Dan Kaplan reports: The California Senate has approved a bill that would update the state’s pioneering data breach notification law, the lawmaker who introduced the legislation announced Friday. The bill from Democratic Sen. Joe Simitian is a reintroduction of the same measure that he proposed last year, but which was ultimately vetoed by Gov. Arnold…
Category: State/Local
Last State Without a Breach Notice Law? Not Mississippi
Tanya Forsheit reports: Yesterday, Mississippi Governor Haley Barbour approved Mississippi’s first breach notification law, House Bill 583, leaving only four states without a notification law (Alabama, Kentucky, New Mexico, and South Dakota). Read more on InformationLawGroup. The law goes into effect July 1, 2011.
Virginia Adds Medical Information Breach Notice Law
David Navetta writes: The state of Virginia has passed a breach notice law requiring notice of security breaches involving medical information. […] “Breach of the security of the system” means unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security, confidentiality, or integrity of medical information maintained by an individual or…
Addition to Washington Breach Law Imposes Retailer Liability in Payment Card Breaches
Under a Washington law effective July 1, 2010, certain entities involved in payment card transactions may be liable to financial institutions for costs associated with reissuing payment cards after security breaches. Designed to encourage the reissuance of payment cards as a means of mitigating harm caused by security breaches, Washington H.B. 1149 applies to three…
Nevada and New Hampshire Data Security and Privacy Laws Take Effect
Hunton & Williams LLP write: On January 1, 2010, two important state data security and privacy laws took effect in Nevada and New Hampshire. The laws create new obligations for most companies that do business in Nevada and for health care providers and business associates in New Hampshire. Nevada’s law requires “data collectors,” including government…
Massachusetts Data Security Regulations Final Amendments Released
Tanya Forsheit reports: As we noted earlier this week, Massachusetts indicated late last week it would issue its last round of amendments to its data security regulations scheduled to take effect March 1, 2010, 201 CMR 17.00. The last round of amendments are not particularly significant, although it is worth noting that, contrary to the…