Skip to content

Title

Note:

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

When assessing the potential level of risk based on the nature and sensitivity of the PII, most PII will be classified as low, moderate or high impact. Information related to businesses, such as name and address, is considered public information because it’s available to the public from other sources. This type of information doesn’t meet the definition of PII when it’s not linked or linkable to an individual; however, personal information disclosed on the officers of a corporation, partners in a partnership, sole proprietor, etc., is PII.

Likelihood of Access and use of the PII. The likelihood of access and use of the PII potentially compromised by the data breach, including whether the PII was properly encrypted, or rendered partially or completely inaccessible by other means. The following items are considered when assessing the likelihood of access and use of PII potentially compromised by a data breach: Security Safeguards, including whether the PII was properly encrypted, or rendered partially or completely inaccessible by other means; Format and Media, including whether the format of the PII or the media on which it is maintained may make it difficult and resource-intensive to use; Duration of Exposure, including how long the PII was exposed; and Evidence of Misuse, including any evidence confirming that the PII is being misused, or that it was never accessed.

Type of Data Breach. The type of data breach, including the circumstances of the data breach, as well as the actors involved and their intent. The following items are considered when determining the type of data breach: Intent, including whether the PII was compromised intentionally, unintentionally, or whether the intent is unknown; and Recipient, including whether the PII was disclosed to a known or unknown recipient, and the trustworthiness of a known recipient.

After assessing the risk of harm to individuals potentially impacted by a data breach, PGLD/IM will determine how to best mitigate the identified risks. Because each data breach is fact-specific, the decision of whether to take countermeasures, offer guidance, or provide services to potentially impacted individuals will depend on the circumstances of the data breach. Actions the IRS can take to limit, reduce, or mitigate the risk of harm to potentially impacted individuals include:

Countermeasures, such as placing markers on the accounts (e.g., identity theft markers and/or IRS Data Breach Tracking Indicator), ensuring the individuals are aware of the availability of the Identity Protection Personal Identification Number (IP PIN) for filing tax returns, using database filters, or other internal safeguards;

Guidance, such as providing individuals with information on how they may obtain a free credit report, how they may set up a fraud alert or place a credit freeze, and whether they should consider changing or closing certain accounts; and

Services, such as offering identity protection/identity monitoring or an IP PIN.

After IM has completed its risk analysis of a data breach and developed a recommendation regarding the appropriate response, data breaches with a total factor rating point between 8 and 9 and categorized or classified as "Code Red" are included in a Code Red Recommendations Report and presented to the Incident Management Associate Director for review (no approval required).

If the recommendation is to notify, then potentially impacted individuals are notified of the data breach via Letter 4281C, IM Breach Notification Letter.

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.