Two-day Notification Requirement for Security Breaches

WashingtonAgency guidance

Ask Donna

How this section applies to your facts.

Washington OIC Technical Assistance Advisories and Emergency Orders › Two-day Notification Requirement for Security Breaches

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

MIKE KREIDLER

STATE INSURANCE COMMISSIONER

STATE OF WASHINGTON

OFFICE OF

INSURANCE COMMISSIONER

Phone: (360) 725-7000

www.lnsurance.wa.gov

Technical Assistance Advisory 2017-01 1

TO: All Licensees with Consumers residing in the State of Washington

FROM: Insnrance Commissioner Mike Kreidler 'YY1 B t\

DATE: April 30, 2017

SUBJECT: Two-day Notification Requirement for Security Breaches

A security breach is the unauthorized acquisition of data that compromises the security,

confidentiality, or integrity of personal inforrnation maintained by a person or business.2

If a security breach occurs, all licensees must notify the Insurance Commissioner. The notification

must be made in writing and must include the number of consumers potentially affected and the

actions being taken by the licensee. The notification must be made within two (2) business days

after determining that a security breach occurred. 3

A security breach occurs the first day on which the breach is known to the licensee or the date

when the breach should have been known to the licensee if reasonable diligence had been used.4

A licensee is considered to have knowledge of a breach if the event is known or, by exercising

reasonable diligence, would have been known to any person who works for or is an agent of the

licensee. 5

Two types of information are included within the security breach notification requirements:

•

Personal information that seems reasonably likely to subject consumers to a risk of criminal

activity, 6 and

1 This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions,

approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).

2 RCW 19.255.010(4).

3 WAC 284-04-625(2).

4 See 45 C.F.R. 164.404(a)(2).

5 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.

6 RCW 19.255.010(5); WAC 284-04-625(2)(a)

o a risk of criminal

activity, 6 and

1 This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions,

approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).

2 RCW 19.255.010(4).

3 WAC 284-04-625(2).

4 See 45 C.F.R. 164.404(a)(2).

5 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.

6 RCW 19.255.010(5); WAC 284-04-625(2)(a). Categories include social security number, driver's license munber

or Washington identification card nun1ber, and account nu1nber or credit or debit card nu1nber in cotnbination with

any required security code, access code, or password that would per1nit access to an individual's financial account.

•

Unsecured protected health information that compromises the security or privacy of the

consumer's protected information. 7

Failure to notify the Insurance Commissioner of a security breach is considered an unfair method

of competition or a deceptive practice.8 It may result in the levying of fines or an order to cease

and desist the selling of insurance in the state ofWashington under RCW 48.30.010.

For a single breach of personal information that involves more than five hundred ( 500) Washington

residents, the person or business must notify the Washington State Attorney General's Office. 9

The breach of unprotected health infonnation must also be reported and notification provided

pursuant to 45 C.F.R. 164.400 through 164.410.

For any questions related to security breach notifications, please contact Dan Halpin, Compliance

Analyst, at DanH@oic.wa.gov or (360) 725-7089.

7 WAC 284-04-625(2)(b);

8 WAC 284-04-625(1)

9 Please refer to: http://www.atg.wa.gov/data-breach-notifications

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

Two-day Notification Requirement for Security Breaches · WA OIC Technical Assistance Advisory 2017-01 | Frix