Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Notification can only be accomplished if the reporting employee/point of contact (POC) is able to provide the SSNs/EINs of the potentially impacted individuals/businesses.
The IRS, through PGLD/IM, will identify potentially impacted individuals of an IRS data breach who have been sent Letter 4281C by inputting History Items on CC ENMOD (only if the account is on the Master File (MF)) and marking each entity (on CC ENMOD and/or CC IMFOLE) with the IRS data breach tracking indicator TC 971 AC 505 (only if the account is on the MF). A TC 971 AC 505 will only be input on the accounts of individuals who are sent Letter 4281C because of an intentional unauthorized access or disclosure (UNAX/UNAD) if they are offered identity protections such as identity protection/identity monitoring services or IP PIN in the letter. If they are only advised of their rights under IRC 7431, Civil Damages For Unauthorized Inspection Or Disclosure Of Returns And Return Information, then no TC 971 AC 505 will be input. Although no TC 971 AC 505 will be input, History Items will still be added to CC ENMOD (if the account is on the MF). See IRM 10.5.4.5.1.1, Applying the IRS Data Breach Tracking Indicator to IRS Data Breaches, for additional information.
The IRS, through PGLD/IM, will identify potentially impacted businesses of an IRS data breach who have been sent Letter 4281C by inputting History Items on CC ENMOD (only if the account is on the Master File (MF)). Since the TC 971 AC 505 isn’t applied to BMF accounts, History Items will be input on BMF entities to alert anyone looking at the account that business information has been exposed and to add a heightened awareness of any unusual activity.
The objectives of communications in the event of a possible compromise of SBU data, including PII and tax information, within the IRS are as follows:
To comply with OMB and Treasury Department directives which mandate notification to potentially impacted individuals if there is a potential risk that the compromised data may be used by someone other than the owner of the information to commit a crime or fraud.
Get a plain-English answer with a citation back to this text.
Ask AI about this code