Authorized IRS e-file Providers of Individual Income Tax Returns
Chapter 2 – Must Read
1225 Publ 1345 (PDF) · 2026-10-03 edition · updated 2026-10-04 · United States
Publications for Individual Income Tax Returns¶
This publication, Publication 1345, Authorized IRS e-file Providers of Individual Income Tax Returns, provides rules and requirements for participation in IRS e-file of individual income tax returns and related forms and schedules. Violating a provision of this publication may subject the Authorized IRS e-file Provider (Provider) to sanctions. Providers should familiarize themselves with Revenue Procedure 2007-40, 2007-26 I.R.B. 1488 (or the latest update) and Publication 3112 , IRS e-file Application and Participation, to ensure compliance with requirements for participation in IRS e-file. The IRS revises Publication 1345 annually.
• Publication 4164 , Modernized e-file (MeF) Guide for Software Developers and Transmitters. This publi- cation outlines the communication procedures, transmission formats, business rules and validation procedures for returns e-filed through the Modernized e-file (MeF) system.
• Publication 4557 , Safeguarding Taxpayer Data, A Guide for Your Business. This publication provides helpful information on safeguarding taxpayer data including how to create a data security plan.
• Publication 5708 , Creating a Written Information Security Plan for Your Tax & Accounting Practice. Publication 5708 will be used by Tax and Accounting practices for information on developing an Information Security Plan. The publication was developed during the Security Summit, jointly by private sector companies, State and local tax agencies and the IRS.
Safeguarding IRS e-file¶
Safeguarding of IRS e-file from fraud and abuse is the shared responsibility of the IRS and Authorized IRS e-file Providers. Providers must be diligent in recognizing and preventing fraud and abuse in IRS e-file . Neither the IRS nor Providers benefit when fraud or allegations of abuse tarnish the integrity and reputation of IRS e-file . Providers must report fraud and abuse to the IRS as indicated in the “ Where to Get More Informa- tion? ” section. Providers must also cooperate with IRS investigations by making available to the IRS, upon request, information and documents related to returns with potential fraud or abuse.
Safeguarding taxpayer data is a top priority for the IRS. It is the legal responsibility of government, businesses, organizations, and individuals that receive, maintain, process, share, transmit or store taxpayers’ personal information. Taxpayer data is defined as any information that is obtained or used in the preparation of a tax return (e.g., income statements, notes taken in a meeting, or recorded conversations). Putting safeguards in place to protect taxpayer information helps prevent fraud and identity theft and enhances customer confidence and trust.
Protecting taxpayer data is required by law. Federal law gives the Federal Trade Commission (FTC) authority to set data safeguard regulations for various entities, including professional tax return preparers. According to the FTC Safeguards Rule in Part 314 (16 C.F.R.), tax return preparers must create and enact security plans to protect client data. Failure to do so may result in a FTC investigation.
The FTC also works to protect taxpayer data. Providers subject to the Gramm-Leach-Bliley Act must follow the FTC’s Financial Privacy and Safeguard Rules. The Safeguards Rule requires the protection of the security, confidentiality and integrity of customer information by implementing and maintaining a comprehensive information security program. The program must include administrative, technical, and physical safeguards appropriate to the business’s size, the nature and scope of its activities, and the sensitivity of the customer information at issue.
3
Here are a few basic security steps:
• Recognize phishing emails
• Create a data security plan
• Review internal controls
• Report any data theft or loss
• Implement multi-factor authentication for anyone accessing taxpayer information. This is required under FTC Safeguards Rule Part 314, (16 C.F.R).
All persons and entities who receive taxpayers’ personal information can use Publication 4557 , Safeguarding Taxpayer Data, A Guide for Your Business, to help determine their data privacy and security needs and implement safeguards to protect the information. Publication 4557 includes information about security standards and best practice guidelines to safeguard consumer information such as personal tax data, with links to several resources including National Institute of Standards and Technology (NIST) publications. Not taking necessary steps to implement or correct your security program may result in sanctions from the FTC. Failures that lead to an unauthorized disclosure may subject you to penalties under sections 7216 and/or 6713 of the Internal Revenue Code (I.R.C.).
At a minimum, providers must require taxpayer’s who have established an online account to validate access to a second factor (email, phone or other secure authenticator) before being permitted to electronically transmit their tax return to the IRS. For a taxpayer creating a new account, this requires validation of the phone number, email, or other secure authenticator prior to electronically submitting a tax return. For a taxpayer logging back into an existing account, this requires multi-factor authentication of the taxpayer prior to granting access to tax data stored within the account. Multi-factor authentication requires the use of at least two of these authentication factors: a knowledge factor (for example, a password); a possession factor (for example, a token); and an inherence factor (for example, biometric). It is strongly recommended that software providers follow NIST guidelines and prohibit taxpayers from using an unfixed Voice over Internet Protocol (VoIP) phone number as a possession factor.
Providers appoint an individual as a Responsible Official who is responsible for ensuring the firm meets IRS e-file rules and requirements. Providers with problems involving fraud and abuse may be suspended or expelled from participation in IRS e-file, be assessed preparer and other civil penalties or be subject to legal action.
IRS e-file Security, Privacy and Business Standards¶
The IRS has mandated six security, privacy, and business standards to supplement the Gramm-LeachBliley Act to better serve taxpayers and protect their information collected, processed and stored by Online Providers of individual income tax returns. The first five standards continue to apply to Online Providers, while Standard number six, “Reporting of Security Incidents,” is now mandated for all Providers.
Individual income tax returns refer to the 1040 family of returns. Refer to the IRS Publication 3112 , IRS e-file Application and Participation, for definition of Online Provider.
The security and privacy objectives of these standards are:
• Setting minimum encryption standards for transmission of taxpayer information over the internet and authentication of website owner/operator’s identity beyond that offered by standard version SSL certificates.
• Periodic external vulnerability scan of the taxpayer data environment.
• Protection against bulk-filing of fraudulent income tax returns.
• The ability to timely isolate and investigate potentially compromised taxpayer information.
4
These standards also address certain business and customer service objectives, such as instant payment options, access to website owner/operator’s contact information, and Online Provider’s written commitment to maintaining physical, electronic, and procedural safeguards of taxpayer information that comply with applicable law and federal standards.
• Extended Validation SSL Certificate Online Providers of individual income tax returns must have a valid and current Extended Validation Secure Socket Layer (SSL) certificate using TLS 1.2 or later and minimum 2048-bit RSA/128-bit AES.
• External Vulnerability Scan Online Providers of individual income tax returns must contract with an independent third-party vendor to run weekly external network vulnerability scans of all their “system components” in accordance with the applicable requirements of the Payment Card Industry Data Security Standards (PCIDSS) . All scans must be performed by a scanning vendor certified by the Payment Card Industry Security Stan- dards Council and listed on their current list of Approved Scanning Vendors (ASV) . In addition, Online Providers of individual income tax returns whose systems are hosted must ensure that their host complies with all applicable requirements of the PCIDSS .
For the purposes of this standard, “system components” is defined as any network component, server, or application that is included in or connected to the taxpayer data environment. The taxpayer data environment is that part of the network that has taxpayer data or sensitive authentication data.
If scan reports reveal vulnerabilities, action must be taken to address the vulnerabilities in line with the scan report’s recommendations. Retain weekly scan reports for at least one year. The ASV and the host (if present) must be in the United States.
• Information Privacy and Safeguard Policies This standard applies to Authorized IRS e-file Providers participating in Online Filing of individual income tax returns that own or operate a website through which taxpayer information is collected, transmitted, processed or stored. These Providers must have a written information privacy and safeguard policy consistent with the applicable government and industry guidelines and including the following statement: “we maintain physical, electronic and procedural safeguards that comply with applicable law and federal standards.”
In addition, Providers’ compliance with these policies must be certified by a privacy seal vendor acceptable to the IRS.
• Protection Against Bulk Filing of Fraudulent Income Tax Returns This standard applies to Online Providers of individual income tax returns that own or operate a website through which taxpayer information is collected, transmitted, processed or stored. These Online Providers must implement effective technologies to protect their website against bulk filing of fraudulent income tax returns. Taxpayer information must not be collected, transmitted, processed or stored otherwise.
• Public Domain Name Registration This standard applies to Online Providers of individual income tax returns that own or operate a website through which taxpayer information is collected, transmitted, processed or stored. These Online Providers must have their website’s domain name registered with a domain name registrar that is in the United States and accredited by the Internet Corporation for Assigned Names and Numbers (ICANN) . The domain name must be locked and not be private.
5
• Reporting of Security Incidents Authorized IRS e-file Providers of individual income tax returns must report security incidents to the IRS as soon as possible but not later than the next business day after confirmation of the incident. For the purposes of this standard, an event that can result in an unauthorized disclosure, misuse, modification, or destruction of taxpayer information (e.g., breach) must be considered a reportable security incident.
Providers with multiple roles must follow instructions for submitting incident reports at “ Instructions for Reporting Security Incidents .”
Those that are EROs only must contact their local stakeholder liaison by following the instructions at “ Data Theft Information for Tax Professionals .”
In addition, if the Provider’s website is the cause of the incident, the Provider must cease collecting taxpayer information via their website immediately upon detection of the incident and until the underlying causes of the incident are successfully resolved.
Returns Filed Using IRS e-file¶
A return filed using IRS e-file may be a composite of electronically transmitted data and certain paper documents or be completely paperless. The paper portion of a composite return may consist of Form 8453 , U.S. Individual Income Tax Transmittal for an IRS e-file Return, and other paper documents that cannot be electronically transmitted are attached to the form and mailed to the IRS (See Submitting the Electronic Return to the IRS ).
Filing individual income tax returns using IRS e-file is limited to tax returns with prescribed due dates in the current year and two previous years. A taxpayer can electronically file an individual income tax return yearround except for a short cutover period at the end of the calendar year.
If Providers submit state individual income tax returns as part of Federal/State e-file, state returns become a part of the electronically transmitted data. States often require the submission of paper documents to complete the return, but they are separate from paper documents for federal returns. Providers should process state paper documents according to applicable state rules.
Returns Not Eligible for IRS e-file¶
The following individual income tax returns and related return conditions cannot be processed using IRS e-file :
• Tax returns with fiscal year tax periods;
• Returns with forms or schedules that can’t be processed by IRS e-file ;
• Tax returns with Taxpayer Identification Numbers (TIN) within the range of 900-00-0000 through 999-999999. Exception: Adoption Taxpayer Identification Numbers (ATIN) and Individual Taxpayer Identification Numbers (ITIN) may fall within the range above. Valid ATINs have the digits 93 in the fourth and fifth positions. Valid ITINs have digits within a range of 50 through 65, 70 through 88, 90 through 92 and 94 through 99 in the fourth and fifth positions. See “Verifying Taxpayer Identity and Taxpayer Identification Numbers (TINs)” for more information on ATINs and TINs; and
• Tax returns that the IRS cannot electronically process because the returns have rare or unusual processing conditions or that exceed the specifications for returns allowable in IRS e-file . These conditions change from year to year. The software should alert Providers to these conditions when they occur. If Providers transmit electronic return data with one of these conditions to the IRS, the transmission rejects, and the taxpayer may have to file the tax return on paper. The software package documentation or the software’s support program should provide information that is more specific.
6
Submitting a Timely Filed Electronic Tax Return¶
All prescribed due dates for filing of returns apply to e-file returns. All Providers must ensure that returns are promptly processed. A Provider that receives a return for electronic filing on or before the due date of the return (including extensions) must ensure that it transmits the electronic part of the return on or before the due date. An electronically filed return isn’t considered filed until the IRS acknowledges acceptance of the electronic part of the tax return for processing. The IRS accepts individual income tax returns electronically only if the taxpayer signs the return using a Personal Identification Number (PIN). If Providers transmit the electronic portion of a return on or shortly before the due date and the IRS ultimately rejects it, but the Provider and the taxpayer comply with the requirements for timely resubmission of a correct return, the IRS considers the return timely filed. For additional information about the filing of a return through IRS e-file, see “ Submitting the Electronic Return to the IRS .”
Transmitters may provide electronic postmarks to taxpayers for individual returns if the Transmitters follow the requirements stated in “ Chapter 4 – Transmission .” The receipt of an electronic postmark provides taxpayers with confidence that they have filed their return timely. The date of the electronic postmark is considered the date of filing when the date of electronic postmark is on or before the prescribed due date and the return is received by the IRS after the prescribed due date for filing. All requirements for signing the return and completing a paper declaration, if required, as well as for timely resubmitting of a rejected timely filed return, must be adhered to for the electronic postmark to be considered the date of filing.
Federal/State e-file¶
is a cooperative tax filing effort between the IRS and most states, which allows Providers to file federal and state returns electronically to IRS. The state return can be sent linked to the federal return (by including the Submission ID of the federal return in the state submission), or it can be sent unlinked (standalone). On linked returns, the federal return must be accepted before the linked state return can be filed. In addition to accepting federal and state individual income tax returns electronically in a single transmission, state-only returns are also accepted if the return:
• was previously rejected by the state;
• is originated separately from the federal return;
• is a part-year residency return;
• is a non-resident state return; or
• is a married filing separately state return, but the federal return was filed jointly.
The IRS provides state acknowledgment services. Participating states can send their acknowledgment to the IRS for Transmitters to pick up when they pick up their federal acknowledgment.
Adding Federal/State e-file to a Provider’s business is like the process it went through to become a Provider. Refer to Publication 3112 , IRS e-file Application and Participation, for further details. Also, the Provider should contact the state coordinators for the state programs in which it participates for further explanation of state rules and requirements.
7
Get a plain-English answer with a citation back to this text.
Ask AI about this code