Who Is Covered?
Any person who owns, licenses or maintains computerized data that includes personal information. Conn. Gen. Stat. § 36a-701b(a)(1).
What Information Is Protected?
“Personal information” means an individual’s (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; (ii) taxpayer identification number; (iii) identity protection personal identification number issued by the Internal Revenue Service; (iv) driver’s license number, state identification card number, passport number, military identification number or other identification number issued by the government that is commonly used to verify identity; (v) credit or debit card number; (vi) financial account number in combination with any required security code, access code or password that would permit access to such financial account; (vii) medical information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (viii) health insurance policy number or subscriber identification number, or any unique identifier used by a health insurer to identify the individual; or (ix) biometric information consisting of data generated by electronic measurements of an individual’s unique physical characteristics used to authenticate or ascertain the individual’s identity, such as a fingerprint, voice print, retina or iris image; or (B) user name or electronic mail address, in combination with a password or security question and answer that would permit access to an online account. Conn. Gen. Stat. § 36a-701b(a).
What Is A “Breach”?
“Breach of security” means unauthorized access to or unauthorized acquisition of electronic files, media, databases or computerized data, containing personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable. Conn. Gen. Stat. § 36a-701b(a)(1).
What Triggers Notification?
Discovery of the breach to any resident of this state whose personal information was breached or is reasonably believed to have been breached. Conn. Gen. Stat. § 36a-701b(b)(1).
Likelihood of Harm Analysis: However, notification is not required if, after an appropriate investigation and consultation with relevant federal, state and local agencies responsible for law enforcement, the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired and accessed. Conn. Gen. Stat. § 36a-701b(b)(1).
How Is Notice Provided To Individuals?
Timing: Notice shall be made without unreasonable delay but not later than sixty days after the discovery of such breach, unless a shorter time is required under federal law, subject to certain exceptions. Conn. Gen. Stat. § 36a-701b(b)(1).
Delivery: Notice may be provided by:
- Written notice;
- Telephone notice;
- Electronic notice consistent with the requirements of the E-Sign Act;
- Substitute notice, provided such person demonstrates that the cost of providing notice in accordance with subdivision (1), (2) or (3) of this subsection would exceed $250,000, that the affected class of subject persons to be notified exceeds 500,000 persons or that the person does not have sufficient contact information. Substitute notice shall consist of the following: a) Electronic mail notice when the person has an electronic mail address for the affected persons; b) conspicuous posting of the notice on the website of the person if the person maintains one; and c) notification to major statewide media, including newspapers, radio and television. Conn. Gen. Stat. § 36a-701b(e).
In the event of a breach of login credentials under subparagraph (B) of subdivision (2) of subsection (a) of this section, notice to a resident may be provided in electronic or other form that directs the resident whose personal information was breached or is reasonably believed to have been breached to promptly change any password or security question and answer, as applicable, or to take other appropriate steps to protect the affected online account and all other online accounts for which the resident uses the same user name or electronic mail address and password or security question and answer. Conn. Gen. Stat. § 36a-701b(f)(1).
Content: The notice must offer affected residents appropriate identity theft prevention services and, if applicable, identity theft mitigation services. Such service or services must be provided at no cost to such residents for a period of not less than 24 months. The notice must provide all information necessary for such residents to enroll in the service or services and include information on how such residents can place a credit freeze on their credit files. Conn. Gen. Stat. § 36a-701b(b)(2)(B).
Likelihood of Harm Exception: Notification is not required if, after an appropriate investigation the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired or accessed. Conn. Gen. Stat. § 36a-701b(a)(1).
Is Notice To The Government Required?
Yes. Notice of a breach of security must be provided to the Attorney General. Conn. Gen. Stat. § 36a-701b(b)(2)(A).
Is Notice To Credit Reporting Agencies Required?
No.
Are There Security Measure Standards?
No.
What Are The Possible Consequences Of A Violation?
Failure to comply with the requirements constitutes an unfair trade practice for purposes of section 42-110b and shall be enforced by the Attorney General. Conn. Gen. Stat. § 36a-701b(g).
Are There Any Exemptions/Exceptions?
Any person that maintains such person’s own security breach procedures as part of an information security policy for the treatment of personal information and otherwise complies with the timing requirements of this section, shall be deemed to be in compliance with the security breach notification requirements of this section, provided such person notifies, as applicable, residents of this state, owners and licensees in accordance with such person’s policies in the event of a breach of security and in the case of notice to a resident, such person also notifies the Attorney General not later than the time when notice is provided to the resident.
Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelines established by the primary or functional regulator, as defined in 15 U.S.C. 6809(2), shall be deemed to be in compliance with the security breach notification requirements of this section, provided (1) such person notifies, as applicable, such residents of this state, owners, and licensees required to be notified under and in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or functional regulator in the event of a breach of security, and (2) if notice is given to a resident of this state in accordance with subdivision (1) of this subsection regarding a breach of security, such person also notifies the Attorney General not later than the time when notice is provided to the resident. Conn. Gen. Stat. § 36a-701b(g).
Any person that is subject to and in compliance with the privacy and security standards under the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act (“HITECH”) shall be deemed to be in compliance with this section, provided that (1) any person required to provide notification to Connecticut residents pursuant to HITECH shall also provide notice to the Attorney General not later than the time when notice is provided to such residents if notification to the Attorney General would otherwise be required under subparagraph (A) of subdivision (2) of subsection (b) of this section, and (2) the person otherwise complies with the requirements of subparagraph (B) of subdivision (2) of subsection (b) of this section.Conn. Gen. Stat. § 36a-701b(h).
