Note:
Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States
See also the definition of "Incident."
Data Breach Incident
An incident involving a loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information. A few common examples include: a laptop or portable storage device containing PII is lost or stolen; an email containing PII is inadvertently sent to the wrong person; or a box of documents with PII is lost or stolen during shipping.
Data Breach Management
The process of managing incidents involving a loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information.
Data Breach Notification
The process of notifying potentially impacted individuals following the evaluation of an incident involving a loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information, which results in a likelihood of harm to these individuals.
Data Breach Risk Assessment
A risk assessment conducted on an incident involving a loss, theft, or inadvertent unauthorized disclosure of SBU data, including PII and tax information. The risk assessment includes factors that must be considered, specifically the context of the data breach and the data that was disclosed. Example: An IRS employee in the field loses a taxpayer case file. The case file contained PII data such as name, address, social security number, and other tax data. It is not known if the loss of the PII data will lead to identity theft. The IRS conducts a risk assessment and examines key factors to determine if notification must be given to the potentially impacted individual.
Disclosure
Making known to any person, in any manner, a return or return information. IRC 6103 governs the rules for how, when, to whom, and what federal tax information can or cannot be disclosed. See IRM 11.3.1, Disclosure of Official Information, Introduction to Disclosure.
Enterprise Electronic Fax (EEFax)
Enterprise Electronic Fax is the Servicewide standard system for secure faxing. It allows you to send and receive electronic documents directly from your computer. Incoming faxes appear as Adobe Acrobat pdf files in your group EEFax from no reply@efax.gov.
Erroneous Taxpayer Correspondence (ETC)
Correspondence is erroneous when it has been sent to the wrong address or addressee and it involves SBU data, including PII and tax information. Erroneous taxpayer correspondence can also be notices, letters, transcripts, faxes, or other electronic/digital documents sent with mixed entity information such as correct taxpayer information is on page one, but unrelated taxpayer information is on page two; two letters for different taxpayers in the same envelope; the attachment in the correspondence is for a different taxpayer, etc.
Federal Information Processing Standards (FIPS)
A set of standards that describe document processing, encryption algorithms and other information technology standards for use within non-military government agencies and by government contractors and vendors who work with the agencies.
Federal Information Processing Standards (FIPS) Publications
Publications issued by the National Institute of Standards and Technology (NIST) after approval by the Secretary of Commerce pursuant to Section 5131 of the Information Technology Reform Act of 1996 (Public Law 104-106) and the Federal Information Security Management Act of 2002 (Public Law 107-347).
Federal Tax Information (FTI)
Any return or return information as defined in IRC 6103(b). This includes any information obtained, received, or generated by IRS or any Treasury component with respect to determining liability, potential liability, or amount of liability under the IRC. FTI falls under the SBU data category called tax information or Tax. This IRM uses the term tax information to encompass all types of tax data. See IRM 10.5.1, Privacy and Information Protection, Privacy Policy, for additional information.
Federal Trade Commission (FTC)
An independent agency of the United States government, established in 1914 by the Federal Trade Commission Act, with the principal mission of promoting "consumer protection" and the elimination and prevention of what regulators perceive to be "anti-competitive" business practices.
Form 14164, Personally Identifiable Information (PII) Analysis
Employees report data breaches involving erroneous taxpayer correspondence involving the disclosure of SBU data, including PII and tax information, i.e., a notice, letter, or transcript, which was mailed, emailed, faxed, EEFaxed, or generated or transmitted via IVES, RAIVS, TDS, SDT, or other electronic transmission, to the wrong address or addressee; or inadvertent unauthorized disclosures of SBU data, including PII and tax information, such as verbal disclosures, or emails sent to the wrong person or not properly encrypted; or the loss, theft, or unauthorized destruction of documents containing SBU data, including PII and tax information, such as hardcopy records, documents, or case files, packages lost or stolen during UPS or FedEx shipment, or lost or stolen remittances; or electronic disclosures of SBU data, including PII and tax information, in IRMs, Training Materials, PowerPoints, IRS Source, SharePoint, etc., or on external systems/sites such as WhatsApp, GitHub, etc., or SBU data, including PII and tax information, shared with, or input or uploaded to, Artificial Intelligence (AI) or other internet tools or sites used for translation, document conversion, etc., via PGLD’s e-Trak online breach reporting form (PII Breach Reporting Form). The online breach reporting form is a web-based online reporting form fillable only through e-Trak, a web interface for case tracking. The Personally Identifiable Information (PII) Analysis form is auto-populated through e-Trak based on the information the reporting employee/point of contact (POC) enters on the e-Trak online breach reporting form. Form 14164 is generated for informational purposes to provide reporting employees/POCs with a summary of their responses from the e-Trak online breach reporting form for their records. If the reporting employee/POC indicated there was PII involved in the data breach on the e-Trak online breach reporting form, e-Trak generates a Form 14164, PII Analysis, and includes it, and Excel spreadsheets, in an email sent to the employee. The email requests the employee identify the impacted individuals and/or businesses on the spreadsheets attached to the email and to return the completed spreadsheets within two business days to the *PII mailbox. Note: Form 14164 is viewable from the Publishing Catalog, but it is not fillable.
Form 14164-A, Personally Identifiable Information (PII) Breach Reporting
Employees report data breaches involving erroneous taxpayer correspondence involving the disclosure of SBU data, including PII and tax information, i.e., a notice, letter, or transcript, which was mailed, emailed, faxed, EEFaxed, or generated or transmitted via IVES, RAIVS, TDS, SDT, or other electronic transmission, to the wrong address or addressee; or inadvertent unauthorized disclosures of SBU data, including PII and tax information, such as verbal disclosures, or emails sent to the wrong person or not properly encrypted; or the loss, theft, or unauthorized destruction of documents containing SBU data, including PII and tax information, such as hardcopy records, documents, or case files, packages lost or stolen during UPS or FedEx shipment, or lost or stolen remittances; or electronic disclosures of SBU data, including PII and tax information, in IRMs, Training Materials, PowerPoints, IRS Source, SharePoint, etc., or on external systems/sites such as WhatsApp, GitHub, etc., or SBU data, including PII and tax information, shared with, or input or uploaded to, Artificial Intelligence (AI) or other internet tools or sites used for translation, document conversion, etc., via PGLD’s e-Trak online breach reporting form (PII Breach Reporting Form). The online breach reporting form is a web-based online reporting form fillable only through e-Trak, a web interface for case tracking. Note: A representation of the PII Breach Reporting Form is viewable from the Publishing Catalog, but it is not fillable. It is only accessible/fillable on e-Trak. The fillable version on e-Trak contains drop-down selections to aid in completion of the form.
Fraud Alert
A fraud alert is a statement that a credit reporting agency adds to an individual’s credit file at the individual’s request. It alerts creditors that the individual may be a victim of fraud. This statement requires creditors to take certain steps to verify the individual’s identity before establishing any new credit accounts in his or her name, issuing a new card on an existing account, or increasing the credit limit on an existing account.
Hardcopy
Hardcopy media are physical representations of information, most often associated with paper printouts. However, printer and facsimile ribbons, drums, and platens are all examples of hardcopy media. The supplies associated with producing paper printouts are often the most uncontrolled. Hard copy materials that include sensitive data that leave an organization without effective sanitization expose a significant vulnerability to "dumpster divers" and over-curious employees, risking unwanted information disclosures. [NIST Special Publication 800-88, Guidelines for Media Sanitization]
Harm/Risk of Harm
Includes any of the following effects of a breach of confidentiality, integrity, availability, or fiduciary responsibility: potential for blackmail; disclosure of private facts; mental pain and emotional distress; potential for secondary uses of the information that could result in fear or uncertainty, or unwarranted exposure leading to humiliation or loss of self-esteem; identity theft; or financial loss.
Identity Theft
Use of an individual’s personal information, without the individual’s permission, to commit fraud or other crimes.
Incident
OMB M-17-12 defines an Incident as an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. An incident is classified as an incident if it involves SBU information but doesn’t involve PII. Often, an occurrence may be first identified as an incident, but later identified as a data breach once it is determined that the incident involves PII, as is often the case with a lost or stolen laptop or electronic storage device.
Get a plain-English answer with a citation back to this text.
Ask AI about this code