Tag Archives: Oregon

Oregon

Who Is Covered?

“Covered entity” means a person that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person’s business, vocation, occupation or volunteer activities. Or. Rev. Stat. Ann. § 646A.602(5)(a).

What Information Is Protected?

“Personal information” means:

A. A consumer’s first name or first initial and last name in combination with any one or more of the following data elements, if encryption, redaction or other methods have not rendered the data elements unusable or if the data elements are encrypted and the encryption key has been acquired:

  1. A consumer’s social security number;
  2. A consumer’s driver license number or state identification card number issued by the Department of Transportation;
  3. A consumer’s passport number or other identification number issued by the United States;
  4. A consumer’s financial account number, credit card number or debit card number, in combination with any required security code, access code or password that would permit access to a consumer’s financial account, or any other information or combination of information that a person reasonably knows or should know would permit access to the consumer’s financial account;
  5. Data from automatic measurements of a consumer’s physical characteristics, such as an image of a fingerprint, retina or iris, that are used to authenticate the consumer’s identity in the course of a financial transaction or other transaction;
  6. A consumer’s health insurance policy number or health insurance subscriber identification number in combination with any other unique identifier that a health insurer uses to identify the consumer; or
  7. Any information about a consumer’s medical history or mental or physical condition or about a health care professional’s medical diagnosis or treatment of the consumer.

B. A user name or other means of identifying a consumer for the purpose of permitting access to the consumer’s account, together with any other method necessary to authenticate the user name or means of identification.

C. Any of the data elements or any combination of the data elements described in subparagraph (A) or (B) of this paragraph without the consumer’s user name, or the consumer’s first name or first initial and last name, if: (i) Encryption, redaction or other methods have not rendered the data element or combination of data elements unusable; and (ii) The data element or combination of data elements would enable a person to commit identity theft against a consumer. Or. Rev. Stat. Ann. § 646A.602(12)(A)(a).

What Is A “Breach”?

“Breach of security” means an unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of personal information that a person maintains or possesses. Or. Rev. Stat. Ann. § 646A.602(1)(a).

What Triggers Notification?

The covered entity being subjected to a breach of security or receiving notice of a breach of security from a vendor. Or. Rev. Stat. Ann. § 646A.604(1).

Likelihood of Harm Analysis: A covered entity does not need to notify consumers of a breach of security if, after an appropriate investigation or after consultation with relevant federal, state or local law enforcement agencies, the covered entity reasonably determines that the consumers whose personal information was subject to the breach of security are unlikely to suffer harm. The covered entity must document the determination in writing and maintain the documentation for at least five years. Or. Rev. Stat. Ann. § 646A.604(8).

How Is Notice Provided To Individuals?

Timing: Notice must be provided in the most expeditious manner possible, without unreasonable delay, but not later than 45 days after discovering or receiving notification of the breach of security, but only after the covered entity undertakes reasonable measures that are necessary to:

  1. Determine sufficient contact information for the intended recipient of the notice;
  2. Determine the scope of the breach of security; and
  3. Restore the reasonable integrity, security and confidentiality of the personal information. Or. Rev. Stat. Ann. § 646A.604(3).

Delivery: Notice may be made:

  1. In writing;
  2. Electronically, if the covered entity customarily communicates with the consumer electronically or if the notice is consistent with the provisions of the E-Sign Act;
  3. By telephone, if the covered entity contacts the affected consumer directly; or
  4. With substitute notice, if the covered entity demonstrates that the cost of notification otherwise would exceed $250,000 or that the affected class of consumers exceeds 350,000, or if the covered entity does not have sufficient contact information to notify affected consumers. For the purposes of this paragraph, “substitute notice” means: (A) Posting the notice or a link to the notice conspicuously on the covered entity’s website if the covered entity maintains a website; and (B) Notifying major statewide television and newspaper media. Or. Rev. Stat. Ann. § 646A.604(4).

Content: Notice must include:

  1. A description of the breach of security in general terms;
  2. The approximate date of the breach of security;
  3. The type of personal information that was subject to the breach of security;
  4. Contact information for the covered entity;
  5. Contact information for national consumer reporting agencies; and
  6. Advice to the consumer to report suspected identity theft to law enforcement, including the Attorney General and the Federal Trade Commission. Or. Rev. Stat. Ann. § 646A.604(5).

Is Notice To The Government Required?

Yes, if the number of consumers to whom the covered entity must send the notice exceeds 250. Or. Rev. Stat. Ann. § 646A.604(1)(b).

Is Notice To Credit Reporting Agencies Required?

Yes. If a covered entity discovers or receives notice of a breach of security that affects more than 1,000 consumers, the covered entity shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain reports on consumers on a nationwide basis of the timing, distribution and content of the notice the covered entity gave to affected consumers and shall include in the notice any police report number assigned to the breach of security. A covered entity may not delay notifying affected consumers of a breach of security in order to notify consumer reporting agencies. Or. Rev. Stat. Ann. § 646A.604(6).

Are There Security Measure Standards?

Yes. A covered entity and a vendor shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of personal information, including safeguards that protect the personal information when the covered entity or vendor disposes of the personal information. In addition to complying with any federal law that provides greater protection to personal information than the protections that this section provides or with the HIPAA, a covered entity or vendor is in compliance if it implements an information security program that includes:

A. Administrative safeguards such as:

  1. Designating one or more employees to coordinate the security program;
  2. Identifying reasonably foreseeable internal and external risks with reasonable regularity;
  3. Assessing whether existing safeguards adequately control the identified risks;
  4. Training and managing employees in security program practices and procedures with reasonable regularity;
  5. Selecting service providers that are capable of maintaining appropriate safeguards and practices, and requiring the service providers by contract to maintain the safeguards and practices;  
  6. Adjusting the security program in light of business changes, potential threats or new circumstances; and
  7. Reviewing user access privileges with reasonable regularity.

B. Technical safeguards such as:

  1. Assessing risks and vulnerabilities in network and software design and taking reasonably timely action to address the risks and vulnerabilities;
  2. Applying security updates and a reasonable security patch management program to software that might reasonably be at risk of or vulnerable to a breach of security;
  3. Monitoring, detecting, preventing and responding to attacks or system failures; and
  4. Regularly testing, monitoring and taking action to address the effectiveness of key controls, systems and procedures.

C. Physical safeguards such as:

  1. Assessing, in light of current technology, risks of information collection, storage, usage, retention, access and disposal and implementing reasonable methods to remedy or mitigate identified risks;
  2. Monitoring, detecting, preventing, isolating and responding to intrusions timely and with reasonable regularity;
  3. Protecting against unauthorized access to or use of personal information during or after collecting, using, storing, transporting, retaining, destroying or disposing of the personal information; and
  4. Disposing of personal information, whether the covered entity or vendor disposes of the personal information on or off the covered entity’s or vendor’s premises or property, after the covered entity or vendor no longer needs the personal information for business purposes or as required by local, state or federal law by burning, pulverizing, shredding or modifying a physical record and by destroying or erasing electronic media so that the information cannot be read or reconstructed. Or. Rev. Stat. Ann. § 646A.622(1), (2).

What Are The Possible Consequences Of A Violation?

In addition to all other penalties and enforcement provisions provided by law, any person who violates or who procures, aids or abets in a violation shall be subject to a penalty of not more than $1,000 for every violation, which shall be paid to the General Fund of the State Treasury. Every violation is a separate offense and, in the case of a continuing violation, each day’s continuance is a separate violation, but the maximum penalty for any occurrence shall not exceed $500,000.  Additionally, a violation is an unlawful practice under Or. Rev. Stat. Ann. § 646.607. Or. Rev. Stat. Ann. §§ 646A.624(4); 646A.604(11)(a).

If the director has reason to believe that any person has engaged or is engaging in any violation, the director may issue an order, subject to ORS chapter 183, directed to the person to cease and desist from the violation, or require the person to pay compensation to consumers injured by the violation. The director may order compensation to consumers only upon a finding that enforcement of the rights of the consumers by private civil action would be so burdensome or expensive as to be impractical. Or. Rev. Stat. Ann. § 646A.624(3).

Are There Any Exemptions/Exceptions?

With the exception of the requirement to send notice to the attorney general, the breach notification requirements do not apply to:

  1. Personal information that is subject to, and a person that complies with, notification requirements or procedures for a breach of security that the person’s primary or functional federal regulator adopts, promulgates or issues in rules, regulations, procedures, guidelines or guidance.
  2. Personal information that is subject to, and a person that complies with, a state or federal law that provides greater protection to personal information and disclosure requirements at least as thorough as the protections and disclosure requirements provided under this section.
  3. A covered entity or vendor that complies with regulations promulgated under Title V of the Gramm-Leach-Bliley Act.
  4. A covered entity or vendor that complies with regulations promulgated under the Health Insurance Portability and Accountability Act. Or. Rev. Stat. Ann. § 646A.604(9).