Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Sections in this part
See (3) and (4) below and the If/then Guide for Reporting Incidents and Data Breaches (PDF) for additional reporting requirements based on what was lost, stolen, destroyed, or disclosed.
The Treasury Inspector General for Tax Administration (TIGTA). Report the incident/data breach to TIGTA by calling 800-366-4484, if the incident/data breach involves: the loss or theft of an IRS IT asset, e.g., an IRS issued computer, laptop, router, printer, cell phone, removable storage media (CD/DVD, flash drive, floppy, etc.); or the loss or theft of a non-IRS IT asset (BYOD device); or an IRS IT asset or BYOD asset lost or stolen during UPS or FedEx shipment; or the loss, theft, or unauthorized destruction of official records (whether the documents contain PII or not); or the loss, theft, or unauthorized destruction of documents containing SBU data, including PII and tax information, such as hardcopy records, documents, or case files, packages lost or stolen during UPS or FedEx shipment, or lost or stolen remittances.
Local Law Enforcement. Report the incident/data breach to your local Law Enforcement authority and file a Police Report if the incident/data breach involves a theft, but do not disclose sensitive data and/or taxpayer data.
Treasury Shared Services Security Operations Center (TSOC). The applicable reporting office – either PGLD/IM or CSIRC – will report to the Treasury Computer Security Incident Response Center (TCSIRC) for further submission to TSOC as necessary.
CSIRC will report incidents to TCSIRC for assessment and reporting to the Cybersecurity and Infrastructure Security Agency (CISA) as necessary.
For data breaches reported to PGLD/IM through the online reporting tool, IM will report to TCSIRC data breaches meeting Treasury’s reporting requirements.
The PPC Director in PGLD will coordinate with Treasury when additional reporting may be required to law enforcement, oversight entities, or Congress.
Visit the Report Losses, Thefts or Disclosures page in the Disclosure and Privacy Knowledge Base Site and see the If/Then Guide for Reporting Incidents and Data Breaches (PDF) listed in the Other Related Resources section for additional information and guidance. If you are a flexiplace (telework) employee (frequent, recurring or ad hoc) or a mobile employee, print a copy of the If/Then Guide for the office and one to keep at home in case your IRS IT asset or BYOD asset is lost or stolen, and you can’t access IRS Source.
Get a plain-English answer with a citation back to this text.
Ask AI about this code