Skip to content
HexaTransfer
Back to blog
Productivity & Collaboration

Secure File Sharing for Accountants and CPAs

Exchange financial documents securely with clients. Compliance-ready file sharing solutions for accountants, CPAs, and bookkeepers.

Accountants and CPAs exchanging W-2s, K-1s, 1099s, and audited financials need IRS-compliant secure portals — not email attachments. The practical stack: a tax client portal like SmartVault, Canopy, or TaxDome ($50 to $100/user/month), an E2EE ad-hoc transfer tool like HexaTransfer or Tresorit Send for one-off sends, and PDF password protection on every deliverable. IRS Publication 4557 requires tax preparers to protect taxpayer data with "reasonable safeguards," and the FTC Safeguards Rule (amended 2023) now mandates encryption of customer information in transit and at rest for any firm with 5,000+ client records.

IRS Publication 4557 and the FTC Safeguards Rule

Publication 4557 ("Safeguarding Taxpayer Data") requires all tax professionals to maintain a written information security plan (WISP), encrypt sensitive data, use MFA, and report breaches to the IRS Stakeholder Liaison. Since 2023, firms must also appoint a Qualified Individual to oversee the program.

The FTC Safeguards Rule applies to any "financial institution," which the FTC interprets broadly — tax preparers, CPAs with bookkeeping services, and financial planners all qualify. Key 2023 amendments:

  • MFA on all systems accessing customer information
  • Encryption of all customer information in transit and at rest
  • Written incident response plan
  • Regular penetration testing or continuous monitoring
  • Annual board-level reports for firms with 5,000+ records

Non-compliance triggers FTC enforcement and reputational damage. A breach involving taxpayer data also obliges notification to affected clients, the IRS, and state AGs.

Client Portals Built for Tax Workflows

Generic file-sharing tools miss tax-specific features: year-over-year folder structures, engagement letters, e-signatures on 8879s, and integration with tax prep software. Purpose-built portals:

  • SmartVault: $20 to $70/user/month, tight integration with Lacerte, ProSeries, UltraTax, Drake
  • TaxDome: $50 to $100/user/month, all-in-one practice management plus portal
  • Canopy: similar pricing, strong on task workflows
  • Intuit Link: free with Lacerte and ProConnect, limited to Intuit users
  • Securefilepro: bundled with CCH Axcess, tight CCH integration
  • ShareFile (Citrix, now part of Progress): $50 to $120/user/month, strong compliance posture

Pick based on your prep software and size. Solo and small-firm practitioners fit TaxDome or SmartVault. Mid-size firms running CCH or Thomson Reuters fit Securefilepro or a dedicated ShareFile tenant.

Collecting Source Documents From Clients

Tax season demands a steady intake of W-2s, 1099s, mortgage statements, brokerage 1099-Bs, K-1s, and receipts. Clients vary widely in tech comfort. Design the collection flow for the lowest common denominator:

  • Email clients a portal invite with a single-sentence instruction: "Click this link, upload your W-2."
  • Accept mobile uploads (most portals have client apps)
  • Don't require client account creation for one-time senders — use a branded upload page
  • Provide a drag-and-drop bulk uploader for clients with 20+ documents
  • Never accept source documents via unencrypted email (even if the client insists)

For clients who refuse to use the portal, have a pre-written response: "For your protection, we can't accept tax documents by email. Please use this secure link instead." Include the link in every reminder.

Delivering Tax Returns and Engagement Documents

The finished 1040, state return, and supporting workpapers are highly sensitive. Package them in a PDF with a password the client knows (commonly last 4 of SSN, which is a weak default — prefer a passphrase from the engagement letter).

Deliverable package typically includes:

  • Client copy of federal and state returns (.pdf, 30 to 200 pages, 2 to 20 MB)
  • 8879 e-file authorization forms (sent separately for signature)
  • Invoice
  • Planning memo or notes for next year
  • Tax payment vouchers if balances due

For 8879 and similar signature requirements, use an IRS-compliant e-signature provider: Docusign, Adobe Acrobat Sign, or the signature tools in TaxDome/SmartVault. KBA (knowledge-based authentication) is required by IRS rules for remote e-signature on 8879.

Handling K-1s, 1099s, and Multi-Party Distributions

Partnerships and S-corps distribute K-1s to dozens or hundreds of partners. Mailing paper K-1s is expensive and slow. Electronic delivery is allowed if the partner consents and receives specific disclosures.

Workflow for mass K-1 distribution:

  1. Generate individual K-1 PDFs from Lacerte, UltraTax, or CCH
  2. Password-protect each PDF with a partner-specific password
  3. Upload to your portal or send via secure transfer
  4. Notify each partner with a standard email template
  5. Track delivery and download receipts for audit purposes

For 1099 filing to recipients, you can deliver electronically with consent. Services like Track1099, Yearli, or Tax1099 handle both IRS filing and recipient delivery through secure portals.

Audit-Ready File Retention

Tax preparer retention requirements vary:

  • Circular 230 (for EAs, CPAs, attorneys practicing before IRS): 3 years from return filing
  • AICPA professional standards: 7 years for most workpapers
  • State CPA boards: often 7 years
  • Specific engagements (audit, attest): retention tied to the engagement contract

Practical policy: keep everything for 7 years, then archive to cold storage (Backblaze B2 at $6/TB/month) for an additional 3 years, then delete per your retention policy. Document the policy in your WISP.

The retention copy must itself be protected. Encrypted archives on encrypted drives, stored offsite with access logs. A stolen backup drive containing seven years of tax returns is a breach.

Engagement Letter Clauses That Match Your Tools

Your engagement letter is the contractual bridge between your security controls and client obligations. Include:

  • A section authorizing electronic delivery of tax documents
  • Named channel (client portal URL or specific transfer service)
  • Client's consent to use of named cloud providers for document storage
  • Language assigning responsibility for password secrecy
  • Client's agreement to notify you within 48 hours of any suspected compromise

Without these clauses, a client who emails their W-2 in the clear and gets phished has grounds to argue you should have stopped them. With them, you've documented a shared responsibility model.

Incident Response When the Inevitable Happens

Even well-secured firms face phishing, ransomware, and malicious insiders. Your incident response plan (IRP) should cover:

  1. Immediate containment: disconnect affected machines, rotate credentials
  2. Assessment: which client records were accessed
  3. Notification to the IRS: phone the Stakeholder Liaison within hours
  4. Notification to state AGs: timing varies by state (10 to 60 days typical)
  5. Notification to clients: clear, factual, with guidance on credit monitoring
  6. Offer credit monitoring: usually IdentityForce, Experian, or Equifax, 12 to 24 months
  7. Post-incident review: root cause, remediation plan, WISP update

Cyber insurance for small CPA firms typically runs $1,500 to $4,000/year for $1M coverage. The policy often covers notification costs, credit monitoring, and forensics — which vastly exceed any realistic payout.

A Realistic Stack for a 5-Person CPA Firm

  • Tax prep: Drake Tax, UltraTax CS, or Lacerte
  • Client portal: SmartVault or TaxDome
  • E-signature: bundled with portal or Docusign
  • Ad-hoc transfers: encrypted transfer tool for one-offs
  • Password manager: 1Password Business
  • Backup: Datto, iDrive, or Acronis
  • Cyber insurance: $1M policy
  • Annual WISP review: required under Pub 4557

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file