Skip to content

Title

Note:

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

Form 14164, Personally Identifiable Information (PII) Analysis, is auto-populated through e-Trak based on the information the reporting employee/POC enters on the e-Trak online breach reporting form (PII Breach Reporting Form). Form 14164 is generated for informational purposes to provide reporting employees/POCs with a summary of their responses from the e-Trak online breach reporting form for their records. Form 14164 is viewable from the Publishing Catalog, but it is not fillable.

An incident/data breach is reported to CSIRC via CSIRC’s Computer Security Incident Reporting Form if the incident/data breach involves the loss or mishandling of IRS information technology resources, or the loss or theft of an IRS IT asset or an asset in the Bring Your Own Device (BYOD) program, or an IRS IT asset or BYOD asset lost or stolen during UPS or FedEx shipment, or if it involves multiple assets, i.e., an IRS IT asset or BYOD asset and hardcopy records or documents containing SBU data, including PII and tax information. Note that the form and instructions for incidents/data breaches involving IT assets are different from the forms and instructions for all other data breaches.

An incident is reported to SAMC via SAMC’s Incident Reporting Link if the incident involves the loss or theft of ID media, including SmartID cards, PAC cards, Pocket Commissions (credentials), etc., building access cards, building or room keys, government property or equipment, or physical security incidents and/or threats. Note the reporting requirement time frame for SAMC is within 30 minutes of discovery.

After a data breach is reported, PGLD/IM receives notification via email (delivered to the *PII mailbox) from either CSIRC or e-Trak. The email contains the information necessary to conduct a risk assessment and to determine if the data breach meets high-risk data breach criteria.

The *PII mailbox is a centralized communication tool used by PGLD/IM to send and receive all communications throughout the data breach intake process. Data breach summaries with a brief description of the data breach are automatically sent via email to the *PII mailbox whenever data breaches are reported to CSIRC via the Computer Security Incident Reporting Form or to PGLD/IM via the PII Breach Reporting Form.

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.