Pennsylvania

Who Is Covered?

An entity that maintains, stores or manages computerized data that includes personal information. 73 Pa. Stat. Ann. § 2303(a).

 

What Information Is Protected?

“Personal information” is an individual’s first name or first initial and last name in combination with and linked to any one or more of the following data elements when the data elements are not encrypted or redacted:

 

  1. Social security number.
  2. Driver’s license number or a State identification card number issued in lieu of a driver’s license.
  3. Financial account number, credit or debit card number, in combination with any required security code, access code or password that would permit access to an individual’s financial account.
  4. Medical information in the possession of a State agency or State agency contractor..
  5. Health insurance information.
  6. A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account.73 Pa. Stat. Ann. § 2302.

 

What Is A “Breach”?

“Breach of the Security of the System.” The unauthorized access and acquisition of computerized data that materially compromises the security or confidentiality of personal information maintained by the entity as part of a database of personal information regarding multiple individuals and that causes or the entity reasonably believes has caused or will cause loss or injury to any resident of this Commonwealth. Good faith acquisition of personal information by an employee or agent of the entity for the purposes of the entity is not a breach of the security of the system if the personal information is not used for a purpose other than the lawful purpose of the entity and is not subject to further unauthorized disclosure. 73 Pa. Stat. Ann. § 2302.

 

What Triggers Notification?

The determination of the breach of the security of the system involving a resident of Pennsylvania whose unencrypted and unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person. 73 Pa. Stat. Ann. § 2303(a).

 

How Is Notice Provided To Individuals?

Timing: Notice shall be made without unreasonable delay except as necessary to meet the needs of law enforcement or in order to take any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the data system. 73 Pa. Stat. Ann. § 2303(a).

Delivery: Notice may be by:

 

  1. Written notice to the last known home address for the individual.
  2. Telephonic notice, if the customer can be reasonably expected to receive it and the notice is given in a clear and conspicuous manner, describes the incident in general terms and verifies personal information but does not require the customer to provide personal information and the customer is provided with a telephone number to call or Internet website to visit for further information or assistance.
  3. Email notice, if a prior business relationship exists and the person or entity has a valid email address for the individual.
  4. Electronic notice, if the notice directs the person whose personal information has been materially compromised by a breach of the security of the system to promptly change the person’s password and security question or answer, as applicable or to take other steps appropriate to protect the person’s online account to the extent the entity has sufficient contact information for the person.
  5. Substitute notice, if the entity demonstrates one of the following: a) The cost of providing notice would exceed $100,000; b) The affected class of subject persons to be notified exceeds 175,000; or c) The entity does not have sufficient contact information.

Substitute notice shall consist of all of the following: 

 

  1. Email notice when the entity has an email address for the subject persons.
  2. Conspicuous posting of the notice on the entity’s Internet website if the entity maintains one.
  3. Notification to major statewide media. 73 Pa. Stat. Ann. § 2302.

Content: None specified.

 

Is Notice To The Government Required?

Yes, if notice must be given to more than 500 individuals in Pennsylvania. Notice to the Attorney General must include the following information to the extent known by the notifying entity:

1. The organization name and location.
2. The date of the breach.
3. A summary of the breach incident.
4. An estimated total number of individuals affected.
5. An estimated total number of individuals in Pennsylvania affected.

 

Is Notice To Credit Reporting Agencies Required?

Yes. When an entity provides notification under this act to more than 500 persons at one time, the entity shall also notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in section 603 of the Fair Credit Reporting Act (Public Law 91-508, 15 U.S.C. § 1681a), of the timing, distribution and number of notices. 73 Pa. Stat. Ann. § 2305.

 

Are There Security Measure Standards?

Yes, for entities that maintain, store or manage computerized data on behalf of the Commonwealth that constitutes personal information.  Such entities must utilize encryption, or other appropriate security measures, to reasonably protect the transmission of personal information over the Internet from being viewed or modified by an unauthorized third party. 73 P.S. § 2305a(a).

 

What Are The Possible Consequences Of A Violation?

A violation of this act shall be deemed to be an unfair or deceptive act or practice in violation of the Unfair Trade Practices and Consumer Protection Law. The Office of Attorney General shall have exclusive authority to bring an action under the Unfair Trade Practices and Consumer Protection Law for a violation of this act. 73 Pa. Stat. Ann. § 2308

Entities that are required to report the incident to consumer reporting agencies must assume the costs of providing the affected individuals with access to one credit report if an individual is not otherwise eligible for a free report, and access to credit monitoring services for 1 year.

 

Are There Any Exemptions/Exceptions?

Yes. Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic personal health information established under the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191, 110 Stat. 1936) and the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5, 123 Stat. 226-279 and 467-496) shall be deemed to be in compliance with the provisions of this act.

Also, the following entities will be deemed to be in compliance:

 

  1. An entity that maintains its own notification procedures as part of an information privacy or security policy for the treatment of personal information and is consistent with the notice requirements of this act shall be deemed to be in compliance with the notification requirements of this act if it notifies subject persons in accordance with its policies in the event of a breach of security of the system. 
  2. A financial institution that complies with the notification requirements prescribed by the Federal Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice is deemed to be in compliance with this act. 
  3. An entity, a State agency or a State agency’s contractor, that complies with the notification requirements or procedures pursuant to the rules, regulations, procedures or guidelines established by the entity’s, State agency’s or State agency’s contractor’s primary State or functional Federal regulator, shall be in compliance with this act. 73 Pa. Stat. Ann. § 2307.