Hawaii

Who Is Covered?

Any business that owns or licenses personal information of residents of Hawaii, any business that conducts business in Hawaii that owns or licenses personal information in any form (whether computerized, paper, or otherwise), or any government agency that collects personal information for specific government purposes. Haw. Rev. Stat. Ann. § 487N-2(a).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:

  1. Social security number;
  2. Driver’s license number or Hawaii identification card number; or
  3. Account number, credit or debit card number, access code, or password that would permit access to an individual’s financial account. Haw. Rev. Stat. Ann. § 487N-1.

What Is A “Breach”?

“Security breach” means an incident of unauthorized access to and acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred, or is reasonably likely to occur and that creates a risk of harm to a person. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key constitutes a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach; provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. Haw. Rev. Stat. Ann. § 487N-1.

“Records” means any material on which written, drawn, spoken, visual, or electromagnetic information is recorded or preserved, regardless of physical form or characteristics. Haw. Rev. Stat. Ann. § 487N-1.

What Triggers Notification?

Discovery or notification of a breach. Haw. Rev. Stat. Ann. § 487N-2(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system. Haw. Rev. Stat. Ann. § 487N-2(a).

Delivery: Notice may be made by:

  1. Written notice to the last available address the business or government agency has on record;
  2. Electronic mail notice, for those persons for whom a business or government agency has a valid electronic mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing set forth in 15 U.S.C. section 7001;
  3. Telephonic notice, provided that contact is made directly with the affected persons; and
  4. Substitute notice in certain circumstances. Haw. Rev. Stat. Ann. § 487N-2(e).

Content: The notice must be clear and conspicuous and include a description of:

  1. The incident in general terms;
  2. The type of personal information that was subject to the unauthorized access and acquisition;
  3. The general acts of the business or government agency to protect the personal information from further unauthorized access;
  4. A telephone number that the person may call for further information and assistance, if one exists; and
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. Haw. Rev. Stat. Ann. § 487N-2(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than one thousand persons at one time pursuant to this section, the business shall notify in writing, without unreasonable delay, the State of Hawaii’s office of consumer protection and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing, distribution, and content of the notice. Haw. Rev. Stat. Ann. § 487N-2(f).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

Any business that violates any provision of this chapter shall be subject to penalties of not more than $2,500 for each violation. The attorney general or the executive director of the office of consumer protection may bring an action pursuant to this section. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(a).

Additionally, any business that violates any provision of this chapter shall be liable to the injured party in an amount equal to the sum of any actual damages sustained by the injured party as a result of the violation. The court in any action brought under this section may award reasonable attorneys’ fees to the prevailing party. No such action may be brought against a government agency. Haw. Rev. Stat. Ann. § 487N-3(b).

Are There Any Exemptions/Exceptions?

Yes. The following are considered to be in compliance:

  1. A financial institution that is subject to the federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice published in the Federal Register on March 29, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, or subject to 12 C.F.R. Part 748, and any revisions, additions, or substitutions relating to the interagency guidance; and
  2. Any health plan or healthcare provider that is subject to and in compliance with the standards for privacy or individually identifiable health information and the security standards for the protection of electronic health information of the Health Insurance Portability and Accountability Act of 1996. Haw. Rev. Stat. Ann. § 487N-3(g).