Skip to Main Content

Rhode Island Becomes the Eighth State This Year to Amend Its Breach Notification Statute

01/01/1970 | 2 minute read

Posted in Breach Notification,Data Breach Notification Laws

cyber security iStock_000041562536_LargeAs the number of data breaches continues to skyrocket, state legislatures around the country are rushing to amend their breach notification statutes. The most recent state to continue this trend is Rhode Island. On June 26, 2015, Rhode Island Governor Gina Raimondo signed into law Senate Bill S0134 (SB134), the Rhode Island Identity Theft Protection Act of 2015. SB134 substantially revises the prior statute by expanding the definition of “personal information,” requiring notification to the state’s attorney general and mandating a risk-based information security program.

Personal Information

California was the first state to enact a data breach statute back in 2003. Since that time, 46 states have followed suit to some degree or another. California could be credited with starting another trend when it expanded its definition of personal information in 2013 to include email addresses and passwords used to access an individual’s online account. SB134 follows California’s example by including email addresses and, not surprisingly given the recent rash of healthcare breaches, medical information and health insurance information.

Notification

Every state breach notification statute in effect today requires notification to the affected individual, but a select few also require notification to the state attorney general. Rhode Island’s latest amendment now requires notification to the attorney general for breaches involving 500 or more residents. The amendment also sets a 45-day window, from confirmation of the breach, for notification to be provided to affected residents. Each reckless violation of Rhode Island’s revised statute, including the failure to notify, can result in a penalty of $100 per record, while knowing and willful violations could reach $200 per record.

Risk-Based Information Security Program

Most states require organizations that collect or store personal information to maintain reasonable security. SB134 goes one step further and requires organizations to “implement a risk based information security program which contains reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information and the purpose for which the information was collected.” The inclusion of the phrase “risk based information security program” suggests that the Rhode Island legislature expects entities to adopt a risk management program similar to that currently mandated in the healthcare industry under the Health Insurance Portability and Accountability Act. Accordingly, it is likely that future investigations by the Rhode Island Attorney General’s Office will include requests for evidence of past security risk assessments and risk management plans.

As previously mentioned, Rhode Island is not the only state to revise its data breach notification statute. This year has seen amendments passed by Connecticut, Montana, Nevada, North Dakota, Oregon, Washington, and Wyoming. In addition, several more states are also considering amendments to their data breach statutes, including Illinois, where an amendment has been passed by the state Senate and House and is awaiting signature by the governor. To help navigate the rapid developments, BakerHostetler has conducted a state-by-state survey of data breach notification laws available here.