Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
These procedures apply only to data breach notifications and notifications to individuals whose personal information was intentionally accessed or disclosed without authorization resulting in an administrative proposal of disciplinary or adverse action against an employee; they do not apply to notifications made pursuant to 26 USC 7431(e), i.e., unauthorized access or disclosure resulting in a criminal indictment. See IRM 10.5.5, Privacy and Information Protection, Unauthorized Access, Attempted Access or Inspection of Taxpayer Records (UNAX) Program Policy, Guidance and Requirements.
Remedial services such as identity protection/identity monitoring services are offered to potentially impacted individuals of an IRS data breach as part of the overall OMB requirement regarding implementation of a data breach response program to mitigate the likely risk of harm, specifically the potential for identity theft.
In unique situations, Letter 4281C with specialized (open) paragraphs may be used for data breaches where, based on the risk assessment, it appears the individual isn’t likely to be at risk of identity theft, but is likely to be subject to other risk of harm. The offer of an identity protection/identity monitoring service will not be included in the letter as these services do not mitigate the potential risk for these types of situations.
Letter 4281C, with specialized (open) paragraphs, may also be used for data breaches involving businesses where there is a potential risk of harm and notification is recommended. Much of the same information will be included in the letter, but the business will not be offered services such as identity protection/identity monitoring.
Generally, individuals potentially impacted by "routine" data breaches caused by IRS employees and contractors will be notified of the data breach and offered identity protection/identity monitoring unless the facts and circumstances of the data breach do not warrant notification.
Generally, individuals potentially impacted by intentional unauthorized accesses or disclosures (UNAX/UNAD) caused by IRS employees and contractors which results in proposed disciplinary or adverse action will be notified of the data breach and offered identity protection/identity monitoring unless the facts and circumstances of the data breach do not warrant notification.
Generally, individuals potentially impacted by IRS data breaches will not be notified of the data breach if the data breach occurred 36 months or more before being reported to PGLD/IM unless the facts and circumstances warrant notification, e.g., if the PII was targeted.
Data breach notifications will be written plainly and clearly, and will generally include the following information:
A brief description of what happened, including the date of the data breach;
To the extent possible, a description of the type of PII disclosed as a result of the data breach (e.g., name, SSN, date of birth, address, etc.);
Actions that potentially impacted individuals should take to protect themselves from potential harm;
A toll-free telephone number that potentially impacted individuals can contact for more information;
A statement that the IRS has provided or will provide potentially impacted individuals with an identity protection/identity monitoring service at no cost (if the risk assessment results in a likelihood of harm, specifically the potential for identity theft (see (2) above), and the contact information for the vendor providing the service.
Get a plain-English answer with a citation back to this text.
Ask AI about this code