The Internal Revenue Service (IRS) has issued a Request for Information (RFI) for Identity Protection and Identity Monitoring Services to enhance safeguards against identity theft and address future taxpayer data breaches. This RFI, dated November 14, 2024, aims to gather information from firms capable of providing comprehensive identity monitoring beyond traditional credit report monitoring, including fraud detection from various data sources. The government seeks a contractor to deliver continuous identity protection for three years post-breach occurrence, supporting varying scales of data breaches—from minor to catastrophic incidents.
The RFI requires responses in two parts: company profiling and capability details. Firms must provide organizational information and responses addressing their capacity to handle the designated levels of breaches, pricing structures, customer support services, and available identity protection features. The document emphasizes that responses are for market research only and not binding, with no proposals or bids expected at this stage. This initiative aligns with federal mandates for safeguarding Personally Identifiable Information (PII) as informed by OMB guidelines. Overall, the RFI underscores the IRS's commitment to strengthening identity protection measures amid growing cybersecurity threats.
The document outlines a Performance Work Statement (PWS) for Identity Protection and Identity Monitoring services, aimed at safeguarding individuals whose Personally Identifiable Information (PII) may be compromised, in compliance with federal guidelines. The contractor is tasked with providing continuous monitoring of PII across various platforms beyond credit reports, offering comprehensive identity theft assistance for a three-year period following a breach notification. Key services include customer support available 24/7, a detailed identity theft resolution process, and continuous credit and PII monitoring.
The scope includes ensuring security through administrative, technical, and physical measures, and the contractor must accommodate both minor and major data breaches. Performance requirements entail regular enrollment reporting, swift provisioning of unique identifiers, and maintaining a Quality Control Plan to ensure service standards. The document specifies deliverables and timelines, emphasizing timely and precise reporting while adhering to federal cybersecurity methods. This PWS reflects the government’s commitment to preventing identity theft and providing affected individuals with support and protection measures.