Wednesday, December 23, 2015

Refreshing Breach Notification - Legislation

About 33 states in 2015 introduced bill updates / addendums for security breach notifications to include reporting to attorney general or similar/central agency for items related to personal information such as biometric, medical and insurance data (and educational institutions to notify parents of breach occurrence).
This leaves only Alabama, New Mexico and South Dakota without breach notification.  Let’s take a peek at some notable states:

  • For Illinois, data to include geolocation information and privacy policies to be posted as per HB 3188 (amends pending).  Additionally, pending HB 3652 Personal Information Protection Act to cover private contact information and it’s transfer – although SB 1833 failed due to veto in September
  • California AB 259 requires breach notification related to SSN, driver’s license number or California card number to provide identity theft prevention and mitigation services for at least 12 months without fee.  AB739 (currently pending) cites breach notification if reasonably believed data has been acquired unless it was encrypted as per existing law according to AB 964.  And, SB 34 states proper protection / safeguards for the automated license plate recognition operators.  Finally, SB 570 expressing expedient breach notification upon compromised.
  • Hawaii SB 1186 prevents notification via email if login credentials were compromised
  • New York SB 4887 and Massachusetts SB  124 includes biometric information for security breach law
  • Tennessee HB 193 requires comptroller of the treasury notification for unauthorized acquisition of computerized data related to security, confidentiality, or integrity of compute information system
  • Virginia HB 2362 requires Chief Information Officer of the Commonwealth to develop protection and notification of confidential data maintained by state agencies for breach events / intrusion / unauthorized use / threats of electronic information
  • Nevada SB 72 requires Division of Enterprise Information Technology Services to investigate and resolve breach attempts of information systems related to agency or elected officer

Bills, amendments and regulatory requirements are being updated to keep up with breaches lessons learned, so the latest/approved bills should be confirmed with each state such as NCSL.ORG



36 comments:

  1. The King Casino | Ventureberg
    Discover the rise sol.edu.kg and fall of the king ventureberg.com/ casino, one of the world's largest The Casino is operated by https://febcasino.com/review/merit-casino/ the King Casino herzamanindir.com/ Group. You can https://tricktactoe.com/

    ReplyDelete
  2. E15D8
    ----
    matadorbet
    ----
    ----
    ----
    ----
    ----
    ----
    ----

    ReplyDelete
  3. C47FBDF987CalvinD710A535FFOctober 16, 2024 at 4:56 PM

    A411E00CF1
    fuar standi

    ReplyDelete
  4. 592BDEFA19Natalie710596103BNovember 26, 2024 at 7:22 PM

    FFC33F929A
    begeni satin al

    ReplyDelete