Two-day Notification Requirement for Security Breaches
WashingtonAgency guidance
Ask Donna
How this section applies to your facts.
Washington OIC Technical Assistance Advisories and Emergency Orders › Two-day Notification Requirement for Security Breaches
Text
MIKE KREIDLER
STATE INSURANCE COMMISSIONER
STATE OF WASHINGTON
OFFICE OF
INSURANCE COMMISSIONER
Phone: (360) 725-7000
www.lnsurance.wa.gov
Technical Assistance Advisory 2017-01 1
TO: All Licensees with Consumers residing in the State of Washington
FROM: Insnrance Commissioner Mike Kreidler 'YY1 B t\
DATE: April 30, 2017
SUBJECT: Two-day Notification Requirement for Security Breaches
A security breach is the unauthorized acquisition of data that compromises the security,
confidentiality, or integrity of personal inforrnation maintained by a person or business.2
If a security breach occurs, all licensees must notify the Insurance Commissioner. The notification
must be made in writing and must include the number of consumers potentially affected and the
actions being taken by the licensee. The notification must be made within two (2) business days
after determining that a security breach occurred. 3
A security breach occurs the first day on which the breach is known to the licensee or the date
when the breach should have been known to the licensee if reasonable diligence had been used.4
A licensee is considered to have knowledge of a breach if the event is known or, by exercising
reasonable diligence, would have been known to any person who works for or is an agent of the
licensee. 5
Two types of information are included within the security breach notification requirements:
•
Personal information that seems reasonably likely to subject consumers to a risk of criminal
activity, 6 and
1 This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions,
approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).
2 RCW 19.255.010(4).
3 WAC 284-04-625(2).
4 See 45 C.F.R. 164.404(a)(2).
5 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.
6 RCW 19.255.010(5); WAC 284-04-625(2)(a)
o a risk of criminal
activity, 6 and
1 This advisory is an interpretive policy statement released to advise the public of the OIC's current opinions,
approaches, and likely courses of action. It is advisory only. RCW 34.05.230(1).
2 RCW 19.255.010(4).
3 WAC 284-04-625(2).
4 See 45 C.F.R. 164.404(a)(2).
5 See 45 C.F.R. 164.404(a)(2); WAC 390-05-190.
6 RCW 19.255.010(5); WAC 284-04-625(2)(a). Categories include social security number, driver's license munber
or Washington identification card nun1ber, and account nu1nber or credit or debit card nu1nber in cotnbination with
any required security code, access code, or password that would per1nit access to an individual's financial account.
•
Unsecured protected health information that compromises the security or privacy of the
consumer's protected information. 7
Failure to notify the Insurance Commissioner of a security breach is considered an unfair method
of competition or a deceptive practice.8 It may result in the levying of fines or an order to cease
and desist the selling of insurance in the state ofWashington under RCW 48.30.010.
For a single breach of personal information that involves more than five hundred ( 500) Washington
residents, the person or business must notify the Washington State Attorney General's Office. 9
The breach of unprotected health infonnation must also be reported and notification provided
pursuant to 45 C.F.R. 164.400 through 164.410.
For any questions related to security breach notifications, please contact Dan Halpin, Compliance
Analyst, at DanH@oic.wa.gov or (360) 725-7089.
7 WAC 284-04-625(2)(b);
8 WAC 284-04-625(1)
9 Please refer to: http://www.atg.wa.gov/data-breach-notifications
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.