State’s are passing legislation to address the concerns of the public over protection of data and notifications and remedies when personal data is breached. So far in 2019, Vermont began regulating data brokers and South Carolina’s adoption of the National Association of Insurance Commissioners’ (NAIC) Insurance Data Security Model Law became effective adding significant breach notification and information security requirements for entities licensed by state insurance regulators, including insurers and agents. The North Carolina Attorney General announced a proposal to make significant changes to that state’s notification law, among them requiring notification for ransomware attacks.
The darker the state, the stricter the breach legislation:
The trend continues in Massachusetts, where last week Gov. Charlie Baker signed legislation substantially updating the state’s breach notification law to add 18 months of of credit monitoring to any breach involving social security numbers (42 months for consumer reporting agencies that are breached).
Other key changes to the MA legislation include: