Who Is Covered?
A person or [state] agency that owns or licenses data that are included in a database. Mich. Comp. Laws Serv. § 445.72(1).
What Information Is Protected?
“Personal information” means the first name or first initial and last name linked to one or more of the following data elements of a resident of Michigan:
- Social security number.
- Driver license number or state personal identification card number.
- Demand deposit or other financial account number, or credit card or debit card number, in combination with any required security code, access code, or password that would permit access to any of the resident’s financial accounts. Mich. Comp. Laws Serv. § 445.63(r).
What Is A “Breach”?
“Breach of the security of a database” or “security breach” means the unauthorized access and acquisition of data that compromises the security or confidentiality of personal information maintained by a person or agency as part of a database of personal information regarding multiple individuals. Mich. Comp. Laws Serv. § 445.63(b).
“Data” means computerized personal information. Mich. Comp. Laws Serv. § 445.63(e).
What Triggers Notification?
Discovery or notice of a security breach with respect to one or more residents of Michigan involving:
- That resident’s unencrypted and unredacted personal information was accessed and acquired by an unauthorized person.
- That resident’s personal information was accessed and acquired in encrypted form by a person with unauthorized access to the encryption key. Mich. Comp. Laws Serv. § 445.72(1).
Risk of Harm Analysis: Notice is not required if the person or agency determines that the security breach has not or is not likely to cause substantial loss or injury to, or result in identity theft with respect to, one or more residents of Michigan. Mich. Comp. Laws Serv. § 445.72(1).
How Is Notice Provided To Individuals?
Timing: Notice must be provided without unreasonable delay. Mich. Comp. Laws Serv. § 445.72(4)(b).
Delivery: Notice may be by:
- Written notice sent to the recipient at the recipient’s postal address in the records of the agency or person.
- Written notice sent electronically to the recipient if any of the following are met: (i) The recipient has expressly consented to receive electronic notice. (ii) The person or agency has an existing business relationship with the recipient that includes periodic electronic mail communications and based on those communications the person or agency reasonably believes that it has the recipient’s current electronic mail address. (iii) The person or agency conducts its business primarily through internet account transactions or on the internet.
- If not otherwise prohibited by state or federal law, notice given by telephone by an individual who represents the person or agency if all of the following are met: (i) The notice is not given in whole or in part by use of a recorded message. (ii) The recipient has expressly consented to receive notice by telephone, or if the recipient has not expressly consented to receive notice by telephone, the person or agency also provides notice under subdivision [1 or 2 above] if the notice by telephone does not result in a live conversation between the individual representing the person or agency and the recipient within three business days after the initial attempt to provide telephonic notice.
- Substitute notice, if the person or agency demonstrates that the cost of providing notice under subdivision [1, 2 or 3 above] will exceed $250,000 or that the person or agency has to provide notice to more than 500,000 residents of this state. Mich. Comp. Laws Serv. § 445.72(5).
Content: Notice shall do all of the following:
- For a notice provided in writing and sent by post or electronically, be written in a clear and conspicuous manner and contain the content required under subdivisions 3 to 7 below.
- For a notice provided telephonically, clearly communicate the content required under subdivisions 3 to 7 below to the recipient of the telephone call.
- Describe the security breach in general terms.
- Describe the type of personal information that is the subject of the unauthorized access or use.
- If applicable, generally describe what the agency or person providing the notice has done to protect data from further security breaches.
- Include a telephone number where a notice recipient may obtain assistance or additional information.
- Remind notice recipients of the need to remain vigilant for incidents of fraud and identity theft. Mich. Comp. Laws Serv. § 445.72(6).
Is Notice To The Government Required?
No.
Is Notice To Credit Reporting Agencies Required?
Yes. After a person or agency provides a notice under this section, the person or agency shall notify each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the security breach without unreasonable delay. A notification under this subsection shall include the number of notices that the person or agency provided to residents of this state and the timing of those notices. However, this notice is unnecessary if the breach involves 1,000 or fewer residents or the person or agency is subject to 15 U.S.C. 6801, et seq. Mich. Comp. Laws Serv. § 445.72(8).
Are There Security Measure Standards?
No. But separate from the breach notification law, Mich. Comp. Laws Serv. § 445.72a requires that a person or agency that maintains a database that includes personal information regarding multiple individuals shall destroy any data that contain personal information concerning an individual when that data is removed from the database and the person or agency is not retaining the data elsewhere for another purpose not prohibited by state or federal law. This subsection does not prohibit a person or agency from retaining data that contain personal information for purposes of an investigation, audit, or internal review. A person who knowingly violates this section is guilty of a misdemeanor punishable by a fine of not more than $250 for each violation. Mich. Comp. Laws Serv. § 445.72a(1), (2).
What Are The Possible Consequences Of A Violation?
A person that knowingly fails to provide any notice of a security breach required under this section may be ordered to pay a civil fine of not more than $250 for each failure to provide notice. The attorney general or a prosecuting attorney may bring an action to recover a civil fine under this section. The aggregate liability of a person for civil fines for multiple violations that arise from the same security breach shall not exceed $750,000. Mich. Comp. Laws Serv. § 445.72(13), (14).
Are There Any Exemptions/Exceptions
A financial institution that is subject to, and has notification procedures in place that are subject to examination by the financial institution’s appropriate regulator for compliance with, the interagency guidance on response programs for unauthorized access to customer information and customer notice prescribed by the board of governors of the Federal Reserve System and the other federal bank and thrift regulatory agencies, or similar guidance prescribed and adopted by the National Credit Union Administration, and its affiliates, is considered to be in compliance with this section. Mich. Comp. Laws Serv. § 445.72(9).
Also, a person or agency that is subject to and complies with HIPAA for the prevention of unauthorized access to customer information and customer notice is considered to be in compliance with this section. Mich. Comp. Laws Serv. § 445.72(10).
