See other bills
under the
same topic
PRIOR PRINTER'S NO. 899
PRINTER'S NO. 1100
THE GENERAL ASSEMBLY OF PENNSYLVANIA
SENATE BILL
No.
824
Session of
2023
INTRODUCED BY PENNYCUICK, DILLON, BREWSTER, DUSH, COSTA,
BOSCOLA, BROOKS, SCHWANK, CAPPELLETTI, CULVER AND MILLER,
JUNE 15, 2023
SENATOR PENNYCUICK, COMMUNICATIONS AND TECHNOLOGY, AS AMENDED,
SEPTEMBER 19, 2023
AN ACT
Amending the act of December 22, 2005 (P.L.474, No.94),
entitled, as amended, "An act providing for security of
computerized data and for the notification of residents whose
personal information data was or may have been disclosed due
to a breach of the security of the system; and imposing
penalties," further providing FOR DEFINITIONS, for
notification of the breach of the security of the system and
for notification of consumer reporting agencies; and
providing for credit reporting and monitoring.
The General Assembly of the Commonwealth of Pennsylvania
hereby enacts as follows:
Section 1. Section 3 of the act of December 22, 2005
(P.L.474, No.94), known as the Breach of Personal Information
Notification Act, is amended by adding a subsection to read:
SECTION 1. THE DEFINITION OF "PERSONAL INFORMATION" IN
SECTION 2 OF THE ACT OF DECEMBER 22, 2005 (P.L.474, NO.94),
KNOWN AS THE BREACH OF PERSONAL INFORMATION NOTIFICATION ACT,
AMENDED NOVEMBER 3, 2022 (P.L.2139, NO.151), IS AMENDED TO READ:
SECTION 2. DEFINITIONS.
THE FOLLOWING WORDS AND PHRASES WHEN USED IN THIS ACT SHALL
<--
<--
<--
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
HAVE THE MEANINGS GIVEN TO THEM IN THIS SECTION UNLESS THE
CONTEXT CLEARLY INDICATES OTHERWISE:
* * *
"PERSONAL INFORMATION."
(1) AN INDIVIDUAL'S FIRST NAME OR FIRST INITIAL AND LAST
NAME IN COMBINATION WITH AND LINKED TO ANY ONE OR MORE OF THE
FOLLOWING DATA ELEMENTS WHEN THE DATA ELEMENTS ARE NOT
ENCRYPTED OR REDACTED:
(I) SOCIAL SECURITY NUMBER.
(II) DRIVER'S LICENSE NUMBER OR A STATE
IDENTIFICATION CARD NUMBER ISSUED IN LIEU OF A DRIVER'S
LICENSE.
(III) FINANCIAL ACCOUNT NUMBER, CREDIT OR DEBIT CARD
NUMBER, IN COMBINATION WITH ANY REQUIRED SECURITY CODE,
ACCESS CODE OR PASSWORD THAT WOULD PERMIT ACCESS TO AN
INDIVIDUAL'S FINANCIAL ACCOUNT.
(IV) MEDICAL INFORMATION IN THE POSSESSION OF A
STATE AGENCY OR STATE AGENCY CONTRACTOR.
(V) HEALTH INSURANCE INFORMATION.
(VI) A USER NAME OR E-MAIL ADDRESS, IN COMBINATION
WITH A PASSWORD OR SECURITY QUESTION AND ANSWER THAT
WOULD PERMIT ACCESS TO AN ONLINE ACCOUNT.
(2) THE TERM DOES NOT INCLUDE PUBLICLY AVAILABLE
INFORMATION THAT IS LAWFULLY MADE AVAILABLE TO THE GENERAL
PUBLIC FROM FEDERAL, STATE OR LOCAL GOVERNMENT RECORDS OR
WIDELY DISTRIBUTED MEDIA.
* * *
SECTION 1.1. SECTION 3 OF THE ACT IS AMENDED BY ADDING A
SUBSECTION TO READ:
Section 3. Notification of the breach of the security of the
20230SB0824PN1100 - 2 -
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
system.
* * *
(c.1) Notice to Attorney General.--When notice of the breach
of the security of the system under this section must be given
to more than 500 affected individuals in this Commonwealth,
notice shall be made concurrently to the Office of Attorney
General. Notice to the Attorney General shall include the
following information TO THE EXTENT KNOWN BY THE NOTIFYING
ENTITY :
(1) The organization name and location.
(2) The date of the breach OF THE SECURITY OF THE
SYSTEM .
(3) A summary of the breach incident OF THE SECURITY OF
THE SYSTEM .
(4) An estimated total number of individuals affected by
the breach OF THE SECURITY OF THE SYSTEM .
(5) An estimated total number of individuals in this
Commonwealth affected by the breach OF THE SECURITY OF THE
SYSTEM .
* * *
Section 2. Section 5 of the act is amended to read:
Section 5. Notification of consumer reporting agencies.
When an entity provides notification under this act to more
than [1,000] 500 persons at one time, the entity shall also
notify, without unreasonable delay, all consumer reporting
agencies that compile and maintain files on consumers on a
nationwide basis, as defined in section 603 of the Fair Credit
Reporting Act (Public Law 91-508, 15 U.S.C. § 1681a), of the
timing, distribution and number of notices.
Section 3. The act is amended by adding a section to read:
20230SB0824PN1100 - 3 -
<--
<--
<--
<--
<--
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Section 5.4. Credit reporting and monitoring.
(a) Assumption of costs.--An entity providing notification
under section 5 shall assume all costs and fees in providing the
affected individuals:
(1) Access to an independent credit report from a
consumer reporting agency supplied once per month for a
period of six months following notification.
(2) Access to credit monitoring services for a period of
12 months following notification.
(b) THAT PROVIDES NOTIFICATION UNDER SECTION 5 AND MEETS THE
REQUIREMENTS OF SUBSECTION (B) SHALL ASSUME ALL COSTS AND FEES
IN PROVIDING THE AFFECTED INDIVIDUALS:
(1) ACCESS TO ONE INDEPENDENT CREDIT REPORT FROM A
CONSUMER REPORTING AGENCY IF THE INDIVIDUAL IS NOT ELIGIBLE
TO OBTAIN AN INDEPENDENT CREDIT REPORT FROM A CONSUMER
REPORTING AGENCY FOR FREE UNDER 15 U.S.C. § 1681 (RELATING TO
CONGRESSIONAL FINDINGS AND STATEMENT OF PURPOSE).
(2) ACCESS TO CREDIT MONITORING SERVICES FOR A PERIOD OF
12 MONTHS FOLLOWING NOTIFICATION. AN ENTITY MAY SATISFY THE
REQUIREMENTS OF THIS PARAGRAPH BY PROVIDING NOTICE TO THE
INDIVIDUAL OF THE AVAILABILITY OF MONITORING SERVICES FOR A
PERIOD OF 12 MONTHS AT NO COST TO THE INDIVIDUAL.
(B) DATA SUBJECT TO CREDIT REPORTING AND MONITORING.--
NOTWITHSTANDING ANY OTHER PROVISION OF LAW, AN ENTITY SHALL BE
SUBJECT TO THE REQUIREMENTS OF THIS SECTION IF THAT ENTITY MAKES
A DETERMINATION THAT A BREACH OF THE SECURITY OF THE SYSTEM HAS
OCCURRED AND REASONABLY BELIEVES THAT AN INDIVIDUAL'S FIRST NAME
AND LAST NAME OR AN INDIVIDUAL'S FIRST INITIAL AND LAST NAME, IN
COMBINATION WITH ANY OF THE FOLLOWING INFORMATION, HAS BEEN
ACCESSED:
20230SB0824PN1100 - 4 -
<--
<--
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
(1) SOCIAL SECURITY NUMBER.
(2) BANK ACCOUNT NUMBER.
(3) DRIVER'S LICENSE OR STATE ID NUMBER.
(C) Notice.--The entity shall inform the affected individual
of the availability of no-cost services under subsection (a)
upon notification in compliance with this act.
Section 4. This act shall take effect in 60 90 days.
20230SB0824PN1100 - 5 -
<--
1
2
3
4
5
6
7