| |

How to Securely Share Tax Documents With Clients

Compliance Guide, Dallas-Fort Worth

How to Securely Share Tax Documents With Clients (Without Using Email)

Email wasn’t built for this, and regulators have made that increasingly clear.

Quick Answer
Emailing tax documents as attachments, even password protected PDFs, doesn’t meet the encryption standards required by IRS Publication 4557 and the FTC Safeguards Rule, both of which mandate encryption of taxpayer data at rest and in transit. Standard email encrypts a message in transit at best, and never encrypts what sits in an inbox afterward. The compliant alternative is a secure client portal using AES-256 encryption at rest and TLS 1.3 in transit, with MFA, per-document access logs, and audit trails, features email simply cannot provide. Portal pricing typically runs $50 to $150 per user per month, and most firms complete a full rollout in about two weeks.

Why Email Doesn’t Meet the Bar, Even When It Feels Secure

Email is often described as the digital equivalent of a postcard. It travels through multiple servers, gets indexed by spam filters, and gets copied onto every device that ever opens it. Even when the connection between mail servers uses TLS encryption in transit, that protection doesn’t extend to the message once it lands and sits in an inbox indefinitely. A single compromised email account, the kind of account takeover we covered in our Business Email Compromise article, can expose years of attachments in one move. From an FTC and IRS audit perspective, email specifically fails in four ways:

No access logs. There’s no way to prove who actually opened or downloaded a document, or when.
No audit trail. If a client claims they never received a document, there’s no record to prove otherwise.
No automatic expiration. Documents remain sitting in an inbox indefinitely, with no way to revoke access later.
No granular permissions. Once a client has the attachment, they can forward it to anyone, with no way to stop it.
A common misconception: emailing an unencrypted tax document isn’t explicitly illegal in most cases, but it directly violates IRS Publication 4557’s requirement to encrypt taxpayer data in transit, and the FTC Safeguards Rule’s parallel requirement for financial institutions, a category that includes tax preparers. We cover this requirement in more detail in our FTC Safeguards Rule and WISP article.

What a Real Client Portal Needs to Actually Replace Email

1

End to End Encryption, at Rest and in Transit

Look specifically for AES-256 encryption for stored documents and TLS 1.3 for data in transit. This is what the IRS, NIST, and the FTC Safeguards Rule effectively mean when they reference “strong encryption.” A vendor who can’t confirm these specific standards by name has a gap worth asking about directly.

2

Multi-Factor Authentication

Both for staff logging in to manage documents and, ideally, for clients accessing their own files. Not just a username and password guarding a folder full of Social Security numbers.

3

Per-Document Access Logs and Audit Trails

A record of exactly who accessed which document and when. This is the single most cited gap during IRS Publication 4557 audits, and closing it is often the fastest compliance win available to a firm.

4

Configurable Retention and Expiration

The ability to set how long a document stays accessible and to revoke access when needed. Rather than a client’s inbox holding a copy of their W-2 indefinitely with no way for the firm to control it.

The Two Main Categories of Solutions

All-in-one practice management with a built-in portal. Platforms like Canopy, TaxDome, or Karbon combine document exchange with broader practice management (workflow, e-signatures, client communication) in a single system, often with direct integrations into tax software like UltraTax CS or Drake Tax.
Standalone secure file-sharing tools. Platforms like ShareFile focus specifically on encrypted document exchange without the full practice management layer, which can be a simpler fit for firms that already have workflow tools they’re happy with.

Either category can satisfy the compliance requirement. The right choice usually comes down to whether your firm wants document sharing bundled with broader practice management, or prefers to keep those systems separate.

Making the Switch Without Disrupting Clients

A full portal rollout typically takes about two weeks: select a vendor, configure it against your firm’s actual workflow, and set a firm policy prohibiting email attachments for tax documents going forward. A written policy statement is worth having on file specifically for audit purposes, something along the lines of: all client documents are exchanged through the portal, which provides encryption, MFA, and access logging, and email attachment of tax documents is prohibited by firm policy, verified periodically through audit log review.

A useful exercise before rolling this out: review the last 30 days of your sent email folder and count how many tax documents went out as attachments. Multiply that across a typical year of client touchpoints, and that’s the actual size of the compliance gap being closed.

A Side Benefit Worth Mentioning: Cyber Insurance

Portal usage has become a standard question on cyber insurance applications for accounting firms. As we cover in our article on cyber insurance costs for CPA firms, underwriters increasingly want proof of documented data handling controls, not just a checkbox answer. Beyond the compliance requirement itself, moving off email can meaningfully help with underwriting, one more reason this isn’t purely a defensive move, but one with a measurable return.

Don’t Forget Portal Access When Staff Leave

A secure portal only stays secure if access to it is managed as carefully as every other system in your firm. As covered in our employee offboarding checklist, portal logins should be added to your firm’s standard access revocation process the same day someone leaves, not treated as a separate system that gets checked later.

Why CPA Firms Choose Silver Storm Solutions

Cybersecurity-first approach FTC Safeguards Rule / WISP expertise
Proactive managed IT services Vendor evaluation and rollout support

We help firms select and roll out a secure client portal that fits their existing tax software and workflow, and document the policy behind it, so it holds up during an audit.

Frequently Asked Questions

Is a password-protected PDF sent by email good enough?

No. Password protection doesn’t provide the same encryption standard, access logging, or audit trail that a compliant portal offers, and the underlying email transmission problems, no expiration and no way to revoke access, remain unchanged.

Is emailing tax documents actually illegal?

Not explicitly illegal in most jurisdictions, but it violates IRS Publication 4557’s encryption in transit requirement and the FTC Safeguards Rule’s parallel requirement, which can result in IRS enforcement action, FTC penalties, and civil liability if a breach occurs.

How long does it take to roll out a secure client portal?

Most firms complete a full rollout, including vendor selection, configuration, and staff and client onboarding, in about two weeks, making it one of the fastest, highest-return compliance improvements available.

Does switching to a portal help with cyber insurance?

Often, yes. Secure portal usage has become a standard question on cyber insurance applications for accounting firms, and demonstrating compliant document handling can positively affect underwriting.

Still Emailing Tax Documents?

SilverStorm Solutions can help you select, configure, and roll out a compliant client portal in about two weeks.

Schedule a Technology Assessment

Related resources:
FTC Safeguards Rule & WISP Compliance: What CPA Firms Must Have in Place ,
Business Email Compromise: Why CPA Firms Are a Top Target ,

Similar Posts