PGLD/Incident Management Data Breach Notification - Letter 4281C
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
The IRS, through PGLD/IM, will notify potentially impacted individuals when a data breach involves the loss, theft or inadvertent unauthorized disclosure of PII, and the result of the risk assessment indicates there is a potential risk that the compromised data may be used by someone other than the owner of the information to commit a crime or fraud. Identity protection/identity monitoring services are offered to individuals if the risk assessment results in a likelihood of harm, specifically the potential for identity theft.
The IRS, through PGLD/IM, may also notify potentially impacted individuals if the result of the risk assessment indicates the individual is not likely to be at risk for identity theft, but is likely to be subject to other risk of harm. The offer of an identity protection/identity monitoring service will not be included in the letter as these services do not mitigate the potential risk for these types of situations.
Breach Notification Letters are not generally issued to potentially impacted businesses. The IRS may notify businesses potentially impacted by a data breach if sensitive business information (other than publicly available information such as the business name and address) is lost or disclosed by the IRS, or an IRS contractor, that could lead to possible fraud against the business, or individuals associated with the business, but the business will not be offered services such as identity protection/identity monitoring.
Get a plain-English answer with a citation back to this text.
Ask AI about this code