identifiable Information Data Extracts (SPIIDE)) Automated Data Loss Prevention (DLP) Tool). CIPEC is a Data Loss Prevention (DLP) tool within the IRS Cybersecurity toolkit.

Business Unit (BU) Data Owner. The BU data owner is the business unit who has responsibility for the information and is therefore responsible for containment and mitigation of the data breach, e.g., if a Power of Attorney (POA) tells an SBSE revenue officer (RO) he or she received Income Verification Express Service (IVES) transcripts he or she did not request, the reporting employee/POC is the RO, but TS is the data owner and carries the responsibility for mitigation and containment.

Reporting Employee/Point of Contact (POC). The reporting employee/POC is the employee who identifies/recognizes a data breach and reports the data breach as required. The reporting employee/POC is responsible for reporting all pertinent information relative to the data breach.

For a full listing of IM terms and their definitions, see Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms.

Exceptions & meaning →

Acronyms

The table below lists commonly used acronyms and their definitions:

Acronym

Definition

BRT

Breach Response Team

BU

Business Unit

BYOD

Bring Your Own Device

CIPEC

Cybersecurity Information Protection Enhancement Controls (previously known as Safeguarding Personally Identifiable Information Data Extracts (SPIIDE))

CSIRC

Computer Security Incident Response Center

FTI

Federal Tax Information

IM

Incident Management

IMEP

Incident Management and Employee Protection

OFDP

Online Fraud Detection and Prevention, within IT Cybersecurity

OMB

Office of Management and Budget

OTC

Office of Taxpayer Correspondence (now Taxpayer Correspondence Services (TCS))

PGLD

Privacy, Governmental Liaison and Disclosure

PII

Personally Identifiable Information

PIIWG

PII Working Group

PIPDS

Privacy, Information Protection and Data Security (name changed to Privacy, Governmental Liaison and Disclosure (PGLD)

PPC

Privacy Policy and Compliance

RIM

Records and Information Management

SAMC

Situational Awareness Management Center

SPIIDE (renamed to CIPEC in 2024)

Safeguarding Personally Identifiable Information Data Extracts. Renamed to Cybersecurity Information Protection Enhancement Controls in 2024.

SBU

Sensitive But Unclassified

TCS

Taxpayer Correspondence Services (formerly OTC)

TS

Taxpayer Services

UNAX

Unauthorized Access

UNAD

Unauthorized Disclosure

For a full listing of IM terms, definitions, and acronyms, see Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms.

Exceptions & meaning →

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.