Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
Sections in this part
The reporting time frame was updated from "within one hour" to "immediately upon discovery," beginning with the October 2019 publication of this IRM to comply with the reporting time frame language in TD P 85-01, Appendix A, Minimum Standard Parameters for Non-National Security Information and Information Systems.
The timely reporting of all erroneous taxpayer correspondence involving the disclosure of SBU data, including PII and tax information, all inadvertent unauthorized disclosures of SBU data, including PII and tax information, all losses or thefts of hardcopy records or documents containing SBU data, including PII and tax information, and all suspected security incidents, including any incidents of loss or mishandling of IRS information technology resources and lost or stolen IRS IT assets and BYOD assets, is critical for quickly initiating any needed investigation or recovery of information by the BU data owner. A prompt report decreases the possibility the information will be compromised and used to perpetrate identity theft or other forms of harm. See IRM 10.5.4.4.4, PGLD/Incident Management Risk Assessment and Mitigation, and Exhibit 10.5.4-1, Glossary of Incident Management Terms, Definitions, and Acronyms, for additional information about, and examples of, harm/risk of harm. See IRM 10.5.4.1.3, Responsibilities, and the Incident/Data Breach Responsibilities for Reporting Employees and Business Unit (BU) Data Owners page in the Disclosure and Privacy Knowledge Base Site for additional information about the actions BU data owners must take to contain data leakage and mitigate risk, or contact PGLD/IM via the *PII mailbox for additional mitigation guidance and assistance.
Get a plain-English answer with a citation back to this text.
Ask AI about this code