Tag Archives: Maryland

Maryland

Who Is Covered?

A business that owns, licenses, or maintains computerized data that includes personal information of an individual residing in Maryland. Md. Code Ann., Com. Law § 14-3504(b).

 

What Information Is Protected?

“Personal information” means:

A. An individual’s first name or first initial and last name in combination with any one or more of the following data elements, when the data elements are not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable:

  1. A social security number, an individual taxpayer identification number, a passport number, or other identification number issued by the federal government;
  2. A driver’s license number or state identification card number;
  3. An account number, a credit card number, or a debit card number, in combination with any required security code, access code, or password, that permits access to an individual’s financial account;
  4. Health information, including information about an individual’s mental health;
  5. A health insurance policy or certificate number or health insurance subscriber identification number, in combination with a unique identifier used by an insurer or an employer that is self-insured, that permits access to an individual’s health information; 
  6. Biometric data of an individual generated by automatic measurements of an individual’s biological characteristics such as a fingerprint, voice print, genetic print, retina or iris image, or other unique biological characteristic, that can be used to uniquely authenticate the individual’s identity when the individual accesses a system or account; or
  7. For purposes of the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual;Md. Code Ann., Com. Law § 14-3501(e).

B. A user name or e-mail address in combination with a password or security question and answer that permits access to an individual’s e-mail account; or

C. For the purposes of the requirements of this title other than the notifications required under § 14-3504(b)(2), (c), (d), (e), (f), and (g) of this subtitle, genetic information with respect to an individual when the genetic information is not encrypted, redacted, or otherwise protected by another method that renders the information unreadable or unusable, including:

  1. Data, regardless of its format, that results from the analysis of a biological sample of the individual or from another source that enables equivalent information to be obtained and that concerns genetic material;
  2. Deoxyribonucleic acids;
  3. Ribonucleic acids;
  4. Genes;
  5. Chromosomes;
  6. Alleles;
  7. Genomes;
  8. Alterations or modifications to deoxyribonucleic acids or ribonucleic acids;
  9. Single nucleotide polymorphisms;
  10. Uninterrupted data that results from the analysis of a biological sample from the individual or other sources; and
  11. Information extrapolated, derived, or inferred from item 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10 of this item. Md. Code Ann., Com. Law § 14-3501

 

What Is A “Breach”?

“Breach of the security of a system” means the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of the personal information maintained by a business. Md. Code Ann., Com. Law § 14-3504(a).

 

What Triggers Notification?

A determination following an investigation that the breach of the security of the system creates a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(b).

 

Likelihood of Harm Analysis

Notification to the individual in not necessary if the business reasonably determines that the breach of the security of the system does not create a likelihood that personal information has been or will be misused. Md. Code Ann., Com. Law § 14-3504(c)(2).

 

How Is Notice Provided To Individuals?

Timing: Notice must be given as soon as reasonably practicable, but not later than 45 days after the business discovers or is notified of the breach of the security system. Md. Code Ann., Com. Law § 14-3504(b)(3).

 

Delivery: Notice may be made by:

  1. Written notice sent to the most recent address of the individual in the records of the business;
  2. Electronic mail to the most recent electronic mail address of the individual in the records of the business, if: (i)  The individual has expressly consented to receive electronic notice; or (ii)  The business conducts its business primarily through Internet account transactions or the Internet;
  3. Telephonic notice, to the most recent telephone number of the individual in the records of the business; or
  4. Substitute notice if the business does not have sufficient contact information to give notice in accordance with item (1), (2), or (3) of this subsection. Substitute notice shall consist of: shall consist of: (a) Electronically mailing the notice to an individual entitled to notification under subsection (b) of this section, if the business has an electronic mail address for the individual to be notified; (b) Conspicuous posting of the notice on the website of the business, if the business maintains a website; and (c) Notification to major print or broadcast media in geographic areas where the individuals affected by the breach likely reside.

 

Content: Except for a breach involving only an email account, notification must include:

  1. To the extent possible, a description of the categories of information that were, or are reasonably believed to have been, acquired by an unauthorized person, including which of the elements of personal information were, or are reasonably believed to have been, acquired;
  2. Contact information for the business making the notification, including the business’s address, telephone number, and toll-free telephone number if one is maintained;
  3. The toll-free telephone numbers and addresses for the major consumer reporting agencies; and
  4. The toll-free telephone numbers, addresses, and website addresses for the Federal Trade Commission and the Office of the Attorney General, and a statement that an individual can obtain information from these sources about steps the individual can take to avoid identity theft. Md. Code Ann., Com. Law § 14-3504(g).

If the breach involves only an email account, notification may be made in electronic or other form, subject to several restrictions, that directs the individual whose personal information has been breached promptly to:

  1. Change the individual’s password and security question or answer, as applicable; or
  2. Take other steps appropriate to protect the email account with the business and all other online accounts for which the individual uses the same user name or email and password or security question or answer. Md. Code Ann., Com. Law § 14-3504(i).

 

Is Notice To The Government Required?

Yes, notice must be provided to the Attorney General prior to providing notice to affected residents. The notice shall include, at a minimum: (i) The number of affected individuals residing in the State; (ii) A description of the breach of the security of a system, including when and how it occurred; (iii) Any steps the business has taken or plans to take relating to the breach of the security of a system; and (iv) The form of notice that will be sent to affected individuals and a sample notice. Md. Code Ann., Com. Law § 14-3504(h).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a business is required under § 14-3504 of this subtitle to give notice of a breach of the security of a system to 1,000 or more individuals, the business also shall notify, without unreasonable delay, each consumer reporting agency that compiles and maintains files on consumers on a nationwide basis of the timing, distribution, and content of the notices. Md. Code Ann., Com. Law § 14-3506(a).

 

Are There Security Measure Standards?

Yes. To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the state shall implement and maintain reasonable security procedures and practices that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations. Md. Code Ann., Com. Law § 14-3503(a).

Additionally, a business that uses a nonaffiliated third party as a service provider to perform services for the business and discloses personal information about an individual residing in the state under a written contract with the third party shall require by contract that the third party implement and maintain reasonable security procedures and practices that are:

 

  1. Appropriate to the nature of the personal information disclosed to the nonaffiliated third party; and
  2. Reasonably designed to help protect the personal information from unauthorized access, use, modification, disclosure, or destruction.

Data Destruction Standards: When a business is destroying a customer’s, an employee’s, or a former employee’s records that contain personal information of the customer, employee, or former employee, the business shall take reasonable steps to protect against unauthorized access to or use of the personal information, taking into account:

 

  1. The sensitivity of the records;
  2. The nature and size of the business and its operations;
  3. The costs and benefits of different destruction methods; and
  4. Available technology.

 

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive trade practice which allows for enforcement action by the Attorney General and a private right of action for any injury or loss sustained. Md. Code Ann., Com. Law §§ 14-3508; 13-401.

 

Are There Any Exemptions/Exceptions?

A business that complies with the requirements for notification procedures, the protection or security of personal information, or the destruction of personal information under the rules, regulations, procedures, or guidelines established by the primary or functional federal or state regulator of the business shall be deemed to be in compliance with this subtitle. Md. Code Ann., Com. Law § 14-3507(b).

Additionally, businesses that are subject to and in compliance with GLBA, FACTA or HIPAA, among other acts, are deemed to be in compliance. Md. Code Ann., Com. Law § 14-3507(c), (d).