Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Keystone State Tweaks its Data Breach Notification Law Again

By Liisa Thomas, Tracy Chau & Kathryn Smith on July 22, 2024
Email this postTweet this postLike this postShare this post on LinkedIn
1721674852-2934740-7018-lxb_photobBavss4ZQcAlxb_photo-
Jon Moore, Unsplash

In what may become an annual tradition, Pennsylvania has amended its breach notification law. The new provisions will take effect on September 26, 2024. As a reminder, Pennsylvania changed its law last year to expand the definition of “personal information” and to create exemptions for HIPAA-regulated entities.

The changes this year are more extensive, bringing the law into closer alignment with other state data breach notification laws. There are several changes to note:

  • Thresholds: If a breach impacts more than 500 Pennsylvania residents, the Attorney General must be notified. Companies must send such notice concurrently with individual notices. If the breach impacts 500 individuals, then notice must be made to credit reporting agencies (the previous threshold was 1,000). 
  • AG Notice Contents: Beginning in September, Pennsylvania will join many other states in requiring companies to include specific content in the notice to the AG. This includes the organization’s name and location, as well as the date of the breach and a summary of the incident. The notice must also include an estimate of the total number of impacted individuals, and number of impacted Pennsylvania residents.
  • Credit Monitoring: If the breach involves social security numbers, bank account numbers, or drivers’ license/state ID numbers, then companies will need to provide 12 months credit monitoring. Additionally, companies will need in these circumstances to give impacted individuals access to a free credit report, if they could not otherwise get free access. 
  • Personal Information: As a reminder, the 2023 amendments added “medical information” to the definition of personal information, that, if breached, would trigger a duty to notify. That definition is now narrowed to be only medical information held by a state agency or its contractor.

Putting It Into Practice: Pennsylvania amended law serves as reminder to review incident response plans. To the extent they list with specificity timing or content requirements, ensure that they address these new developments.

Photo of Liisa Thomas Liisa Thomas

Liisa Thomas, a partner based in the Chicago and London offices, is Leader of the firm’s Privacy and Cybersecurity Practice Group.

Read more about Liisa ThomasEmail
Photo of Tracy Chau Tracy Chau

Tracy Chau is a privacy and cybersecurity associate based in the Chicago office. She is a member of the Intellectual Property Practice Group and the Privacy and Cybersecurity Team.

Read more about Tracy ChauEmail
Photo of Kathryn Smith Kathryn Smith

Kathryn (“Katie”) Smith is an associate in the Intellectual Property Practice Group in the firm’s Chicago office and a member of the Privacy and Cybersecurity Team. She is certified by the International Association of Privacy Professionals (IAPP) for CIPP/US.

Read more about Kathryn SmithEmail
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Eye On Privacy
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo