Tag Archives: Illinois

Illinois

Who Is Covered?

“Data Collector” may include, but is not limited to, government agencies, public and private universities, privately and publicly held corporations, financial institutions, retail operators, and any other entity that, for any purpose, handles, collects, disseminates, or otherwise deals with nonpublic personal information. 815 Ill. Comp. Stat. Ann. 530/5.

What Information Is Protected?

“Personal information” means either of the following:

A. User name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security.

B. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the name or data elements have been acquired without authorization through the breach of security:

  1. Social security number.
  2. Driver’s license number or state identification card number.
  3. Account number or credit or debit card number, or an account number or credit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account.
  4. Medical information.*
  5. Health insurance information.**
  6. Unique biometric data generated from measurements or technical analysis of human body characteristics used by the owner or licensee to authenticate an individual, such as a fingerprint, retina or iris image, or other unique physical representation or digital representation of biometric data. 815 Ill. Comp. Stat. Ann. 530/5.

*“Medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a healthcare professional, including such information provided to a website or mobile application. 815 Ill. Comp. Stat. Ann. 530/5.

**“Health insurance information” means an individual’s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual, or any medical information in an individual’s health insurance application and claims history, including any appeals records. 815 Ill. Comp. Stat. Ann. 530/5.

What Is A “Breach”?

“Breach of the security of the system data” or “breach” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the data collector. “Breach of the security of the system data” does not include good faith acquisition of personal information by an employee or agent of the data collector for a legitimate purpose of the data collector, provided that the personal information is not used for a purpose unrelated to the data collector’s business or subject to further unauthorized disclosure. 815 Ill. Comp. Stat. Ann. 530/5.

What Triggers Notification?

Discovery or notification of a breach. 815 Ill. Comp. Stat. Ann. 530/10(a).

How Is Notice Provided To Individuals?

Timing: The disclosure notification shall be made in the most expedient time possible and without unreasonable delay, consistent with any measures necessary to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. 815 Ill. Comp. Stat. Ann. 530/10(a).

Delivery: Notification may be made by:

  1. Written notice;
  2. Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing as set forth in Section 7001 of Title 15 of the United States Code; or
  3. Substitute notice, in certain circumstances. 815 Ill. Comp. Stat. Ann. 530/10(c).

Content: The notice must include:

  1. The toll-free numbers and addresses for consumer reporting agencies;
  2. The toll-free number, address, and website address for the Federal Trade Commission; and
  3. A statement that the individual can obtain information from these sources about fraud alerts and security freezes. 815 Ill. Comp. Stat. Ann. 530/10(a)(1).

If the breach involves a user name or email address, in combination with a password or security question and answer that would permit access to an online account, when either the user name or email address or password or security question and answer are not encrypted or redacted or are encrypted or redacted but the keys to unencrypt or unredact or otherwise read the data elements have been obtained through the breach of security, notice may be provided in electronic or other form directing the Illinois resident whose personal information has been breached to promptly change his or her user name or password and security question or answer, as applicable, or to take other steps appropriate to protect all online accounts for which the resident uses the same user name or email address and password or security question and answer. 815 Ill. Comp. Stat. Ann. 530/10(a)(2).

Is Notice To The Government Required?

Yes. If notice must be sent to more than 500 Illinois residents as a result of a single breach, notification must also be sent to the Attorney General in the most expedient time possible and without unreasonable delay but in no event later than when the data collector provides notice to consumers. The notice must include:

  1. A description of the nature of the breach of security or unauthorized acquisition or use.
  2. The number of Illinois residents affected by such incident at the time of notification.
  3. Any steps the data collector has taken or plans to take relating to the incident. 815 Ill. Comp. Stat. Ann. 530/10(e).

Is Notice To Credit Reporting Agencies Required?

No.

Are There Security Measure Standards?

Yes. A data collector that owns or licenses, or maintains or stores but does not own or license, records that contain personal information concerning an Illinois resident shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(a).

Contract Requirements: Additionally, a contract for the disclosure of personal information concerning an Illinois resident that is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. 815 Ill. Comp. Stat. Ann. 530/45(b).

Data Disposal Requirements: A person must dispose of the materials containing personal information in a manner that renders the personal information unreadable, unusable, and undecipherable. Proper disposal methods include, but are not limited to, the following:

  1. Paper documents containing personal information may be either redacted, burned, pulverized, or shredded so that personal information cannot practicably be read or reconstructed.
  2. Electronic media and other non-paper media containing personal information may be destroyed or erased so that personal information cannot practicably be read or reconstructed. 815 Ill. Comp. Stat. Ann. 530/40(b).

What Are The Possible Consequences Of A Violation?

A violation of the breach notification laws constitutes an unlawful practice under the Consumer Fraud and Deceptive Business Practices Act, 815 Ill. Comp. Stat. Ann. 505/1, et seq., which allows for the imposition of civil penalties by the Attorney General and a private right of action for individuals that have suffered actual damages. 815 Ill. Comp. Stat. Ann. 530/20.

Failure to properly dispose of records containing personal information may result in a civil penalty of not more than $100 for each individual with respect to whom personal information is disposed of in violation of the law. A civil penalty may not, however, exceed $50,000 for each instance of improper disposal of materials containing personal information. The Attorney General may impose a civil penalty after notice to the person accused of violating this Section and an opportunity for that person to be heard in the matter. The Attorney General may file a civil action in the circuit court to recover any penalty imposed under this Section. 815 Ill. Comp. Stat. Ann. 530/40(d).

Are There Any Exemptions/Exceptions?

Any covered entity or business associate that is subject to and in compliance with the privacy and security standards for the protection of electronic health information established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act shall be deemed to be in compliance with the provisions of this Act, provided that any covered entity or business associate required to provide notification of a breach to the Secretary of Health and Human Services pursuant to the Health Information Technology for Economic and Clinical Health Act also provides such notification to the Attorney General within five business days of notifying the Secretary. 815 Ill. Comp. Stat. Ann. 530/50.