The IRS just kicked off its "Protect Your Clients; Protect Yourself" campaign. Five weeks, one theme: tax pros are the #1 target for identity thieves right now. Not because we're careless. Because we sit on exactly what they want, in one place, for hundreds of people. Here's what I'm doing this week to tighten things up, and what I'd check if I were you: 1. Who actually has access to your client files? Not "who's supposed to have access." Pull the actual list. Former employees, old contractors, that one login you meant to deactivate in March. If you can't answer this in under two minutes, that's your first fix. 2. Is MFA on for every login that touches client data? Software, email, cloud storage, portal. Not just the ones that nag you about it. One unprotected login is the only door a thief needs. 3. Do you have a written data theft response plan? Not in your head. Written. If your systems got compromised tomorrow, would you know who to call first (it's your local IRS Stakeholder Liaison, not the media)? Most firms find out they don't have a plan the same day they need one. 4. Are you actually encrypting what you send, or just assuming your software does it? Check. Don't assume. None of this is glamorous. It's also the difference between a bad week and losing your PTIN, your clients' trust, and possibly your practice. Drop in the comments: what's one gap you found when you actually checked? (Full five-week checklist here: https://www.irs.gov/tax-professionals/protect-your-clients-protect-yourself. Worth the ten minutes.)