Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

National Data Breach Notification Law Proposed

By Dena M. Castricone on November 8, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

At the end of last week, three U.S. Democratic Senators, including Connecticut’s Richard Blumenthal, proposed the 44-page Data Security and Breach Notification Act (“Proposed Act”).  The Proposed Act would preempt the laws of the 48 states that currently have data breach notification laws and the Federal Trade Commission (“FTC”) would have enforcement authority.  State Attorneys General would be permitted to pursue violations of the Proposed Act as civil actions in federal court if the FTC has not already initiated an action. The Proposed Act also provides for sizable civil penalties up to $5 million and criminal penalties including imprisonment for up to 5 years for willful failure to notify those impacted.   Congress has considered proposed legislation on data security measures and breach notification in the past and it is unclear whether this effort will be more successful than the others, but given the recent Uber and Equifax incidents, lawmakers may be more motivated to act.

The Proposed Act would require any business, nonprofit, educational institution or charity that acquires, maintains or uses personal information (“Covered Entity”): (1) to establish and implement policies and procedures related to security practices; and (2) to notify impacted individuals and the FTC not later than 30 days after discovery of a breach with limited exceptions and, under certain circumstances, to notify each major consumer credit reporting agency, the Department of Homeland Security and/or other federal agencies.  A breach is defined as the acquisition or access of electronically maintained personal information without authorization (or a reasonable belief that personal information was accessed or acquired without authorization).   Violations of either the policy or notification provision would be deemed an unfair trade practice under section 5 of the Federal Trade Commission Act.

Personal information under the Proposed Act is defined as: (1) a full social security number; (2) a financial account, credit or debit card number with any applicable access or security code; or (3) the first and last name or first initial and last name in combination with at least one of the following: (a) driver’s license, passport, alien registration number or other seminal government issued number; (b) unique biometric data; or (c) unique account identifier such as a user name along with the password to give access to something of value; or (4) two of the following: (a) home address or telephone number; (b) mother’s maiden name; or (c) complete birth date.

Unlike the data breach notification law in Connecticut and in some other states, the Proposed Act does not mandate credit monitoring.  It does, however, require that the Covered Entity provide an impacted individual with copies of his or her consumer credit report upon request and at certain intervals for 2 years after the request when certain information is involved in the breach.

Notably, financial institutions and health care entities will be deemed to be in compliance with the policy and notification requirements under the Proposed Act if the entities comply with their comparable requirements under other federal statutes and regulations (e.g. Gramm-Leach-Bliley Act and HIPAA/HITECH).

Photo of Dena M. Castricone Dena M. Castricone

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro…

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro Bono Committee.  Prior to joining Murtha Cullina, Dena served as a law clerk to the Chief Justice of the Rhode Island Supreme Court, Frank J. Williams.

As the Chair of the Privacy and Cybersecurity group and a Certified Information Privacy Professional (CIPP/US), Dena provides the full complement of data breach coaching services to business and health care clients including breach notification to individuals and various government entities.  Related to data breaches, she also counsels clients on the creation of information security, incident response plans and other proactive measures.  Additionally, Dena advises clients on compliance with state, federal and international privacy laws including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) as well as many others. Dena has written extensively on privacy and cybersecurity issues and she is the Co-Editor of Privacy and Cybersecurity Perspectives.  Read More

Read more about Dena M. CastriconeEmailDena M.'s Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy and Cybersecurity Perspectives
  • Organization:
    Murtha Cullina LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo