Skip to content
Trust

Security program & incident reporting

NEXACC LLC is an IRS Authorized e-file Provider (EFIN 868369). The controls below are the ones the IRS asks online providers to certify each year, stated plainly so clients, partners, and the IRS can see exactly what is in place. Supporting documentation — the written Information Security Plan, scan reports, and incident records — is available on request.

TLS certificate with automatic renewal; HTTPS enforced on every page (HSTS)

Encrypted transport on every page

www.nexacc.com is served exclusively over HTTPS with a valid, publicly trusted TLS certificate covering the apex and www hosts. HTTP requests are redirected to HTTPS, certificates renew automatically before expiry, and the site is monitored for certificate validity. Form submissions, file uploads, and the client onboarding flow are never transmitted in the clear. Certificate details are verifiable in any browser via the padlock, or through a public certificate-transparency lookup for nexacc.com.

Automated security scan

Automated security scanning

Our public web properties are scanned for external vulnerabilities after significant releases. Scanning covers TLS configuration, exposed services, common web application weaknesses, and dependency-level vulnerabilities in the application's software bill of materials. Findings are triaged by severity, remediated, and re-tested; critical items are treated as same-day work. Scan reports and remediation records are retained and available to the IRS on request. Most recent automated security scan: 2026-08-31 — 0 open high or critical findings.

Information privacy and safeguard policies

Written Information Security Plan

NEXACC maintains a written Information Security Plan built on IRS Publication 4557, IRS Publication 1345, and the FTC Safeguards Rule, with a named security lead, an annual risk assessment, least-privilege access with multi-factor authentication, encryption in transit and at rest, row-level database access controls, vendor due-diligence terms, secure disposal procedures, and annual staff security training. Our public-facing privacy commitments, including IRC §7216 handling of tax return information and HIPAA Business Associate obligations, are published on the privacy page.

Read the Privacy & Safeguards Policy

Web site challenge-response test

Challenge-response on public forms

Every public form that collects contact details — contact, estimator, scheduling, and onboarding entry — requires a challenge-response test that a human can complete and an automated script cannot trivially pass. The challenge is accessible: it uses plain text, works with a screen reader and keyboard only, and requires no image recognition. It is paired with silent bot traps (also used on the single-field newsletter signup) and server-side validation, and repeated failures are rejected before any data is stored or emailed.

Public domain name registration

Publicly registered domain

nexacc.com is registered through GoDaddy.com, LLC and its registration data is publicly viewable through ICANN's registration data lookup: registrar, creation date (2021-08-21), expiry (2027-08-21), registry status codes, and authoritative name servers. Registrant contact details are currently served through the registrar's privacy service; we are switching that off so the registrant organization publishes as NEXACC LLC. Ownership is independently confirmable today through this site's published business details, EFIN listing, and BBB profile.

Look up nexacc.com in ICANN registration data

Security incidents reporting

Incident response and reporting

We maintain a documented incident response procedure: detect and contain, assess scope, preserve evidence, notify, remediate, and complete a written post-incident review. Any confirmed or suspected incident involving taxpayer data is reported to the IRS Stakeholder Liaison and, where applicable, to the appropriate IRS e-Help Desk, the FTC, state tax agencies, state attorneys general, and affected clients — within the timeframes those authorities require and without delay. HIPAA-covered incidents follow Breach Notification Rule timelines under our Business Associate Agreements.

Report a security incident

If you believe client data, taxpayer data, or a NEXACC account has been exposed, phished, or misused, tell us immediately. Reports are welcome from clients, partners, staff, and independent security researchers.

  1. 1Email info@nexacc.com with the subject line "SECURITY INCIDENT" or call +1 (443) 739-9197. Include what you observed, when, and any affected accounts or files.
  2. 2We acknowledge every report within one business day and open a tracked incident record immediately.
  3. 3We contain, investigate, and determine whether taxpayer data or protected health information was involved.
  4. 4Where taxpayer data is involved, we notify the IRS Stakeholder Liaison and other required authorities, and we notify affected clients directly.
  5. 5We deliver a written summary of cause, impact, and corrective action to affected clients once the incident is closed.

Taxpayers who suspect tax-related identity theft should also contact the IRS directly and review IRS Publication 4557 and the IRS Identity Theft Central guidance. Do not include Social Security numbers, bank credentials, or protected health information in your report.

HIPAA & data protection

Your patient data is handled under a documented HIPAA compliance program

Medical billing, credentialing, and revenue cycle work means we touch protected health information. We treat that as the core of the engagement, not an afterthought: signed BAAs, encrypted systems, least-privilege access, and audit trails you can inspect.

Business Associate Agreements

We execute a signed BAA with every covered entity before any PHI moves. Our subcontractors and hosting providers are held to downstream BAAs with the same obligations.

Encryption in transit and at rest

TLS 1.2+ on every connection and AES-256 encryption at rest for all stored records and documents. PHI is never emailed as an attachment — our team opens it through short-lived signed links inside the vault.

Least-privilege access control

Row-level database policies scope every record to the owning practice. Staff access is role-based, individually provisioned, reviewed quarterly, and revoked the same day someone leaves an engagement.

Audit logging and monitoring

Document access, administrative actions, and outbound notifications are written to immutable audit logs with actor, timestamp, and context, so a disclosure accounting request can be answered from records rather than memory.

Workforce training and sanctions

Annual HIPAA Privacy, Security, and Breach Notification training for everyone touching PHI, with confidentiality agreements, background checks, and a documented sanctions policy.

Safeguards and continuity

Written administrative, physical, and technical safeguards, encrypted backups with tested restores, minimum-necessary data handling, and a documented breach response with notification within 30 calendar days of discovery, well inside the 60-day HIPAA ceiling.

Tax-data safeguards

As an IRS Authorized e-file Provider (EFIN 868369), we maintain a written information security plan under IRS Publication 4557 and the FTC Safeguards Rule.

  • Written information security plan

    A documented WISP covering access control, data retention, disposal, vendor review and incident response, reviewed annually.

  • Multi-factor authentication everywhere

    MFA is required on every system that touches taxpayer data, including e-file software, email and the client portal.

  • Encrypted exchange and storage

    Returns, source documents and IDs move through the encrypted client portal — never plain email — and are encrypted at rest.

  • Least-privilege access and logging

    Only the preparer and reviewer on your engagement can open your file, and every access is written to an append-only audit log.

  • Retention and secure disposal

    Taxpayer records are retained per IRS requirements, then securely destroyed. You can request a copy or deletion at any time.

  • Identity-theft response

    If we suspect your tax data was exposed, we notify you, help file Form 14039 and coordinate with the IRS Identity Theft unit.

View our coverage & HIPAA safeguards certificate →

Text us on WhatsApp
TextInstagram