Tax documents contain Social Security numbers, addresses, bank information, income, investments, and other data that can be valuable to identity thieves. Security should be part of how you evaluate a practice.
Prefer a secure client portal
A properly configured portal can provide encrypted transmission, controlled access, activity records, and multifactor authentication.
Ordinary email deserves caution
Email is convenient but can be forwarded, misaddressed, compromised, or retained across many systems. Ask the firm which information should never be sent through ordinary email.
Ask about multifactor authentication
MFA can reduce the risk that a stolen password alone gives an attacker access to tax documents.
Ask how long documents are retained
Understand whether the portal is simply an exchange mechanism or also a long-term document archive.
Do not upload sensitive records to a general contact form
Initial intake should collect enough information to evaluate fit without requesting Social Security numbers, full returns, or financial account numbers.