News & Analysis as of

Data Breach State Data Breach Notification Statutes

Troutman Pepper

Amendments Align Pennsylvania’s Breach Notification Law With Majority of States

Troutman Pepper on

Earlier this year, Governor Josh Shapiro signed amendments to Pennsylvania’s Breach of Personal Information Notification Act (BPINA) into law, which go into effect on September 26. As part of the implementation of these...more

Epiq

Cyber Incidents on the Rise: Tips for Effective Data Breach Notification

Epiq on

Cyber incidents have been growing at an exponential rate in recent years. A recent report from the Identity Theft Resource Center found that there were over one billion data breach victims in Q2 of 2024, which is around five...more

Sheppard Mullin Richter & Hampton LLP

Indiana Amends Breach Notification Law Along with New Adult Website Verification Requirement

Indiana recently amended its breach notification law to include as personal information age verification information collected by adult websites. At the same time, the state passed a new law for adult websites...more

BakerHostetler

Pennsylvania Makes Significant Changes to Its Data Breach Notification Law

BakerHostetler on

On June 28, 2024, Pennsylvania Governor Josh Shapiro signed an amendment to Pennsylvania’s Breach of Personal Information Notification Act into law. The amended law, which includes significant changes to the Keystone State’s...more

ArentFox Schiff

New State Privacy Laws Take Effect Beginning on July 1

ArentFox Schiff on

In the absence of a federal privacy bill, nearly 20 states have passed comprehensive privacy laws. On July 1, three of these states — Florida, Oregon, and Texas — have new laws going into effect, with Montana’s effective in...more

Holland & Knight LLP

New Tennessee Law Creates Heightened Liability Requirement for Class Action Data Breach Lawsuits

Holland & Knight LLP on

As courts have recognized, "[t]he fact that a company has suffered a security breach does not demonstrate that the company did not place significant emphasis on maintaining a high level of security."1 Nevertheless, companies...more

Nelson Mullins Riley & Scarborough LLP

FCC Updates Security Breach Rules for Telecommunications Service Breaches : Privacy Day Awareness

In the privacy world, confidential information relating to the nature, amount, or use of telecommunications services has always been subject to separate rules from other types of customer data. Prior to the advent of...more

Manatt, Phelps & Phillips, LLP

Balancing New Federal & State Cyber Reporting Rules on Health Care & Financial Services Industries

Balancing cybersecurity incident disclosures has been a challenge for those in the trenches for years. That has not changed, and recent regulatory activity should not alter the challenges breach counsel confront. In short,...more

BakerHostetler

Florida and Connecticut Expand Breach Laws to Include Geolocation Data as Personal Information

BakerHostetler on

Consistent with recent trends in broadening the scope of state data breach notification statutes, Connecticut and Florida have expanded the definitions of personal information under their respective data breach notification...more

Venable LLP

Data Breach Notice Requirement Added to Safeguards Rule for Non-bank Financial Institutions

Venable LLP on

Non-bank financial institutions will have a new data breach disclosure requirement effective May 13, 2024. The Federal Trade Commission (FTC) recently updated the Gramm-Leach-Bliley Safeguards Rule (“Safeguards Rule”), adding...more

Troutman Pepper

Cleanup on Aisle 1: Pennsylvania Grocer Rutters Latest to Settle Single-State Data Breach Investigation With Pennsylvania AG

Troutman Pepper on

Rutters, a prominent grocery chain in Pennsylvania with 80 locations statewide, settled a data breach investigation with Attorney General (AG) Michelle Henry’s office by agreeing to pay $1 million and to implement certain...more

Perkins Coie

2023 Breach Notification Law Update: Changes to Notification and Security Requirements Continue at State and Federal Levels

Perkins Coie on

A flurry of legislative activity over the past year has brought meaningful changes to a variety of privacy and security provisions in state and federal law. At the state level, as in 2022, we have seen a handful of changes to...more

Mintz - Privacy & Cybersecurity Viewpoints

Release of new Mintz Matrix! States keep tinkering

Several states have clarified or tightened their data breach notification statutes since we last updated the Mintz Matrix at the beginning of the year. Please click here for the latest edition of the Mintz Matrix, which is a...more

Foley & Lardner LLP

State Data Breach Notification Laws - September 2023

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Davis Wright Tremaine LLP

New Iowa Legislation Creates Cybersecurity Safe Harbor

Iowa becomes the fourth U.S. state to provide an affirmative defense for companies that adopt a cybersecurity framework - Iowa is the fourth state—following Ohio, Connecticut, and Utah—to provide a statutory incentive for...more

Davis Wright Tremaine LLP

Data Breach Notification Law Update: Texas

Texas amended its data breach notification law to significantly tighten the deadline for notifying the state attorney general (AG) of a data breach affecting 250 or more state residents. Senate Bill 768, which amended Section...more

Health Care Compliance Association (HCCA)

Five Years After ‘a Singular Human Error,’ Two Breach Notices, Revenue Firm Settles With OCR

Five Years After ‘a Singular Human Error,’ Two Breach Notices, Revenue Firm Settles With OCR - As far as settlements for alleged HIPAA violations go, a recent agreement announced by the HHS Office for Civil Rights (OCR)...more

Kohrman Jackson & Krantz LLP

Federal Court Rules No Common Law Duty to Prevent or Respond to Data Breaches

Like most healthcare entities, Indiana’s Trinity Health collects, stores, maintains and uses a large volume of particularly sensitive information about patients and others, including Personally Identifiable Information (PII)...more

Sheppard Mullin Richter & Hampton LLP

May 2nd Marks Effective Date of Pennsylvania Breach Law Amendments

As we wrote in November, Pennsylvania amended its data breach notification laws last year, and those changes go into effect tomorrow (May 2, 2023). Beginning tomorrow, if a breach of username/email accounts and their...more

Davis Wright Tremaine LLP

Data Breach Notification Law Update: Utah and Pennsylvania

For businesses subject to data breach notification requirements in Utah and Pennsylvania, a series of significant amendments will soon go into effect in both states. ...more

Foley & Lardner LLP

State Data Breach Notification Laws - March 2023

Foley & Lardner LLP on

While most state data breach notification statutes contain similar components, there are important differences, meaning a one-size-fits-all approach to notification will not suffice. What’s more, as data breaches continue to...more

Ankura

Ankura CTIX FLASH Update - January 2023 - 4

Ankura on

PayPal Discloses December 2022 Security Incident Involving Credential Stuffing Attacks - PayPal has begun sending out notification letters to individuals impacted by a security incident that occurred in early December...more

Lerman Senter PLLC

FCC Proposes Updated Data Breach Notification Requirements

Lerman Senter PLLC on

The Federal Communications Commission has released a Notice of Proposed Rulemaking (NPRM) seeking to modernize the data breach reporting requirements for customer proprietary network information (CPNI), which apply to all...more

Mintz - Privacy & Cybersecurity Viewpoints

FCC Proposes Changes to its Reporting Requirements for Customer Data Breaches

On December 28, 2022, the Federal Communications Commission (“FCC”) adopted a Notice of Proposed Rulemaking (“NPRM”) seeking to modernize and strengthen its rules to better protect consumers from the harm caused by breaches...more

Wyrick Robbins Yates & Ponton LLP

2022 Hindsight: Breach Notification Year in Review

While new comprehensive state privacy laws took most of the headlines this year, security threats and incident response remain key risk factors for privacy compliance programs and the subject of important legal developments....more

409 Results
 / 
View per page
Page: of 17

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide