Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Incident Management Intake may also include events received from CIPEC for investigation.
After PGLD/IM reviews the information submitted and performs an initial assessment of the data breach, if SBU data, including PII and tax information, is involved, PGLD/IM will, if necessary, request additional information to fully assess the data breach to complete the risk assessment. This may include asking the reporting employee/point of contact (POC) if all efforts have been made to secure the return or recovery of the asset(s) or documents involved in the data breach if not already documented on the PII Breach Reporting Form. If the data breach is input through the e-Trak online breach reporting form (PII Breach Reporting Form) and the employee indicated an SSN or EIN was disclosed, the reporting employee/POC will receive an Impacted Individuals and/or Business Excel Spreadsheet as an attachment to the email received from e-Trak. If the data breach is input through other than the e-Trak online reporting form, PGLD/IM will send an Impacted Individuals Excel Spreadsheet to the reporting employee/POC and the employee’s manager if an SSN is needed for notification. The reporting employee/POC is responsible for providing the complete, unredacted tax identification numbers (SSNs/EINs) of the potentially impacted individuals and/or businesses and emailing the spreadsheet via secure email to the *PII mailbox within two business days of receipt.
Get a plain-English answer with a citation back to this text.
Ask AI about this code