TIGTA recommends IRS address security vulnerabilities for ACA reporting

Sovos
December 10, 2014

The U.S. Treasury Inspector General of Tax Administration (TIGTA) has published a report detailing weaknesses in the IRS system for collecting tax information returns related to the Affordable Care Act (ACA). Specifically, TIGTA examined the ACA Information Returns (AIR) Release 1 Project.

TIGTA generated the report to determine how well the IRS can mitigate risk in regard to ACA reporting. This included issues relating to fraud detection, security and testing. Based upon security assessments conducted by the IRS, TIGTA provided several recommendations for how the agency’s chief technology officer should address weaknesses found within AIR.

Here are a few of TIGTA’s suggestions:

  • There should be systems in place to find and mitigate risks. Additionally, the IRS should run vulnerability scans on all databases.
  • Current vulnerabilities must be immediately resolved.
  • The agency must develop ACA plans of action and milestones to ensure the risks are mitigated within required timeframes.
  • Third-party contractors that conduct testing processes must be managed by the IRS information technology testing and implementation organization.

The IRS did not agree with TIGTA’s assessment in all regards. However, it did issue a statement to demonstrate its commitment to developing more secure systems and addressing vulnerabilities. 

“The IRS is committed to ensuring the security of our information technology systems and maintaining appropriately configured databases,” the IRS said. “[TIGTA’s] report acknowledges our security practices and makes several recommendations that upon implementation, will contribute to our shared objective of identifying and mitigating security vulnerabilities.”

The importance of securing taxpayer data
Though the TIGTA report focused on the IRS, it points to the importance of protecting taxpayer data as it is transmitted for the health care law’s new tax information reporting requirements. Insurers, large employers and self-insured employers must all ensure they have a secure system in place for collecting necessary data that is to be furnished to the IRS.

This is particularly true as more consumers become concerned about their data, and there is a growing risk of breaches. Additionally, experts predict there will be a large-scale breach in 2015 that will give more attention to the necessity of information security for consumer health care information, according to EHR Intelligence.

Furthermore, several new tax forms were introduced and organizations are scrambling to determine which department will be responsible for ACA reporting. There is general confusion about the health care law’s provisions; therefore, employers and insurers should take steps now to ensure accurate reporting that doesn’t put member information at risk.

Check out our education section for more about ACA reporting requirements for insurerslarge employers and self-insured employers.

Sign up for Email Updates

Stay up to date with the latest tax and compliance updates that may impact your business.

Author

Sovos

Sovos is a global provider of tax, compliance and trust solutions and services that enable businesses to navigate an increasingly regulated world with true confidence. Purpose-built for always-on compliance capabilities, our scalable IT-driven solutions meet the demands of an evolving and complex global regulatory landscape. Sovos’ cloud-based software platform provides an unparalleled level of integration with business applications and government compliance processes. More than 100,000 customers in 100+ countries – including half the Fortune 500 – trust Sovos for their compliance needs. Sovos annually processes more than three billion transactions across 19,000 global tax jurisdictions. Bolstered by a robust partner program more than 400 strong, Sovos brings to bear an unrivaled global network for companies across industries and geographies. Founded in 1979, Sovos has operations across the Americas and Europe, and is owned by Hg and TA Associates.
Share this post

North America
June 6, 2024
Observations and Predictions: The Future of Tax and Compliance

When I became the CEO of Sovos one year ago, I knew that I was stepping into an innovative company in an industry primed for a seismic transformation. However, even with this knowledge in place, I must admit that the speed and scope of change over the past year has been extraordinary to witness. Here […]

EMEA IPT
July 8, 2024
Hungary Insurance Premium Tax (IPT): An Overview

Regarding calculating Insurance Premium Tax (IPT), Hungary is the only country in the EU where the regime uses the so-called sliding scale rate model.

North America ShipCompliant
July 3, 2024
The Prospects and Perils of AI in Beverage Alcohol

I recently had the privilege of speaking on a panel at the National Conference of State Liquor Administrators (NCSLA) Annual Conference, a regular meeting of regulators, attorneys and other members of the beverage alcohol industry to discuss important issues affecting our trade. Alongside Claire Mitchell, of Stoel Rives, and Erlinda Doherty, of Vinicola Consulting, and […]

North America ShipCompliant
June 27, 2024
Shifting Focus: How to Make Wine Country Interesting to Millennials

Guest blog written by Susan DeMatei, President, WineGlass Marketing WineGlass Marketing recently conducted a study to explore how Millennials and Gen X feel about wine, wine culture and wine country. The goal was to gain insight into how we can make wine, wine club and wine country appealing to these new audiences. We’ll showcase in-depth […]

North America Sales & Use Tax
June 24, 2024
Illinois to Adjust Sales Tax Nexus Rules in Light of PetMeds Threat

Illinois is poised to change their sourcing rules again, trying to find their way in a world where states apply their sales tax compliance requirements equally to both in-state and remote sellers. With this tweak, they will effectively equalize the responsibilities of remote sellers with no in-state presence, to those that have an Illinois location. […]

EMEA VAT & Fiscal Reporting
June 21, 2024
ViDA Rejected Again – Europe Misses Another Chance to Harmonize e-Invoicing

During the latest ECOFIN meeting on 21 June, Member States met to discuss if they could come to an agreement to implement the VAT in the Digital Age (ViDA) proposals. At the ECOFIN meeting in May, Estonia objected to the platform rules being proposed, instead requesting to make the new deemed supplier rules optional (an […]