Skip to content

Title›Note:

High-Risk Data Breaches

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

A high-risk data breach includes any data breach that meets the OMB definition of a major incident or includes any special circumstances requiring an enhanced response because of significant risk to:

Customers: Affects a significant number of individuals or high-profile individuals;

Business Results: Overwhelming increase of phone traffic, reduced taxpayer access to IRS systems or online applications, negative affect on revenue protection; or,

IRS Reputation: Potential for extensive media involvement, congressional interest, or negative exposure.

High-risk data breaches may be identified through several different channels. For example:

Cybersecurity may identify a potential breach of an IRS system or application.

PGLD or another BU may identify a loss, theft, or inadvertent, unauthorized disclosure of SBU data, including PII and tax information, with unusual circumstances.

A third-party data owner may identify a breach of SBU data, including PII and tax information.

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.