WA OIC Technical Assistance Advisory 2017-01

Two-day Notification Requirement for Security Breaches

Year: 2017Length: 472 wordsOfficial source
MIKE KREIDLER STATE INSURANCE COMMISSIONER STATE OF WASHINGTON OFFICE OF INSURANCE COMMISSIONER Phone: (360) 725-7000 www.lnsurance.wa.gov Technical Assistance Advisory 2017-01 1 TO: All Licensees with Consumers residing in the State of Washington FROM: Insnrance Commissioner Mike Kreidler 'YY1 B t\ DATE: April 30, 2017 SUBJECT: Two-day Notification Requirement for Security Breaches A security breach is the unauthorized acquisition of data that compromises the security, confidentiality, or integrity of personal inforrnation maintained by a person or business.2 If a security breach occurs, all licensees must notify the Insurance Commissioner. The notification must be made in writing and must include the number of consumers potentially affected and the actions being taken by the licensee. The notification must be made within two (2) business days after determining that a security breach occurred. 3 A security breach occurs the first day on which the breach is known to the licensee or the date when the breach should have been known to the licensee if reasonable diligence had been used.4 A licensee is considered to have knowledge of a breach if the event is known or, by exercising reasonable diligence, would have been known to any person who works for or is an agent of the licensee. 5 Two types of information are included within the security breach notification requirements: • Personal information that seems reasonably likely to subject consumers to a risk of criminal activity, 6 and 1 This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions, approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1). 2 RCW 19.255.010(4). 3 WAC 284-04-625(2). 4 See 45 C.F.R. 164.404(a)(2). 5 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190. 6 RCW 19.255.010(5); WAC 284-04-625(2)(a). Categories include social security number, driver's license munber or Washington identification card nun1ber, and account nu1nber or credit or debit card nu1nber in cotnbination with any required security code, access code, or password that would per1nit access to an individual's financial account. • Unsecured protected health information that compromises the security or privacy of the consumer's protected information. 7 Failure to notify the Insurance Commissioner of a security breach is considered an unfair method of competition or a deceptive practice.8 It may result in the levying of fines or an order to cease and desist the selling of insurance in the state ofWashington under RCW 48.30.010. For a single breach of personal information that involves more than five hundred ( 500) Washington residents, the person or business must notify the Washington State Attorney General's Office. 9 The breach of unprotected health infonnation must also be reported and notification provided pursuant to 45 C.F.R. 164.400 through 164.410. For any questions related to security breach notifications, please contact Dan Halpin, Compliance Analyst, at DanH@oic.wa.gov or (360) 725-7089. 7 WAC 284-04-625(2)(b); 8 WAC 284-04-625(1) 9 Please refer to: http://www.atg.wa.gov/data-breach-notifications
WA OIC Technical Assistance Advisory 2017-01: Two-day Notification Requirement for Security Breaches | Justis AI