How to Securely Share Tax Documents With Clients
How to Securely Share Tax Documents With Clients (Without Using Email)
Email wasn’t built for this, and regulators have made that increasingly clear.
Emailing tax documents as attachments, even password protected PDFs, doesn’t meet the encryption standards required by IRS Publication 4557 and the FTC Safeguards Rule, both of which mandate encryption of taxpayer data at rest and in transit. Standard email encrypts a message in transit at best, and never encrypts what sits in an inbox afterward. The compliant alternative is a secure client portal using AES-256 encryption at rest and TLS 1.3 in transit, with MFA, per-document access logs, and audit trails, features email simply cannot provide. Portal pricing typically runs $50 to $150 per user per month, and most firms complete a full rollout in about two weeks.
Why Email Doesn’t Meet the Bar, Even When It Feels Secure
Email is often described as the digital equivalent of a postcard. It travels through multiple servers, gets indexed by spam filters, and gets copied onto every device that ever opens it. Even when the connection between mail servers uses TLS encryption in transit, that protection doesn’t extend to the message once it lands and sits in an inbox indefinitely. A single compromised email account, the kind of account takeover we covered in our Business Email Compromise article, can expose years of attachments in one move. From an FTC and IRS audit perspective, email specifically fails in four ways:
What a Real Client Portal Needs to Actually Replace Email
| 1 |
End to End Encryption, at Rest and in TransitLook specifically for AES-256 encryption for stored documents and TLS 1.3 for data in transit. This is what the IRS, NIST, and the FTC Safeguards Rule effectively mean when they reference “strong encryption.” A vendor who can’t confirm these specific standards by name has a gap worth asking about directly. |
| 2 |
Multi-Factor AuthenticationBoth for staff logging in to manage documents and, ideally, for clients accessing their own files. Not just a username and password guarding a folder full of Social Security numbers. |
| 3 |
Per-Document Access Logs and Audit TrailsA record of exactly who accessed which document and when. This is the single most cited gap during IRS Publication 4557 audits, and closing it is often the fastest compliance win available to a firm. |
| 4 |
Configurable Retention and ExpirationThe ability to set how long a document stays accessible and to revoke access when needed. Rather than a client’s inbox holding a copy of their W-2 indefinitely with no way for the firm to control it. |
The Two Main Categories of Solutions
Either category can satisfy the compliance requirement. The right choice usually comes down to whether your firm wants document sharing bundled with broader practice management, or prefers to keep those systems separate.
Making the Switch Without Disrupting Clients
A full portal rollout typically takes about two weeks: select a vendor, configure it against your firm’s actual workflow, and set a firm policy prohibiting email attachments for tax documents going forward. A written policy statement is worth having on file specifically for audit purposes, something along the lines of: all client documents are exchanged through the portal, which provides encryption, MFA, and access logging, and email attachment of tax documents is prohibited by firm policy, verified periodically through audit log review.
A Side Benefit Worth Mentioning: Cyber Insurance
Portal usage has become a standard question on cyber insurance applications for accounting firms. As we cover in our article on cyber insurance costs for CPA firms, underwriters increasingly want proof of documented data handling controls, not just a checkbox answer. Beyond the compliance requirement itself, moving off email can meaningfully help with underwriting, one more reason this isn’t purely a defensive move, but one with a measurable return.
Don’t Forget Portal Access When Staff Leave
A secure portal only stays secure if access to it is managed as carefully as every other system in your firm. As covered in our employee offboarding checklist, portal logins should be added to your firm’s standard access revocation process the same day someone leaves, not treated as a separate system that gets checked later.
Why CPA Firms Choose Silver Storm Solutions
| Cybersecurity-first approach | FTC Safeguards Rule / WISP expertise |
| Proactive managed IT services | Vendor evaluation and rollout support |
We help firms select and roll out a secure client portal that fits their existing tax software and workflow, and document the policy behind it, so it holds up during an audit.
Frequently Asked Questions
Is a password-protected PDF sent by email good enough?
No. Password protection doesn’t provide the same encryption standard, access logging, or audit trail that a compliant portal offers, and the underlying email transmission problems, no expiration and no way to revoke access, remain unchanged.
Is emailing tax documents actually illegal?
Not explicitly illegal in most jurisdictions, but it violates IRS Publication 4557’s encryption in transit requirement and the FTC Safeguards Rule’s parallel requirement, which can result in IRS enforcement action, FTC penalties, and civil liability if a breach occurs.
How long does it take to roll out a secure client portal?
Most firms complete a full rollout, including vendor selection, configuration, and staff and client onboarding, in about two weeks, making it one of the fastest, highest-return compliance improvements available.
Does switching to a portal help with cyber insurance?
Often, yes. Secure portal usage has become a standard question on cyber insurance applications for accounting firms, and demonstrating compliant document handling can positively affect underwriting.
Still Emailing Tax Documents?
SilverStorm Solutions can help you select, configure, and roll out a compliant client portal in about two weeks.
Related resources:
FTC Safeguards Rule & WISP Compliance: What CPA Firms Must Have in Place ,
Business Email Compromise: Why CPA Firms Are a Top Target ,
