New State Security Breach Notification Laws
Client Alert | 1 min read | 09.08.05
Beyond the HIPAA Privacy Rule and the HIPAA Security Rule, health care entities now face potential compliance obligations under an increasing number of state laws requiring notification of security breaches. Following in the footsteps of the California legislature, nineteen other states have now passed security breach notification laws, and there are similar laws pending in eight states whose legislatures are still in session: New Jersey, Massachusetts, Michigan, North Carolina, Ohio, Oregon, Pennsylvania, and Wisconsin.
Each of the recently enacted laws, like the California law, generally require entities to notify promptly the residents of that state if the security, confidentiality or integrity of their personal information – defined similarly by most states with some notable exceptions – has been compromised.
Failure to comply may result not only in enforcement by state officials, but could also result in civil lawsuits – some of the new state laws incorporate a private right of action.
|
|
If your organization loses personal data,
|
The best way to avoid disclosure under the new laws is to avoid the breach in the first place. Therefore, we recommend that as a supplement to existing HIPAA Security measures, health care entities adopt and implement any necessary state-specific procedures for handling the security of personal information generally. Health care entities should also prepare a response plan which includes an established method for notifying individuals when and if their personal information is compromised. Furthermore, most states will accept an existing information security policy if it contains notification provisions that meet the timing requirements of the new laws. If you already have an information security policy, you may wish to review it to ensure it comports with new applicable state law.
Insights
Client Alert | 4 min read | 03.25.26
NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know
The National Association of Insurance Commissioners (NAIC) is intensifying its oversight of how insurers use AI — and the pace of regulatory activity shows no signs of slowing. Over the past several months, the NAIC has published a formal Issue Brief staking out its position on federal AI legislation, launched a multistate AI Evaluation Tool pilot aimed at examining insurers’ AI governance programs, and continued to expand adoption of its AI Model Bulletin across state lines. These developments continue a trend towards enhancing regulation; the NAIC adopted AI Principles in 2020 and a Model Bulletin in 2023 clarifying that existing insurance laws apply to AI systems and establishing expectations for governance, documentation, testing, and third-party oversight. That Model Bulletin has now been adopted in approximately 24 states.
Client Alert | 11 min read | 03.25.26
White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children
Client Alert | 3 min read | 03.24.26
California Considering A Massive Expansion of Its Antitrust Laws
Client Alert | 2 min read | 03.23.26
